- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
Setup a site to site vpn to third party (amazonaws) from our CP R81.20 but the tunnel is not coming up.
initiating traffic on our back end, i can see on the tcpdump ext int that we are sending a isakmp and receive 1 back but thats where it stops. Tunnel does not come up
Any ideas please ?
IP xxxxxxx.co.uk.isakmp > xxxxxxxxxxxx.amazonaws.com.isakmp: isakmp: parent_sa ikev2_init[I]
IPxxxxxxxxxxxamazonaws.com.isakmp > xxxxxxxxx.co.uk.isakmp: isakmp: parent_sa ikev2_init[R]
Hey,
Are you using numbered or unnumbered vti's? Set as permanent tunnel? Mesage me offline, happy to do remote if you allow it. Im fairly experienced with Azure VPN tunnels, though have done couple with AWS as well.
Best,
Andy
Hi,
It is just setup as a site to site vpn, we do not use vti's on our CP
Thanks
Okay..is it set as permanent tunnel via community object tunnel management or no? How do you have below configured?
Andy
Hi,
Set Permanent is not ticked and vpn tunnel sharing is "one vpn tunnel per subnet pair"
Ok, no problem. All debug shows is that you guys are I as initiator, and AWS is R, as in responder, but clearly config is not matching somewhere, as even phase 1 does not seem to be working.
Andy
Did you also do simple vpn debug?
vpn debug trunc
vpn debug ikeon
-try generate some traffic
vpn debug ikeoff (after 2-3 mins)
Look for ike and vpnd files in $FWDIR.log dir
Get them off the fw and examine for any relevant IPs, or you can simply grep -i from ssh as well
ie from expert mode -> grep -i 2.3.4.5 vpnd.elg (just replace 2.3.4.5 with actual peer external IP)
Best,
Andy
And which documentation did you follow when configuring the S2S VPN ?
Hi,
I just followed the phase 1 and 2 proposals set by the third party. Sorry im not great on CP.
If the third party use vti im guessing that would not be an issue if we dont ?
Rgds,
Thats fine, dont worry, we are here to help! Put it this way, for route based VPN, you need VTI. Have a look at my post below, I know its about Azure, but I explained it the best I could. Happy to do remote if you allow that, not an issue. I really feel I could help you with it.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 10 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY