Hello all!
my first post I've ever made here, with an error that's driving me crazy!
Endpoint Security Client: E87.60 Build 986105018
Checkpoint 6200P Cluster: R81.10 take 335
I've been trying to secure our VPN connection with MFA for a year with Endpoint Security Client and Entra ID . However, I cannot switch authentication for all users, because there is an onnoying problem with the new identity provider (Microsoft Entra ID).
I already had tickets open regarding that topic, that had been passed on to the escalation engineer. Unfortunately, no solution was provided after gathering a lot of logs over months. The engineer was very rude and kept asking for new logs without providing a solution.
I would like to hear your opinion and at the same time ask if you know the problem?
Explanation:
- Microsoft Entra ID is used as an identity provider.
See link: https://learn.microsoft.com/de-de/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial
- Multifactor authentication is required when establishing a connection. -> Everything fine.
But after a few hours the VPN connection no longer works
Helpdesk.log from Endpoint Security Client (Advanced Logging)
[21 Feb 17:04:03] No reply from the gw ip=X.X.X.X for tunnel test packet. Office Mode IP=A.A.A.A, source port=18009.
[21 Feb 17:04:05] No reply from the gw ip=X.X.X.X for tunnel test packet. Office Mode IP=A.A.A.A, source port=18010.
[21 Feb 17:04:08] IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.
[21 Feb 17:04:08] Client state is connected
[21 Feb 17:04:08] Tunnel (2) disconnected. State is connected. Trying to reconnect.
[21 Feb 17:04:18] IKE connection failed, error code=-1000. Reason: Site is not responding.
[21 Feb 17:04:18] Client state is reconnecting
[21 Feb 17:04:18] Reconnect failed. trying again (2)
......
[21 Feb 17:06:17] Client state is reconnecting
[21 Feb 17:06:17] State reconnecting. Roaming timeout is reached, cancelling connection (2)
Site is not responding --> There is no vpn error with user/password authentication at the same time for hundreds of users.
It looks like there is an error with vpn phase 1 or 2, by using Entra ID.
The problem can be solved for a few hours by reestablishing the VPN connection.
The time, in which the connection works fine without problems can be influenced by changing the DHCP lease time.
- If the DHCP Lease Time is 60 minutes, the problem occurs several times a day. (4-5 times in 8 hours with vpn connection)
- If the DHCP Lease Time is 960 minutes, the error only occurs once every 2-3 days.
Automatic DHCP lease: the DHCP Lease time is configured to the same value on our DHCP Server. -> Same error
Manual (using IP pool): Using CP as DHCP Server--> Same error with manual IP Pool.
Global properties -> Remote Access --> Endpoint Connect
Re-authenticate user every is set to 720 minutes according Checkpoint recommendation.
Question:
Does anyone have the same problem or any advice?