- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Failed to enforce VPN policy (11)
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Failed to enforce VPN policy (11)
Hello Checkmates,
Customer has request to establish a VPN tunnel over an existing VPN tunnel ( two miktotiks over existing VTI tunnel between CheckPoint R80.40 and Juniper).
When tunnel is initiated from Miktrotik behind CP, the IKE packet is dropped from CP with message:
"Failed to enforce VPN policy (11)".
Regard, sk106241.
I've changed setting fw ctl set int encrypt_non_gw_rdp_ike 1 , but without success
Please, do you have some suggestions about this problem, or is TAC necessary for this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, please raise a TAC case. Also, the mentioned SK does not seem to be related to your specific case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Actually, it is relevant. the second case "Site to Site" seems to be your situation. Did you try setting up VPN debug, as SK recommends?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Val, thank you for answer, sorry for late response, meanwhile client has decided for other better solution. If we have same request in future, we will take debug.
