Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dc09
Explorer

No response from gateway for 1st packet

Hi,

i've problem with vpn connections. I added a new site, but when i try to connect, i have error: No response from gateway for 1st packet.

I found similar problem here(https://community.checkpoint.com/t5/Remote-Access-VPN/Remote-Access-VPN-No-response-from-gateway-for...) but i think my router and routing are not a problem.

How can i debug problem? What have i done so far:

  • vpn debug on and check logs, i did not found any errors
  • fw monitor -e "accept src=ip_address;" - looks good, communication is on the same eth
  • i can curl any site form that gateway

What else should i check?

 

Cheers

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

Is your client connecting to the gateway you are performing the debugging from?
If so, have you done an fw ctl debug drop | grep x.y.z.w

0 Kudos
dc09
Explorer

hi,

there arent any drops from my endpoint client ip address. I noticed that i have the correct https/443 communication, but there is nothing on the 4500 port.

 

0 Kudos
PhoneBoy
Admin
Admin

That would imply the NAT-T packets are getting blocked upstream somehow. 
Have you tried from a different network?

0 Kudos
dc09
Explorer

Yes, i tried two different networks and isp, but still same error.

0 Kudos
PhoneBoy
Admin
Admin

If the gateway is not receiving the NAT-T packet that you can see, it might be something on the client side.
Can you see on the client side that it's sending the NAT-T packet?

0 Kudos
dc09
Explorer

I have set up access to another site on the same client and everythings works fine there. I added fresh logs from trac.log. 

[IKE] TimeoutEventHandler: Got Timeout event #1001 - its looks weird

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events