- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have the vpn site to site between checkpoint and fortigate as below ( NAT only at checkpoint )
I have referenced and configured many guides but tunnel still does not work.
The log on the Fortigate reports that phase 2 is failing ( when no use NAT , everythings is good )
Pls, help me this issue ( nextime, we will swap ASA to checkpoint )
My device runs os 81.20
My configuration is as pictures below.
Thank,
It's far better to post screenshots inline in the editor rather than as attachments, FYI.
The fact it works without NAT occurring on the Check Point side suggests the Fortigate isn't configured correctly to account for the NAT addresses.
8.png -> change from host to subnet. if this not works change to gateway. Both changes require policy push.
topo i cannot read so cannot double check encryption domains / nat table. Also make sure disable nat option is disabled in the vpn community.
Apart from what guys said, make sure below are set to FALSE on CP side from guidbedit.
Andy
ike_enable_supernet
ike_p2_enable_supernet_from_R80.20
ike_use_largest_possible_subnets
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY