Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marco32
Contributor

VPN and SmartLSM doesn't works

Hi there,

I'm trying in my LAB to create a VPN from a CheckPoint Gateway and several 1570R managed by SmartProvisiong.

Every SMB is connected to a SmartProvisiong of a CMA in my MDS and use a cellular interface to reach my network.

The CheckPoint Gateway is managed by the same CMA.

 

I followed SmartProvisioning Adming Guide, but I see only some tunnel_test packet and no other traffic.

I don't have any route to EncryptionDomain in CheckPoint Gateway even if I try to use permanent tunnel.

 

The EncryptionDomain of the Gateway is configured with a group containing a subnet.

The EncryptionDomain on SmartLSM Gateway is configured Manual (on Topology page) witha range of IP that are used as NAT.

 

Traffic coming to Gateway from it's EncryptionDomain is dropped as:

# fw ctl zdebug + drop | grep 20.20.20.100
@;389050;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=1 20.20.20.100:1 -> 10.10.10.9:0 dropped by fw_log_ip_routing_failure Reason: IP routing failed (ipout routing failure);

Can some one help me?


Regards

M

0 Kudos
5 Replies
the_rock
MVP Gold
MVP Gold

Run command -> ip r g 20.20.20.100 and see path its taking. Confirm first it is correct and if so, we can run fw monitor to verify.

0 Kudos
Marco32
Contributor

#ip r g 20.20.20.10
20.20.20.100 via 10.176.2.200 dev eth1 src 10.176.2.90cache

 

#ip r g 10.10.10.9

RTNETLINK answers: Network is unreachable

 

20.20.20.100 is on Gateway side , 10.10.10.9 is on SMB

Traffic need to start from 20.20.20.100 to 10.10.10.9

0 Kudos
the_rock
MVP Gold
MVP Gold

Can you draw simple diagram showing how this is configured and whats supposed to access what on the other side? Even basic paint diagram would help : - )

Cheers.

Andy

0 Kudos
the_rock
MVP Gold
MVP Gold

We need to find out WHY that IP shows unreachable, thats the key here.

0 Kudos
Marco32
Contributor

Hi the_rock,

main issue seems that no route are present on Gateway and on SMB. I see tunnel_test from SMB to Gateway but VPN is marked as down.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events