- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi All,
Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.
Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason: "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.
Thank you.
Hi All,
Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.
Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason: "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.
Thank you.
Hi All,
Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.
Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason: "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.
Thank you.
Hi All,
Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.
Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason: "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.
Thank you.
PFS use is very usual, so i do not think that it could be an issue here...
PFS use is very usual, so i do not think that it could be an issue here...
PFS use is very usual, so i do not think that it could be an issue here...
Hi @G_W_Albrecht ,
Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...
Hi @G_W_Albrecht ,
Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...
Hi @G_W_Albrecht ,
Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...
Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?
Andy
Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?
Andy
Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?
Andy
All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.
All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.
All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.