Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
MVP Silver
MVP Silver

Intermittency in P2 of an S2S VPN

Hello everyone,

Are there any troubleshooting steps that can be used to determine whether an intermittency issue in phase 2 of a VPN against AWS is the responsibility of my Check Point?

I have a VPN that occasionally has problems with phase 2, where VoIP traffic travels.
The problem is with the SIP protocol, which occasionally becomes unstable, leading to user complaints about calls and the service in general.

I have detected drop logs related to INSPECTION SETTINGS, especially due to a problem with SIP traffic "retransmissions."

My question is, are these logs "sufficient" to determine that the problem is caused by Check Point?
Is it possible to have a list of preliminary steps to review, with an intermittent problem in phase 2 of a VPN?

Thank you

0 Kudos
4 Replies
the_rock
MVP Platinum
MVP Platinum

 Just regular VPN debug, I would say.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Debug I meant buddy:

-vpn debug trunc

-vpn debug ikeon

-generate some traffic

-vpn debug ikeoff

Check vpnd* and ike* files in $FWDIR/log dir

Best,
Andy
0 Kudos
Lesley
MVP Gold
MVP Gold

You have to test if either the vpn is unstable or only the voice traffic so you can exclude stuff. Try to send different traffic then voice to the same destinations and check when voice does not work if other traffic does. Then you know where to search.

For debugging vpn I would use traffic logs. So check from and towards the remote servers but also remote peer ip. VPN debug is second option with ike viewer 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
the_rock
MVP Platinum
MVP Platinum

That approach makes sense, lesley.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events