- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello Team,
Two checkpoint 6200-P Quantum firewall is configured in cluster, and management server is configured in local vm-appliance and IPsec tunnel is configured between checkpoint and sophos firewall.
But when we are trying to access the management server behind the sophos firewall, i am getting the errror below.
Unable to connect the management server.
Management server and both firewall is reachable behind the sophos firewall, I have allowed 19009 port also into sophos policy for VPN traffice but still the error is same.
I have tried to capture the tcpdump but was not able to understand why management server is not rechable.
I have also attached the tcpdump logs file.
Please help me to get it resolved.
Some topology diagrams and details about Sophos VPN might help.
I dont have topology diagram right now but i have attached logs for refrence.
it will help to you?
No, logs you are attached are not helping at all.
Whats failing? ssh, console, web ui? Can you swnd output of api status and cpwd_admin list if ssh is accessible?
Andy
Hello, I am not able to login into smart console.
On what device this tcpdump is made?
Looks like there is a route incorrect. This looks like return traffic. I do not see initial traffic in capture meaning it comes in on ETHX and it replies on ETHY this will be out of state.
Tcpdump is made on the primary gateway,
Note that management traffic does NOT go over VPN by design.
Not sure if this applies here since it's not clear where all the components sit in relation to each other.
A simple network diagram would help tremendously.
Hi,
Are Implied Rules enabled? If so, SmartConsole traffic might hit rule number 0 and will not pass via the VPN tunnel.
I had the same with one of our customer and needed to exclude SmartConsole traffic from the Implied Rules.
Please check sk105719.
Regards,
Martijn
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
16 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY