- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
March 11th @ 5pm CET / 12pm EDT
AI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hello.
Can someone advise exactly how Check Point stand with GRE support?
I understand they can’t build or terminate GRE tunnels, but can they pass the traffic through?
There is a VPN between 2 Cisco Routers who are trying to establish a tunnel however it isn’t coming up. After discussions, I realised they are using GRE over IPSEC VPN.
I have now concluded that this is the reason why it’s not coming up.
Any suggestions?
Hi, Static NAT is set up on the firewall.
500 and 4500 allowed through the firewall.
no drop logs.
all I see is router A sending UDP 500 to router B and vice versa.
Obviously the VPN is never getting past phase 1.
are you saying GRE traffic should pass without an issue then?
I will ask them to add the commands to the Cisco routers below.
FYI ipsec on cisco defaults to NAT-T enabled. This has been the default for a very long time.
show run all
will show hidden defaults.
I had a similar issue on a GRE tunnel that was not coming up between 2 GRE routers, that were communicating over an IPSec tunnel.
Creating a specific rule that allowed the GRE service (nevertheless there was an "allow any over IPSec" rule below it) solved it.
Hi Jochen,
Hope you are doing well, i have a similar setup with the customer, where he has Mikrotik routers in DC doing gre over ipsec with microtik on the remote sites.
did you connect the cisco router behind the checkpoint on lan or you directly connected them, could you share the rule and NAT config for the same as well ?
Hi Karan,
The routers were connected at both sides behind the LAN port of the CP FW's. Between both CP's, an IPSec tunnel was implemented. Then, within the IPSec tunnel, a GRE tunnel between the routers was build (without NAT etc). In order to fix the gre issue, an explicit rule with service "gre" accept was created.
KR, jochen
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 32 | |
| 18 | |
| 13 | |
| 12 | |
| 10 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 |
Fri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY