- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
Is NAT-T enabled by default on Checkpoint equipment?
We have a GW, where we have created multiple VPNs with other clients, but specifically, with 1 client (Cisco ASA), we are having communication problems and according to the tests that the endpoint performs, suggests us to "disable" the NAT-T, but this option of disabling the NAT-T in the GW, affects in general to all the VPNs that you have created, right?
Could someone please confirm this for me.
Greetings.
Ikev2 is way better and more secure, but give it a try.
IKEv1 will be a lot easier to debug. You will have to open legacy_ike.elg in IKEView.
I believe process is the same for ikev2 as well, at least based on TAC cases I had in the past.
Andy
We found the error, and fixed it.
It's weird, but we'd better not even touch it, hahaha.
It turns out, we touched the configuration of the
"VPN TUNNEL SHARING"
Select the option: "One VPN Tunnel per each pair of hosts" .... Once this option was selected, it started to work.
Checkpoint really surprises me 🤣😲
We were seeing the traffic coming out of the encrypted firewall, and everything was fine for us, but the Cisco ASA was not seeing the traffic coming to their equipment, and we had to move to that option, once we did that, it started to work normally.
I really don't understand why, but at least it is working. 🙃
Dont touch it bro, let it be 🙂
GOOD JOB! 👍👍
Andy
Btw, just a comment, keep in mind, this is not necessarily CP issue, I had seen this being needed because of Cisco in the past.
Regardless, now you know to try those options if you ever have this problem in the future 😉
Andy
Yes, I think so.
Although I still believe as you do, that the best option, when you have a mix on both sides of the VPN of segments and hosts, the best is to use the "... per Gateway pair", but today, it didn't feel like working well, HAHAHAHA.
It is useful for the notes. 😂🤣
I hear ya bro :). Trust me, even with lots of other vendors, sometimes, the most logical option is NOT the one that works haha
Andy
You can review both actually...vpn debug trunc command "resets" those files anyway.
Andy
You are correct that, in releases prior to R80.10, that Check Point gateways will never initiate NAT-T (except SMB gateways that always have).
So, nowadays, in version from R80.20 onwards, the GW Checkpoint, have the ability to "INITIATE" the communication on the NAT-T?
What is the default behavior of a GW with NAT-T enabled?
Is it in listening mode, or can it be the one that initiates this traffic?
Yes, Check Point gateways can initiate NAT-T from R80.10 and above.
The option should be enabled by default.
Did you confirm nat option inside vpn community?
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
3 | |
3 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY