Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
darren97
Participant

R81.20 Failed to resolve VPN MEP gateway

Hello,

We have a Check Point FW cluster running R81.20.

Recently, we had a customer who has two locations with the same encryption domain. To solve this, we used a MEP solution — the customer’s two locations are configured as Center Gateways and our location as a Satellite Gateway.

However, we encountered a problem. When the customer connects to our SFTP service, everything works fine. But when we try to connect to their site for a different service, we get the following error: “Failed to resolve VPN MEP gateway.”


The encryption domains are negotiated correctly, and it even worked for several days. However, without any changes on our or the customer’s side, we are now getting this error.


Has anyone experienced the same issue?

Thank you.

0 Kudos
6 Replies
darren97
Participant

"Set Permanent Tunnels" solved the problem.

0 Kudos
darren97
Participant

After "Set Permanent Tunnels", publish and install, it worked for several hours.

Unfortunately, again the same problem: Failed to resolve VPN MEP gateway.

0 Kudos
PhoneBoy
Admin
Admin

This is probably going to require TAC to assist in debugging.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Are the customer gateways also Check Points?

0 Kudos
darren97
Participant

No they're not.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

OK, you might need to look through the MEP options in the admin guide and see if there's some configuration you can tweak:

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/T...

You should also consider how the remote site/gateways will route back to the VPNs - are they aware they are in a MEP situation? Are they participating with the DPD coming from the CP side? 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events