- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello.
Can someone advise exactly how Check Point stand with GRE support?
I understand they can’t build or terminate GRE tunnels, but can they pass the traffic through?
There is a VPN between 2 Cisco Routers who are trying to establish a tunnel however it isn’t coming up. After discussions, I realised they are using GRE over IPSEC VPN.
I have now concluded that this is the reason why it’s not coming up.
Any suggestions?
Hi, Static NAT is set up on the firewall.
500 and 4500 allowed through the firewall.
no drop logs.
all I see is router A sending UDP 500 to router B and vice versa.
Obviously the VPN is never getting past phase 1.
are you saying GRE traffic should pass without an issue then?
I will ask them to add the commands to the Cisco routers below.
FYI ipsec on cisco defaults to NAT-T enabled. This has been the default for a very long time.
show run all
will show hidden defaults.
I had a similar issue on a GRE tunnel that was not coming up between 2 GRE routers, that were communicating over an IPSec tunnel.
Creating a specific rule that allowed the GRE service (nevertheless there was an "allow any over IPSec" rule below it) solved it.
Hi Jochen,
Hope you are doing well, i have a similar setup with the customer, where he has Mikrotik routers in DC doing gre over ipsec with microtik on the remote sites.
did you connect the cisco router behind the checkpoint on lan or you directly connected them, could you share the rule and NAT config for the same as well ?
Hi Karan,
The routers were connected at both sides behind the LAN port of the CP FW's. Between both CP's, an IPSec tunnel was implemented. Then, within the IPSec tunnel, a GRE tunnel between the routers was build (without NAT etc). In order to fix the gre issue, an explicit rule with service "gre" accept was created.
KR, jochen
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY