Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rakesh1313
Explorer

Management Server Is not able to login via IPsec Tunnel

Hello Team,

Two checkpoint 6200-P Quantum firewall is configured in cluster, and management server is configured in local vm-appliance and IPsec tunnel is configured between checkpoint and sophos firewall.

But when we are trying to access the management server behind the sophos firewall, i am getting the errror below.

Unable to connect the management server.

Management server and both firewall is reachable behind the sophos firewall, I have allowed 19009 port also into sophos policy for VPN traffice but still the error is same.

I have tried to capture the tcpdump but was not able to understand why management server is not rechable.

I have also attached the tcpdump logs file.

Please help me to get it resolved.

0 Kudos
9 Replies
_Val_
Admin
Admin

Some topology diagrams and details about Sophos VPN might help.

0 Kudos
Rakesh1313
Explorer

I dont have topology diagram right now but i have attached logs for refrence.

it will help to you?

 

0 Kudos
_Val_
Admin
Admin

No, logs you are attached are not helping at all.

0 Kudos
the_rock
Legend
Legend

Whats failing? ssh, console, web ui? Can you swnd output of api status and cpwd_admin list if ssh is accessible?

Andy

0 Kudos
Rakesh1313
Explorer

Hello, I am not able to login into smart console.

0 Kudos
Lesley
Leader Leader
Leader

On what device this tcpdump is made?

Looks like there is a route incorrect. This looks like return traffic. I do not see initial traffic in capture meaning it comes in on ETHX and it replies on ETHY this will be out of state. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Rakesh1313
Explorer

Tcpdump is made on the primary gateway,

0 Kudos
PhoneBoy
Admin
Admin

Note that management traffic does NOT go over VPN by design.
Not sure if this applies here since it's not clear where all the components sit in relation to each other.
A simple network diagram would help tremendously.

Martijn
Advisor
Advisor

Hi,

Are Implied Rules enabled? If so, SmartConsole traffic might hit rule number 0 and will not pass via the VPN tunnel.
I had the same with one of our customer and needed to exclude SmartConsole traffic from the Implied Rules.

Please check sk105719.

Regards,
Martijn

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events