- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi
I am trying to establish a VPN with an interoperable device[Sophos]. As checked, all the VPN parameters are matching.
The VPN itself is not getting established and I am able to find the below mentioned log in SmartLog :
Informational Exchange Received Delete IKE-SA from Peer: xx.xx.xx.xx; Cookies: xxxxxxxxxxxxxxxxxxxxxxxxxxx
Any idea regarding why this issue occurred.
You made it all the way through IKE Phase 1 as I suspected, then the Delete SA happened immediately after. Your SA Lifetime timers for Phase 1 and/or Phase 2 do not match, check them on both sides.
you should be able to find the causing issue with vpn debug ikeon (turn it off with vpn debug ikeoff) and the opening relevant file (ike.elg) with checkpoint ikeview and see if there are any kind of problem regarding phase 2
I am only able to find phase1 info. Couldn't find any phase2 related info from ike.elg file
Try to generate some traffic if you can' t have a phase 2 established check the encryption domain for both gateway involved and vpn community , verify there are no nat rule that match this kind of traffic if there are no need for nat
Please click the "+" sign next to "P1" and post another screenshot so we can see how far you are getting in Phase 1. If Phase 1 is completely succeeding but is immediately followed by a "Delete SA" notification, check the Phase 1 and Phase 2 SA Lifetime timers and make sure they match exactly on both sides. Note that the Phase 1 timer is expressed in minutes on the Check Point and the Phase 2 timer is expressed in seconds, while most other vendors express both values in seconds.
You made it all the way through IKE Phase 1 as I suspected, then the Delete SA happened immediately after. Your SA Lifetime timers for Phase 1 and/or Phase 2 do not match, check them on both sides.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY