If the subnets/Proxy-IDs proposal made by the Check Point in IKE Phase 2 does not match the Juniper subnet definitions EXACTLY (matching subsets are not allowed on Juniper/Fortinet/Sonicwall whereas they are allowed on Cisco/Check Point), the Juniper will discard the request and not answer. Either the Juniper administrator needs to modify their policy to match the subnets/masks your Check Point is proposing, or you need to explicitly define the subnets you want to propose to the Juniper in a user.def file on the Security Management Server. See sk62590 for the proper user.def.* file to edit as there are numerous variants depending on the version of the security gateway, and see sk108600 for the proper syntax definition of the Proxy-IDs in the user.def.* file.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com