Hello,
My client's demand is to attempt to connect via endpoint vpn client from a WiFi network that is behind CP.
I have exempted Office Mode addresses from the external interface, however I am still not able to establish the connection..the vpn client gets stuck at 47%
What I get from the logs is the following:
16:57:49.995884 IP 192.168.244.20.10415 > X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]
16:57:50.258470 IP 192.168.244.20.10415 > X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]
16:57:50.522939 IP 192.168.244.20.10415 > X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]
16:57:50.831110 IP 192.168.244.20.10415 > X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]
16:57:51.050687 IP 192.168.244.20.10415 > X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]
Any guidance regarding this one ?
Let me specify that the external interface of Checkpoint is in the RFC1918 range and that the IPSEC Link selection mechanism is statically NATted where the red one is what is depicted as X.X.X.X in tcpdump.
Regards