Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dphonovation
Collaborator
Jump to solution

Creating VPN community w/ private IPs in Enc Domain breaks ICMP?

I have a weird outtage today where somehow the licensing on my cluster got all out of whack. I've fixed it and cluster is now all green.

However what I now notice is that ICMP to a Remote Office is broken as soon as I have a community setup on the CP side.

 

Checkpoint Public IP: x.x.x.x

Checkpoint VPN Encryption Domain: 10.10.171.0/24

Remote peer Public IP: z.z.z.z

Remote Peer Encryption Domain: 192.168.1.0/24 and 192.168.11.0/24

 

As soon as I configure this community (star or mesh), z.z.z.z can no longer ping x.x.x.x

 

Checkpoint logs report "Clear text packet should be encrypted".

 

I went as far as blowing out all the VPN communities, disabling IPSEC VPN. Pushing policy. Then reenabling and readding the community. I'm rather confused, as I know for a fact before this used to be fine.

 

On top of this, Checkpoint Mobile stopped working entirely.

0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events