Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
siddu099
Contributor

IPSEC PUBLIC IP BEHAIND NAT

Hi Team,

 

We created the the ipsec with in our  lab firewall checkpoint and FortiGate , my checkpoint topology having private ip 

the nat happen on redhat openstack portal tunnel is up but i cat able to reach the destination side

is there any thing else need to check

cp.png

 
 

 

Thanks

Siddu

 

0 Kudos
6 Replies
the_rock
MVP Diamond
MVP Diamond

Hey Siddu,

What have you done so far as far as troubleshooting? Any packet captures, debugs, any logs you can share? Just telling us something is not accessible does not tell us anything, sorry 😞

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

For starters, run this from expert mode:

fw ctl zdebug + drop | grep x.x.x.x

Just replace x.x.x.x with dst IP

ctrl c to stop and observe if any messages/logs

On FGT side:

di de di

di de app ike -1

di di en

observe debug messages

q to stop and di de di again

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
PhoneBoy
Admin
Admin

You need to configure Link Selection in the gateway/cluster object.
R82 offers the Enhanced Link Selection option, but this is how you can configure it in any version:

image.png

the_rock
MVP Diamond
MVP Diamond

Good point! I assumed that was set already, but definitely worth confirming.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

Scroll further right in the SmartView Monitor, is NAT-T active for that tunnel?  If not make sure support for it is enabled on both sides.  Also you'll need to implement Phoneboy's suggestion concerning Link Selection.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos
the_rock
MVP Diamond
MVP Diamond

I believe NAT-T is by default enabled on both CP and FGT.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events