Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
Advisor
Advisor

Impact of SMS version on R80.10 VPN

I have some VPN running on an all-R80.10 environment: SMS & appliances, with some interoperable objects which are Checkpoint with embedded GAIA. Really, the classical stuff: VPN communities, encryption domains, excluded services, PSK, all runs well.

If I migrate the management station from R80.10 to R80.30 without changing anything on the hub gateways, all VPN go down with the error message "According to the policy this packet shouldn't have been decrypted" for production traffic. VPN TU, installing policy, disabling acceleration, nothing solves the issue.

When I shut down the R80.30 SMS and restart the R80.10 SMS and apply policy, all VPN go up again.

As it was production, I didn't have much time to go deep. Any known procedure here? I never had the mix of R80.30 & R80.10 running VPN, but well R80.30 MGT with R77.30 or R80.20 and I didn't have those kind of VPN issues.

0 Kudos
1 Reply
G_W_Albrecht
Legend
Legend

Looks like wrong encryption domain - did you do any manual VPN changes in user.def that will not survive an upgrade ?

CCSE CCTE CCSM SMB Specialist

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events