- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Issue configuring VPN with VTI between Checkpoint ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Issue configuring VPN with VTI between Checkpoint and Azure
Hello,
I am trying to make work a VPN tunnel between a Checkpoint Firewall (R80.10 Tale 259) and Azure but I am getting the following error:
Notify Payload
Critical: No
Length: 40
Next payload: Notify
Protocol: 0
Type: Quick Crash Detection Token
ndata: 1c 61 db 62 ad 9a 5b 98 3f 64 1b d1 c8 69 a2 b0 6f 0d c5 79 79 94 6c 15 02 3b 6a 16 df 1f be 43
spisize: 0
And then:
Notify Payload
Critical: No
Length: 8
Next payload: None
Protocol: IKE
Type: Invalid IKE SPI
spisize: 0
It is weird because Phase 1 and Phase 2 negotiate look ok at the begin but then I start to receive these messages and the tunnel does not get established.
My config parameters:
https://community.checkpoint.com/t5/Remote-Access-Solutions/Azure-Site-to-Site-VPn-fail/td-p/16102
I have tried to modify the timers following some Azure and Checkpoint documentation but without success. Adny idea about what coould be happening? Thank you very much. Best Regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
General debugging information for VPNs are here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You ever get a resolution on this? We're seeing this same kind of error frequently with a Palo Alto peer on the other end of our tunnel. Just curious.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Would also be interested in the solution. Got the same issue here as well with a cisco device on the other end.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anybody who had this with ASA and resolved it ? Same issue here R80.40.
worth pointing its IKEv2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm getting the same thing with R80.40 <> Azure Cloud VPN, has anyone found a solution to this? The SK listed above has also been deleted.
