Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

VPN issue between Checkpoint on AWS and Cisco ASA on premise

Hello,

I have VPN tunnel up and running between CheckPoint R77.30 on AWS and Cisco ASA on premise. Traffic is coming from Cisco side however, from CheckPoint side it is getting dropped( Encryption fail reason: Packet is dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge Database) and reject ( Encryption failure: no response from peer.). Please advise

8 Replies
Highlighted

What did you find, if you compared Checkpoint and ASA vpn configuration?

0 Kudos
Highlighted

Issue was due to VPN domain mismatch. Resolved now after giving same subnet IPs at both end. Check point had full subnet defined and at cisco only 3 Ips of same subnet were there

0 Kudos
Highlighted
Pearl

Check on your Cisco what VPN Encryption Domain networks (crypto map) the Check Point tries to negotiate with it. Adjust your Cisco config accordingly.

0 Kudos
Highlighted

Thanks Danny,

You were right. CheckPoint had the full remote network subnet in its VPN domian, where as at Cisco side only 3 IPs of subnet were listed. After adjusting VPN domain, connection worked fine

0 Kudos
Highlighted

Yeah. This type of error generally comes when mismatch of VPN Encryption domain. It should same at both end.

First it choose the valid Proposal and negotiate with same proposal. So check the Encryption method & Algorithm as well.

0 Kudos
Highlighted

Thanks Gaurav,

You were right. CheckPoint had the full remote network subnet in its VPN domian, where as at Cisco side only 3 IPs of subnet were listed. After adjusting VPN domain, connection worked fine

Highlighted

Ok Great.

0 Kudos
Highlighted
Nickel

when you configured the VPN domain, you set up your network subnet too, in the group networks?