Dear team,
Hope you are all doing great.
I am experiencing an issue with a previously working VPN tunnel connected to a server behind an ASA firewall. My side is running Checkpoint R81.2. The problem began yesterday, when l was configuring a route based VPN which l later deleted after it failed.
When I run a tracert to the VPN IP from inside my network, the traffic fails at my firewall with an "Insufficient message passed" error. I can send traffic to the other site, but l am not receiving any return traffic. The engineers on the server side are observing the same behavior – they can send traffic to me but cannot receive anything from my end.
The VPN logs on our Checkpoint firewall show the following error:
Connection terminated before the Security Gateway was able to make a decision: Insufficient data passed. To learn more see sk113479. First possible rule: Layer: Application & URL Filtering, Rule: 5. Missing classifier objects: 1: APPLICATION
I have confirmed that the VPN tunnel (Phase 1 and Phase 2) is establishing successfully, and basic routing appears to be correct. The issue seems to reside in the application filtering or inspection layer. I also checked the encryption settings for my VPN communities and those on the server — they match. There is currently no proxy between my side and the remote end.
Your contributions and insights into resolving this would be highly appreciated.
Thank you