- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: VPN with third Party Device and supernetting
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN with third Party Device and supernetting
Hello Community,
I have a question about VPN site-to-site between Check Point and third party devices.
My version is R80.30 Take 215.
As such, the VPN tunnel works, the peer customer complains about strange Phase2 connection attempts.
However, the source IP address is not stored on the Check Point in the VPN domain on my site.
The technician suspects subneting at the check point.
I found out the following:
ike_enable_supernet = false
ike_use_largest_possible_subnets = true
ike_p2_enable_supernet_from_R80.20 = by_global
I am not sure whether the Check Point makes a supernetting of the VPN domain networks.
Can someone tell me based on these three settings whether the check point makes a supernetting of the networks in the VPN domain?
What I also find strange is that I see via "vpn tu tlist" that my WAN VIP is trying to initiate a phase2 tunnel,
in addition to the three existing phase 2 tunnels , the tunnel does not come Up because the peer does not allow it.
Thank you for your support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk108600: VPN Site-to-Site with 3rd party
sk144094: VPN tunnels with 3rd party peers fail because of mismatched IDs
sk88780: Troubleshooting "No valid SA" error
- Tags:
- vpn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the answer.
I've checked it all out and I'm still unsure.
My question here is. Does the R80.30 Take 215 make summery subnetting in a VPN site-to-site between check point and third party device?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See sk108600: VPN Site-to-Site with 3rd party: Check Point Security Gateway dynamically supernets subnets to reduce the amount of SA overhead - this happens always.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ike_use_largest_possible_subnets = true
That’s one of the settings that controls superneting.
