- CheckMates
- :
- Products
- :
- General Topics
- :
- IPSec between R81.20 VS gateway and MS Azure gatew...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSec between R81.20 VS gateway and MS Azure gateway
Hi,
I'm looking for some guidance in regards to creating an IPSec tunnel between a R81.20 VS gateway and MS Azure gateway controlled by a 3rd party;
What I see from my end is successful peering - both Phase 1 and Phase 2, but the end-to-end communication does not go through the tunnel. I'm running AES265/SHA256, DG group 19 for Phase 1, and AES256/SHA256 with PFS SH Group 19
vpn tu tlist shows me an SPI for the tunnel, SmartView Monitor shows the tunnel as Up. Seen from Checkpoint side, all should be in place and working, yet it doesn't.
I have heard from the 3rd party mentioning that in their experience they have seen pre-R81.20 gateways working fine in similar scenarios but failing after an R81.20 upgrade, problem which gor presumably resolved by including an (unknown) Checkpoint ID?? for the Traffic Selectors - I'm puzzled by this statement, haven'd heard anything about this myself.
Any advice is appreciated, I've spent a lot of hours on this without any progress at all. 😞
Thanks,
Daniel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We successfully configured VPN's to Azure with R81.20 (both VS and ClusterXL) using the following resources:
https://support.checkpoint.com/results/sk/sk101275
https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices#RouteBasedOffers
Your values might be outside what is supported on the Azure side.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Was it IKE v1 or V2 you ended up using?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See if below post I made helps, if not, let me know, happy to help further.
Andy
