- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all.
I'm trying to setup a VPN tunnel to a 3rd party and am running into some issues. These are the instructions I have received from the third party regarding the setup:
Encrypt Mode:
IKEv2 only
IKE (Phase 1) Proposal
IKE (Phase 2) Proposal
With the exception of setting the protocol to ESP (not been able to find how to do this) I have done everything else according to these instructions:
When looking in SmartView Tracker I see an 'traffic selectors unacceptable' log entry. Not quite sure how to proceed with this.
We're running R77.30 take 204
Thanks in advance for any assistance.
Tbgaz,
As far as I can remember there are some known problems with IKEv2 and third party gateways. I think there was a problem with SecureXL. Did you tried to disable the acceleration ?
Please have a look at the IKEv2 VPN limitations in VPN limitations in R77.30
Espacially sk102437, sk114834 and sk112139.
Wolfgang
Hi Wolfgang,
Thanks for the reply. I've made some progress, the tunnel is now showing as up. I checked SecureXL but it isn't configured on the gateway. From the 3rd party endpoint to our gateway a 'child SA is successfully created' log entry is created, but going in the opposite direction I see a log message 'Child SA exchange: Peer's message is unacceptable'.
Is it a case that we have to use IKEv1 or is that less than ideal?
Did you consult sk108600: VPN Site-to-Site with 3rd party already ? This is a valuable document for that kind of issues...
Hi. The issue has been resolved. The 3rd party gateway needed to be tweaked to allow connectivity.
Best is pinching with a sharp needle from behind 😁
Is it possible that you share what was being "tweaked"?
Thanks
Would it be possible to share what the tweak was?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY