Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
This widget could not be displayed.
6 Replies
This widget could not be displayed.

Hi All,

 

Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.

 

Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:  "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.

 

Thank you.

 

 

encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortigate

encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortigate

encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortigate

Hi All,

 

Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.

 

Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:  "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.

 

Thank you.

 

 

Hi All,

 

Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.

 

Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:  "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.

 

Thank you.

 

 

Hi All,

 

Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.

 

Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:  "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.

 

Thank you.

 

 

0 Kudos
0 Kudos
0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver
G_W_Albrecht
MVP Silver
MVP Silver
G_W_Albrecht
MVP Silver
MVP Silver

PFS use is very usual, so i do not think that it could be an issue here...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

PFS use is very usual, so i do not think that it could be an issue here...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

PFS use is very usual, so i do not think that it could be an issue here...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
0 Kudos
0 Kudos
LeeBingKang
Advisor
LeeBingKang
Advisor
LeeBingKang
Advisor

Hi @G_W_Albrecht ,

 

Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...

Hi @G_W_Albrecht ,

 

Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...

Hi @G_W_Albrecht ,

 

Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...

0 Kudos
0 Kudos
0 Kudos
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond

Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Andy

Best,
Andy
"Have a great day and if its not, change it"

Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Andy

Best,
Andy
"Have a great day and if its not, change it"

Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
0 Kudos
0 Kudos
Timothy_Hall
MVP Gold
MVP Gold
Timothy_Hall
MVP Gold
MVP Gold
Timothy_Hall
MVP Gold
MVP Gold

All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos
0 Kudos
0 Kudos