Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Pavel88
Explorer

invalid ike sa

hello.

I have a vpn between checkpoint and a 3rd party with a dynamically assigned IP address,

I can establish a tunnel only from one way (from the 3rd party) but not from the checkpoint.

it uses a certificate.

from vpnd I can see a lot of massages : 

ikeSimpOrder::setPeer: peer is not a user (is user: 0) or invalid ike sa 

is this message relevant and something has to be checked? 

thank you.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

That generally means your encryption domains are not subnetted/defined the same way on both sides.
See here to debug: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events