- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
We have a site-to-site checkpoint VPN
We are using VMWARE HCX to migrate some workloads through that tunnel. HCX uses NAT-T to build a VPN tunnel using whatever transport is available, which in this case happens to be a checkpoint VPN tunnel, so we are tunneling NAT-T through a checkpoint VPN tunnel.
This has been working for months.
On Friday it broke after we installed the CVE patch and rebooted all the gateways.
Here is the log message "Failure preparing tunnel creation, internal error"
We opened a ticket with TAC on Friday and spoke to an engineer who said they had seen this once before, but it was fixed by an unrelated hotfix.
On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"
I don't believe this to be true.
Is anybody else running HCX over a checkpoint VPN (or any other NAT-T traffic)?
Anybody else seen this error and know the fix?
Thanks
On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"
I agree with you, Im 100% positive that is NOT true.
Is it failing on phase 1 or 2?
Andy
the checkpoint is dropping the packets so it never gets as far as phase 1
we have looked at that, but in this case default route is the route that should be used
we have just tried a different tunnel to a different site and it seems to be working so I guess it is supported after all
100% supported, it always has been. Btw, just wondering...does it make any difference if tunnel is reset from both ends? Whats the other side?
Andy
The broken tunnel is VMWARE HCX on both ends. This was working fine for weeks. We rebooted the checkpoint gateways and it stopped working. I beleieve the HCX tunnel was reset, but that is managed by a different team. We just built a new HCX mesh over the same checkpoint tunnel as the broken one, and it seems to be working. The strange thing is the checkpoint is definitely dropping traffic for the broken mesh, and passing traffic for the working mesh. Maybe something in the packet is messed up.
Can you do basic VPN debug and attach iked and vpnd files?
Andy
vpn debug trunc
vpn debug ikeon
-generate some traffic
vpn debug ikeoff
look for iked and vpnd files in $FWDIR/log dir
the checkpoint tunnels are up and always have been. we don't have any diagnostics from HCX. Anyway, it now seems it does work, apart from the original mesh.
I would say if it can be reset from that side, it may help.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 10 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY