- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: VPN Site to Site down
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Site to Site down
Hi there to you all,
I face a rather annoying situation.
Our client has bought several SMB Appliances for protection and safe routing through VPN Site to Site communication.
We implemented a Star network topology with those appliances.
The star is on our private cloud (it is on a vm) and the satellites are centrally managed through Smart-1 Cloud.
Well, everything was good till yesterday when the VPN tunnel could not be established, the negotiation fails on Main Mode packet 5-6 with "INVALID-COOKIE".
Also, follow sk126092, it did not work for us.
The appliances were a cluster of two 1600 SMBs.
The weird thing is that inside the Smart-1 cloud says that it has "issues": "IPSec VPN blade is about to expire Jun 26, 2023 (Evaluation)" when on the appliance itself everything seems ok: "IPSec, expiration Never, Service CPSB-VPN"
I suspect that this is a glitch on Smart-1 Cloud because when I check "Licenses" in the tab below for each member of the cluster, it says that "127.0.0.1 Never 00-1C-... CPAP-AP1600 CPSG-C-12-U CPSB-FW CPSB-VPN CPSB-IA CPSB-SSLVPN-500 CPSB-ADNC CPSB-ADNC-M..."
Any ideas?
Update: we are in the third "phase" of ecalation but with no result so far.
It seems that licensing "problems" is just "cosmetics" and nothing has to do with the real problem that causes the IKE rejection.
We have already renew our certificates to no avail,
we created brand new certificates and installed them also to no avail.
Please, we need your ideas!!!
Help!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What firmware release is being used here?
Also, have you attempted any debugging steps here? https://support.checkpoint.com/results/sk/sk62482
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there PhoneBoy,
The current firmware version is R81.10 (996000575)
I followed the steps on the sk, I had a session with a Checkpoint Engineer (3rd escalation) but to no avail
Thank you for your effort anyway,
I would appreciate any other ideas!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have the exact set of symptoms in sk126062?
Otherwise, those remediation steps won't work and deeper debugs will be required.
Did you actually take the debugs as specified in sk62482 and provide these to TAC?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes and yes.
Thanks again for your effort!
