- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- IPSEC PUBLIC IP BEHAIND NAT
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSEC PUBLIC IP BEHAIND NAT
Hi Team,
We created the the ipsec with in our lab firewall checkpoint and FortiGate , my checkpoint topology having private ip
the nat happen on redhat openstack portal tunnel is up but i cat able to reach the destination side
is there any thing else need to check
Thanks
Siddu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Siddu,
What have you done so far as far as troubleshooting? Any packet captures, debugs, any logs you can share? Just telling us something is not accessible does not tell us anything, sorry 😞
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For starters, run this from expert mode:
fw ctl zdebug + drop | grep x.x.x.x
Just replace x.x.x.x with dst IP
ctrl c to stop and observe if any messages/logs
On FGT side:
di de di
di de app ike -1
di di en
observe debug messages
q to stop and di de di again
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to configure Link Selection in the gateway/cluster object.
R82 offers the Enhanced Link Selection option, but this is how you can configure it in any version:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good point! I assumed that was set already, but definitely worth confirming.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Scroll further right in the SmartView Monitor, is NAT-T active for that tunnel? If not make sure support for it is enabled on both sides. Also you'll need to implement Phoneboy's suggestion concerning Link Selection.
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe NAT-T is by default enabled on both CP and FGT.
Andy


