Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dr_Steve_Brule
Participant

Check Point-to-Check Point IPSEC VPN tunnel - eclipsed and narrow

Hi all,

I recently setup a new S2S CP-to-CP IPSEC VPN.

Site 1 - 6200 GW cluster (active/standby) - R81.20 JHF 41 (VPN domain 10.10.0.0/16)

Site 2  - SMB 1800 single appliance - R81.10.08 (VPN domain 10.20.0.0/16)

Mgmt - Smart-1 Cloud - R81.20

The VPN has overall been stable except for communication between certain /24 subnets within the VPN domains.  For example, overnight I lost communication from 10.20.80.90 to the 10.10.5.0/24 subnet at site 1.  All other inter-site traffic was communicating just fine.  I checked 'vpn tu tlist' and saw several "narrow" and "eclipsed" entries with "No outbound SA" on a couple of entries.

This is a simple S2S with no overlapping networks and no NAT between the two sites.  I've seen some SKs regarding narrowed and eclipsed tunnel related to third-party VPNs, but nothing really for CP-to-CP. 

In the community settings, for VPN tunnel sharing, I'm using "one VPN tunnel per subnet pair".  Should I just change this "to one tunnel per Gateway pair"?

0 Kudos
2 Replies
G_W_Albrecht
Legend Legend
Legend

One VPN Tunnel per subnet pair- Once a VPN tunnel has been opened between two subnets, subsequent sessions between the same subnets will share the same VPN tunnel. This is the default setting and is compliant with the IPsec industry standard

So i would ask CP TAC to resolve the issue instead of moving to Gateway pair.

 

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
the_rock
Legend
Legend

I will tell you my experience with that setting (I meant setting per gateway pair) when it comes to CP to CP tunnels...I always found its best to have that enabled when you have mix of subnets/hosts in the tunnel, otherwise, you just leave it default. Sounds like you may need to do basic VPN debug to see whats going on and then check ike files, as well as vpnd.elg from $FWDIR/log

Just do this on 6200 side:

vpn debug trunc

vpn debug ikeon

-generate some traffic, wait minute or so

vpn debug ikeoff

Then look and examine those files and search for the IPs affected.

Hope that helps.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events