Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Cimpeanu
Collaborator

IPSec between R81.20 VS gateway and MS Azure gateway

Hi,

I'm looking for some guidance in regards to creating an IPSec tunnel between a R81.20 VS gateway and MS Azure gateway controlled by a 3rd party; 

What I see from my end is successful peering - both Phase 1 and Phase 2, but the end-to-end communication does not go through the tunnel. I'm running AES265/SHA256, DG group 19 for Phase 1, and AES256/SHA256 with PFS SH Group 19

vpn tu tlist shows me an SPI for the tunnel, SmartView Monitor shows the tunnel as Up. Seen from Checkpoint side, all should be in place and working, yet it doesn't.

 

I have heard from the 3rd party mentioning that in their experience they have seen pre-R81.20 gateways working fine in similar scenarios but failing after an R81.20 upgrade, problem which gor presumably resolved by including an (unknown) Checkpoint ID?? for the Traffic Selectors - I'm puzzled by this statement, haven'd heard anything about this myself. 

 

Any advice is appreciated, I've spent a lot of hours on this without any progress at all. 😞

 

Thanks,

Daniel

 

0 Kudos
3 Replies
Alex-
Advisor
Advisor

We successfully configured VPN's to Azure with R81.20 (both VS and ClusterXL) using the following resources:

 

https://support.checkpoint.com/results/sk/sk101275

 

https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices#RouteBasedOffers

 

Your values might be outside what is supported on the Azure side.

0 Kudos
Daniel_Cimpeanu
Collaborator

Was it IKE v1 or V2 you ended up using?

0 Kudos
the_rock
Legend
Legend

See if below post I made helps, if not, let me know, happy to help further.

Andy

 

https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emc...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events