Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marco32
Contributor

VPN and SmartLSM doesn't works

Hi there,

I'm trying in my LAB to create a VPN from a CheckPoint Gateway and several 1570R managed by SmartProvisiong.

Every SMB is connected to a SmartProvisiong of a CMA in my MDS and use a cellular interface to reach my network.

The CheckPoint Gateway is managed by the same CMA.

 

I followed SmartProvisioning Adming Guide, but I see only some tunnel_test packet and no other traffic.

I don't have any route to EncryptionDomain in CheckPoint Gateway even if I try to use permanent tunnel.

 

The EncryptionDomain of the Gateway is configured with a group containing a subnet.

The EncryptionDomain on SmartLSM Gateway is configured Manual (on Topology page) witha range of IP that are used as NAT.

 

Traffic coming to Gateway from it's EncryptionDomain is dropped as:

# fw ctl zdebug + drop | grep 20.20.20.100
@;389050;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=1 20.20.20.100:1 -> 10.10.10.9:0 dropped by fw_log_ip_routing_failure Reason: IP routing failed (ipout routing failure);

Can some one help me?


Regards

M

0 Kudos
5 Replies
the_rock
Legend
Legend

Run command -> ip r g 20.20.20.100 and see path its taking. Confirm first it is correct and if so, we can run fw monitor to verify.

0 Kudos
Marco32
Contributor

#ip r g 20.20.20.10
20.20.20.100 via 10.176.2.200 dev eth1 src 10.176.2.90cache

 

#ip r g 10.10.10.9

RTNETLINK answers: Network is unreachable

 

20.20.20.100 is on Gateway side , 10.10.10.9 is on SMB

Traffic need to start from 20.20.20.100 to 10.10.10.9

0 Kudos
the_rock
Legend
Legend

Can you draw simple diagram showing how this is configured and whats supposed to access what on the other side? Even basic paint diagram would help : - )

Cheers.

Andy

0 Kudos
the_rock
Legend
Legend

We need to find out WHY that IP shows unreachable, thats the key here.

0 Kudos
Marco32
Contributor

Hi the_rock,

main issue seems that no route are present on Gateway and on SMB. I see tunnel_test from SMB to Gateway but VPN is marked as down.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events