- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
I noticed something odd about an IKEv2 VPN tunnel with a Cisco ASA. As far as I can tell, the VPN is working without any issues, but the ASA is creating an unexpected IPsec tunnel. If it is possible to clean up, that would be ideal, but if not, it doesn't seem to be causing any issues.
Setup:
The Check Point GW is running R81.10 Take 130, not sure of the Cisco ASA.
The Check Point is sending a public /29 to two different /32 devices on the ASA side. Running a debug shows that when the Cisco sends TSi for Create Child SA, it includes the following:
The first TSi with the ICMP protocol seems odd to me and the root of the issue. I have reached out to the other side with no response. Has anyone seen this before and know what setting / configuration might be causing this on the Cisco side?
Okay, I went back and looked at the logs. This was a Check Point issue that was resolved by going to R81.10 JHF 131.
The issue was present, I applied the update, and I haven't seen the issue in the logs since.
Do you have configured VPN community as "subnet pair" ? Double check if traffic selectors (encryption domains) is really 1:1 on both ends.
Yes, the community is setup as subnet pair. I do not have control over the other side, and since they are ghosting me, I have to take their word that everything is setup as a subnet on their end.
Though the TSi shows a subnet in the second value, it's the first value that is wrong.
Have a look at sk166417, IKEv2 narrowing is not isolated to Checkpoint b.t.w.
I looked over that earlier, it's informative.
I know guy I used to work with showed me how to fix this on Cisco side. He used to work for Cisco TAC in India, said they used to see this issue all the time. Supposedly there was some sort of a bug in a certain version, but was fixed later. Will see if I can find any notes about it.
Best,
Andy
Sounds good. I was also wondering if it was a certain Cisco version, I thought I had this issue with another Cisco VPN, but I am having a difficult time finding it at the moment, but maybe they upgraded and resolved it.
I have good buddy I also worked with and he may know where the guy currently works, so let me see if we can get a hold of him : - ). Its been probably 7 years since I dealt with Cisco, mind you only with ASA, but I have lots of commands from notes I took back in the day.
I will keep you posted on what I find.
Best,
Andy
Did you ever find anything?
Cheers
I upgraded to R81.10 JHF 131 and the issue is currently resolved from what I can tell. Not sure if the Cisco side has changed anything, never heard back from the third-party.
Okay, I went back and looked at the logs. This was a Check Point issue that was resolved by going to R81.10 JHF 131.
The issue was present, I applied the update, and I haven't seen the issue in the logs since.
Let's check for this:
- https://support.checkpoint.com/results/sk/sk170857 (fixed in T131)
- find out for any duplicate objects related to host/subnets in your vpn tu tlist output. If found, delete them from mgmt, install policy and reset tunnel
That could be related...
I have definitely have that bug on another tunnel, but this seems to be different as it's coming from the Cisco side.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY