Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LeeBingKang
Advisor

encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortigate

Hi All,

 

Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.

 

Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:  "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.

 

Thank you.

 

 

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

R77.30 is End of Support.
However, the message means the gateway received a cleartext packet that it expects to receive encrypted.
This is quite likely Scenario 3 in: https://support.checkpoint.com/results/sk/sk108600

0 Kudos
LeeBingKang
Advisor

Hi phoneboy,

 

Thanks for the explanation.

 

I have another things seek your suggestion. Based on the screenshot provided, i found out there is a "PFS" mentioned in the  data encryption method and there is no PFS enable both sides based on the current vpn configuration on both site (fortigate and checkpoint).

Hence, is that possible cause checkpoint think that this packet is clear text as it being encrypted with PFS as well?

0 Kudos
G_W_Albrecht
Legend
Legend

PFS use is very usual, so i do not think that it could be an issue here...

CCSE CCTE CCSM SMB Specialist
0 Kudos
LeeBingKang
Advisor

Hi @G_W_Albrecht ,

 

Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...

0 Kudos
the_rock
Legend
Legend

Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Andy

0 Kudos
Timothy_Hall
Champion
Champion

All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events