- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.
Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason: "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.
Thank you.
R77.30 is End of Support.
However, the message means the gateway received a cleartext packet that it expects to receive encrypted.
This is quite likely Scenario 3 in: https://support.checkpoint.com/results/sk/sk108600
Hi phoneboy,
Thanks for the explanation.
I have another things seek your suggestion. Based on the screenshot provided, i found out there is a "PFS" mentioned in the data encryption method and there is no PFS enable both sides based on the current vpn configuration on both site (fortigate and checkpoint).
Hence, is that possible cause checkpoint think that this packet is clear text as it being encrypted with PFS as well?
PFS use is very usual, so i do not think that it could be an issue here...
Hi @G_W_Albrecht ,
Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...
Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?
Andy
All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY