- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
We have an issue with a VPN tunnel to a Palo Alto firewall. The IPSec renegotiaion is sometimes initated by both peers at the same time, causing the tunnel to be down for one hour until the next renegotition.
In order to solve this we would like to set one peer in passive mode, so the other side always initiate the renegotiaion. Is this possibe to do on the Check Point VPN gateway?
We are running R77.30 on this gateway cluster.
Thanks for your help!
Harry
R77.30 is out of support since September...
@net-harry Check Point VPN GW will try to open a tunnel whenever some traffic is being sent to the remote VPN domain.
Also, it is unclear to me why simultaneous negotiations should fail if both VPN peers are trying to do IKE. One of the IKE SAs should be complete and work anyway. I would recommend looking into some mis-config on PAN side. There must be something wrong there, this is not a normal IPsec behaviour.
Thanks for the information! I agree that it looks like a bug on the Palo Alto side and their engineers are troubleshooting this. On Palo Alto they are able to configure passive, so I just wanted to check if this was possible on the Check Point side to. I noticed that a similar question was posted in the following thread:
If you set PAN for passive, there is still a chance that traffic might be originated from the remote VPN site. To tackle this, set Check Point VPN GW with a permanent tunnel. This way, it will keep tunnel up, actively requesting IKE when there is no SA or the last one expired.
Thanks for the suggestions!
@G_W_Albrecht, one can extend R77.30 support with additional premium on top of the support contract, if required. Also, there are other special cases where R77.30 support might be pro-longed.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 18 | |
| 12 | |
| 9 | |
| 8 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY