Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Brianpiraty_Ale
Contributor

Phase -2 not working in the Ipsec tunnel

We have multiple sub nets in the local encryption domain(checkpoint firewall ) . and only one subnet for the remote peer encryption domain. Remote peer is a non checkpoint device.

Once we have initiated the ping from central gateway to remote gateway , I see that Phase 1 is up.

Phase2 not. Ike .elg file shows that  P1 - main mode - all 6 packets good.

P2- quick mode , the first packet itself ( QM packet 1) itself failed. is the QM packet I see that IP address of central gateway and remote peer.

when I initiate a ping from the device behind the firewall , though the IP is listed in the subnet , it is not encrypted.

what could be wrong in configuration?

0 Kudos
7 Replies
PhoneBoy
Admin
Admin

I would start by looking at the logs in SmartLog/SmartConsole and seeing if there are any errors noted.

0 Kudos
Brianpiraty_Ale
Contributor

no errors. should I see the central gateway IP and peer gateway IP of P2- message 1 or the IPs of both side encryption domain?

0 Kudos
PhoneBoy
Admin
Admin

Depends on the log message in question.

You should certainly see the VPN establish itself in the logs between the two gateways.

If you're not seeing errors in SmartLog, then the traffic is probably being accepted by a rule that doesn't involve encryption.

Do you see what log the traffic from the original (unencrypted) traffic is accepted on?

0 Kudos
Brianpiraty_Ale
Contributor

I see that it is accepted by an explicit rule. only the thing is it is not encrypted

0 Kudos
Kim_Moberg
Advisor

Did you exclude IPSEC group under vpn community?

Best Regards
Kim
0 Kudos
Brianpiraty_Ale
Contributor

yes. that was one of the issue.

0 Kudos
Houssameddine_1
Collaborator

Whenever you setup vpn tunnels and you test with icmp make sure to change the global properties for icmp traffic to be accepted before last, because any traffic matches implied rules will never get encrypted.

For phase 2 negotiation issue, your best friend is sk108600 scenario 1

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Thanks

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events