Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mitesh
Participant
Jump to solution

IPSec VPN Tunnel

Hi,

We recently migrated IPSec Tunnel from CP 9100 to CP 3800 appliance.

Post migration we are unable to see th tunnel traffic logs on CP 3800.

Required blades is enable on CP3800 gateway.

What we are missing here ?

0 Kudos
1 Solution

Accepted Solutions
the_rock
MVP Platinum
MVP Platinum

Ok...do you see any drops on CP side? What about PAN?

Best,
Andy

View solution in original post

0 Kudos
12 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Are you seeing any logs for the 3800 or is it logging locally?

Use "cpstat fw -f log_connection" to check...

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Platinum
MVP Platinum

You cant see just vpn logs or any logs? Sorry, its not entirely clear from your description.

Best,

Andy

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey @Mitesh 

Were you able to fix this mate?

Andy

Best,
Andy
0 Kudos
Mitesh
Participant

@the_rock unable to resolve the issue.

Let me explain the secnario once again, also attaching network diagram.

We are having 2 tier firewall architecture, Checkpoint we are using for Perimeter & Palo Alto for internel (core), server farm is behind the Palo Alto Firewall.

IPSec Tunnel is configured on Checkpoint, Tunnel is up, traffic from remote network is reaching to checkpoint, but we are unable to see the traffic on Palo Alto Firewall.

I suspect may be routing or NAT issue.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Ok...do you see any drops on CP side? What about PAN?

Best,
Andy
0 Kudos
Mitesh
Participant

Palo Alto sidw we are not seeing any packet.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Then for sure sounds its issue on their end, not CP.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

On CP fw, do this from expert -> fw ctl zdebug + drop | grep x.x.x.x

Just replace with right IPon other side. Its been forever since I worked with PAN, so not sure if they have similar command, but you can check the logs.

Best,
Andy
0 Kudos
Mitesh
Participant

How we can verify trafiic is reaching to Palo Alto Interface via Checkpoint ?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Just do tcpdump or fw monitor. You can refer to below site my colleague made while back.

https://tcpdump101.com

 

 

Best,
Andy
0 Kudos
Mitesh
Participant

@the_rock issue got resolved.

It was routing issue from Palo Alto side.

the_rock
MVP Platinum
MVP Platinum

Excellent, thanks for letting us know.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events