I've got an R81.20 gateway where everything works fine, including Remote Access VPN.
Today I've tried to switch to a new ISP circuit. The new circuit is a /31 subnet, so just the firewall and the ISP router. Interface IP, default gateway, Toplogy etc. all updated. Everything else works fine - Internet access, NAT (in and out), email in and out. But Check Point Mobile clients will no longer connect.
In tcpdump I see the client sending traffic hitting the firewall and it's accepted in the logs on the correct rule, but the gateway never answers. It's like the traffic just falls into a black hole. Turning on remote access Control Connections in Global Properties makes no difference either.
I switched back to the old ISP line (on a /29 subnet) and VPN clients work perfectly again.
The only difference is the new ISP circuit being a /31 subnet. Could this alone really be the reason why VPN clients won't connect? Or more specifically why the gateway receives the connecting traffic but fails to reply with a single packet back?
I know /31 subnets have been a problem in the past on SMB appliances, but is this also the case on non-SMB gateways?