cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

VPN issue between Checkpoint on AWS and Cisco ASA on premise

Hello,

I have VPN tunnel up and running between CheckPoint R77.30 on AWS and Cisco ASA on premise. Traffic is coming from Cisco side however, from CheckPoint side it is getting dropped( Encryption fail reason: Packet is dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge Database) and reject ( Encryption failure: no response from peer.). Please advise

8 Replies

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

What did you find, if you compared Checkpoint and ASA vpn configuration?

0 Kudos

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Issue was due to VPN domain mismatch. Resolved now after giving same subnet IPs at both end. Check point had full subnet defined and at cisco only 3 Ips of same subnet were there

0 Kudos
Danny
Pearl

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Check on your Cisco what VPN Encryption Domain networks (crypto map) the Check Point tries to negotiate with it. Adjust your Cisco config accordingly.

0 Kudos

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Thanks Danny,

You were right. CheckPoint had the full remote network subnet in its VPN domian, where as at Cisco side only 3 IPs of subnet were listed. After adjusting VPN domain, connection worked fine

0 Kudos

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Yeah. This type of error generally comes when mismatch of VPN Encryption domain. It should same at both end.

First it choose the valid Proposal and negotiate with same proposal. So check the Encryption method & Algorithm as well.

0 Kudos

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Thanks Gaurav,

You were right. CheckPoint had the full remote network subnet in its VPN domian, where as at Cisco side only 3 IPs of subnet were listed. After adjusting VPN domain, connection worked fine

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

Ok Great.

0 Kudos
Luisnego
Nickel

Re: VPN issue between Checkpoint on AWS and Cisco ASA on premise

when you configured the VPN domain, you set up your network subnet too, in the group networks?