- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi
We have a site-to-site checkpoint VPN
We are using VMWARE HCX to migrate some workloads through that tunnel. HCX uses NAT-T to build a VPN tunnel using whatever transport is available, which in this case happens to be a checkpoint VPN tunnel, so we are tunneling NAT-T through a checkpoint VPN tunnel.
This has been working for months.
On Friday it broke after we installed the CVE patch and rebooted all the gateways.
Here is the log message "Failure preparing tunnel creation, internal error"
We opened a ticket with TAC on Friday and spoke to an engineer who said they had seen this once before, but it was fixed by an unrelated hotfix.
On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"
I don't believe this to be true.
Is anybody else running HCX over a checkpoint VPN (or any other NAT-T traffic)?
Anybody else seen this error and know the fix?
Thanks
On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"
I agree with you, Im 100% positive that is NOT true.
Is it failing on phase 1 or 2?
Andy
the checkpoint is dropping the packets so it never gets as far as phase 1
Maybe this?
https://support.checkpoint.com/results/sk/sk170141
we have looked at that, but in this case default route is the route that should be used
we have just tried a different tunnel to a different site and it seems to be working so I guess it is supported after all
100% supported, it always has been. Btw, just wondering...does it make any difference if tunnel is reset from both ends? Whats the other side?
Andy
The broken tunnel is VMWARE HCX on both ends. This was working fine for weeks. We rebooted the checkpoint gateways and it stopped working. I beleieve the HCX tunnel was reset, but that is managed by a different team. We just built a new HCX mesh over the same checkpoint tunnel as the broken one, and it seems to be working. The strange thing is the checkpoint is definitely dropping traffic for the broken mesh, and passing traffic for the working mesh. Maybe something in the packet is messed up.
Can you do basic VPN debug and attach iked and vpnd files?
Andy
vpn debug trunc
vpn debug ikeon
-generate some traffic
vpn debug ikeoff
look for iked and vpnd files in $FWDIR/log dir
the checkpoint tunnels are up and always have been. we don't have any diagnostics from HCX. Anyway, it now seems it does work, apart from the original mesh.
I would say if it can be reset from that side, it may help.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY