Hello Checkmates,
Customer has request to establish a VPN tunnel over an existing VPN tunnel ( two miktotiks over existing VTI tunnel between CheckPoint R80.40 and Juniper).
When tunnel is initiated from Miktrotik behind CP, the IKE packet is dropped from CP with message:
"Failed to enforce VPN policy (11)".
Regard, sk106241.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
I've changed setting fw ctl set int encrypt_non_gw_rdp_ike 1 , but without success
Please, do you have some suggestions about this problem, or is TAC necessary for this.