Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
iancollins
Participant
Jump to solution

Site to site vpn drops on policy install

I have about 8 site to site vpn connections to customers on our R80.30 firewall.

When I install policy changes, some of these connections drop out. Using vpn tu option 7 fixes it.
I've seen various discussions about this - but am unsure what to try.

We currently have "rematch connections" in the connections persistence settings. Is this the best setting - or are there any recommendations for "keep data connections" or "keep all connections"?

How about overriding the default settings in the services in the ipsec service group - and setting "Keep connections open after the policy has been installed"?

Thanks, Ian

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
MVP Gold
MVP Gold

Try setting the keep_IKE_SAs checkbox as described here:

sk142355: VPN tunnel goes down after policy push, must be reset to bring it up

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

View solution in original post

(1)
3 Replies
Timothy_Hall
MVP Gold
MVP Gold

Try setting the keep_IKE_SAs checkbox as described here:

sk142355: VPN tunnel goes down after policy push, must be reset to bring it up

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
(1)
Dreyfuss
Contributor

Thanks for the info, but unfortunately it didn't work for me. Any other suggestions? 81.10 OS Gaia 3.10 take 174

 

Captura de tela 2025-08-29 102359.png

0 Kudos
CaseyB
Advisor

I would recommend making your own thread with pertinent details as this one is nearly 5 years old.

I did see this new SK today: sk183778 - Site-to-Site VPN tunnel between a Centrally Managed Quantum Spark Gateway and a VPN peer ...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events