- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I welcome colleagues.
Please help with a solution. I am building a vpn tunnel with a remote gateway 1530, which is connected by the same management server.
The WAN external interface works via PPPoE using the provider's login and password, receiving a dynamic address.
In the settings of the smart console, I set up a dynamic address on the WAN interface, in the Link Selection I configure setting resolve by dns name, but the traffic does not enter the tunnel. I renew the vpn certificate by adding alternative names to it, the situation did not help.
By setting a static address, I get the error: Main Mode local machine configured not to respond to unknown IP addresses (i.e. not exportable for SR, and/or not included in the RemoteAccess community, and/or no DAIP's defined).
How should the tunnel be built in this case? What exactly to do in Link Selection?
Please provide more details - we know one peer is a 1530 (firmware version ?) with DAIP managed by a CP SMS (version / jumbo take ?), but you give no details of the peer !
Please look into sk117713: "Main Mode local machine configured not to respond to unknown IP addresses" error on local... and sk167473: Dynamically Assigned IP Address (DAIP) Gateway FAQ
Hi Albrecht.
Thanks for your reply.
SMB version 80.20.35, I don't remember the exact build.
Management server 81.10 latest take. I have seen these articles and none of them helped.
I've tried using just the domain name, fqdn, as written there, but that doesn't help. Tunnel traffic is sent to the Internet.
80.20.35 is rather old, current version is R80.20.50. Still you do not mention the peer ! The SMB GW using DAIP has to start the VPN tunnel - sometimes, NAT-T has to be activated manually. see sk162472.
Peer 81.10 last take.
And where does traversal nat come in if both peers are connected directly to the provider?
It does only come in if the VPN fails ! Better contact TAC to get this resolved quickly...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY