cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

Traffic is not passing through correct rule in case of route based vpn with third party device

Hi All,

I have set up a route based VPN between checkpoint R8.10 and fortigate firewall. both tunnel are up. but traffic is not passing through the rule that i have created for VPN.

Please help to resolve this issue.

With Regards,

Sushil Kumar

0 Kudos
2 Replies
Vladimir
Pearl

Re: Traffic is not passing through correct rule in case of route based vpn with third party device

Please provide more information for us to look at. topology diagram, sanitized rules and VTI configuration data, as well as the logs of the traffic that should be routed via VTIs, but is not.

This being said, do you have actual routes for the remote side on Check Point gateway?

 

0 Kudos

Re: Traffic is not passing through correct rule in case of route based vpn with third party device

Hi Sushil,

 

Assuming you have routes configured in Gaia and a blank group set as the encryption domain.

With route based VPNs, you will either need to enable global setting "VPN Directional match" and then configure rules that are set in this way - https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm?topic=documents/R77..., OR do NOT put the VPN community in the VPN column of the rule.

From experience, one of those will resolve it.

thanks

Peter

0 Kudos