- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
Setup a site to site vpn to third party (amazonaws) from our CP R81.20 but the tunnel is not coming up.
initiating traffic on our back end, i can see on the tcpdump ext int that we are sending a isakmp and receive 1 back but thats where it stops. Tunnel does not come up
Any ideas please ?
IP xxxxxxx.co.uk.isakmp > xxxxxxxxxxxx.amazonaws.com.isakmp: isakmp: parent_sa ikev2_init[I]
IPxxxxxxxxxxxamazonaws.com.isakmp > xxxxxxxxx.co.uk.isakmp: isakmp: parent_sa ikev2_init[R]
Hey,
Are you using numbered or unnumbered vti's? Set as permanent tunnel? Mesage me offline, happy to do remote if you allow it. Im fairly experienced with Azure VPN tunnels, though have done couple with AWS as well.
Best,
Andy
Hi,
It is just setup as a site to site vpn, we do not use vti's on our CP
Thanks
Okay..is it set as permanent tunnel via community object tunnel management or no? How do you have below configured?
Andy
Hi,
Set Permanent is not ticked and vpn tunnel sharing is "one vpn tunnel per subnet pair"
Ok, no problem. All debug shows is that you guys are I as initiator, and AWS is R, as in responder, but clearly config is not matching somewhere, as even phase 1 does not seem to be working.
Andy
Did you also do simple vpn debug?
vpn debug trunc
vpn debug ikeon
-try generate some traffic
vpn debug ikeoff (after 2-3 mins)
Look for ike and vpnd files in $FWDIR.log dir
Get them off the fw and examine for any relevant IPs, or you can simply grep -i from ssh as well
ie from expert mode -> grep -i 2.3.4.5 vpnd.elg (just replace 2.3.4.5 with actual peer external IP)
Best,
Andy
And which documentation did you follow when configuring the S2S VPN ?
Hi,
I just followed the phase 1 and 2 proposals set by the third party. Sorry im not great on CP.
If the third party use vti im guessing that would not be an issue if we dont ?
Rgds,
Thats fine, dont worry, we are here to help! Put it this way, for route based VPN, you need VTI. Have a look at my post below, I know its about Azure, but I explained it the best I could. Happy to do remote if you allow that, not an issue. I really feel I could help you with it.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 21 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY