- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
1530, centrally managed, R81.10.05.
The Spark is behind a local router with a fixed public IP and is centrally managed by a SMS in another country behind a Quantum cluster. The Spark has a private IP as External interface and all NAT have been configured.
A VPN to that cluster has worked for a long time until the central site moved to a new public IP range.
The connection to the SMS has been reinitialised on the Spark to get the new management IP and even SIC has been reset, policy installation work and the timestamps match. However the Spark doesn't seem to send logs anymore and I still see ICA_Services to the old public IP.
A VPN that was done to the central site doesn't work anymore. The central site shows the VPN as up but the Spark has only Phase 1 with No Outbound SA for Phase 2.
I've started a TAC SR but wondered if there was an any experience that could be shared here short of factory default the box. 🙂
Long story short, for the Quantum: Key install successful, methods Group 19, certificates, PFS and the like. Now on the Spark: IKE Error but the traffic arrives on the system.
https://support.checkpoint.com/results/sk/sk176564
https://support.checkpoint.com/results/sk/sk180935
https://support.checkpoint.com/results/sk/sk181315
https://support.checkpoint.com/results/sk/sk176564
https://support.checkpoint.com/results/sk/sk180935
https://support.checkpoint.com/results/sk/sk181315
Thanks Guenther, editing $FWDIR/conf/masters did the trick. This file doesn't get updated when the renegotiation to the new public NAT of the SMS shows as successful. Now logs and the VPN started working again.
Glad to hear ! Did you test policy install, that could overwrite masters file with wrong information...
Apart from the public IP change, this 1500 has a very static policy and they're now all in the office managing the shipping of goods all over the German sphere of influence and I won't be the one disrupting that. 😄
But thanks for the tip, I will arrange a maintenance window with the customer later on.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY