I'm trying in my LAB to create a VPN from a CheckPoint Gateway and several 1570R managed by SmartProvisiong.
Every SMB is connected to a SmartProvisiong of a CMA in my MDS and use a cellular interface to reach my network.
The CheckPoint Gateway is managed by the same CMA.
I followed SmartProvisioning Adming Guide, but I see only some tunnel_test packet and no other traffic.
I don't have any route to EncryptionDomain in CheckPoint Gateway even if I try to use permanent tunnel.
The EncryptionDomain of the Gateway is configured with a group containing a subnet.
The EncryptionDomain on SmartLSM Gateway is configured Manual (on Topology page) witha range of IP that are used as NAT.
Traffic coming to Gateway from it's EncryptionDomain is dropped as:
# fw ctl zdebug + drop | grep 18.104.22.168
@;389050;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=1 22.214.171.124:1 -> 10.10.10.9:0 dropped by fw_log_ip_routing_failure Reason: IP routing failed (ipout routing failure);
Can some one help me?