Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DaoSon
Explorer

Not Up, VPN site to site with NAT

I have the vpn site to site between checkpoint and fortigate as below ( NAT only at checkpoint )

I have referenced and configured  many guides but tunnel still does not work.

The log on the Fortigate reports that phase 2 is failing ( when no use NAT , everythings is good )

Pls, help me this issue ( nextime, we will swap ASA to checkpoint )

My device runs os 81.20

My configuration is as pictures below.

Thank,

 

 

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

It's far better to post screenshots inline in the editor rather than as attachments, FYI.

The fact it works without NAT occurring on the Check Point side suggests the Fortigate isn't configured correctly to account for the NAT addresses.

0 Kudos
Lesley
Authority Authority
Authority

8.png -> change from host to subnet. if this not works change to gateway. Both changes require policy push. 

topo i cannot read so cannot double check encryption domains / nat table. Also make sure disable nat option is disabled in the vpn community. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

Apart from what guys said, make sure below are set to FALSE on CP side from guidbedit.

Andy

ike_enable_supernet

ike_p2_enable_supernet_from_R80.20

ike_use_largest_possible_subnets

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events