- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello.
Can someone advise exactly how Check Point stand with GRE support?
I understand they can’t build or terminate GRE tunnels, but can they pass the traffic through?
There is a VPN between 2 Cisco Routers who are trying to establish a tunnel however it isn’t coming up. After discussions, I realised they are using GRE over IPSEC VPN.
I have now concluded that this is the reason why it’s not coming up.
Any suggestions?
Hi, Static NAT is set up on the firewall.
500 and 4500 allowed through the firewall.
no drop logs.
all I see is router A sending UDP 500 to router B and vice versa.
Obviously the VPN is never getting past phase 1.
are you saying GRE traffic should pass without an issue then?
I will ask them to add the commands to the Cisco routers below.
FYI ipsec on cisco defaults to NAT-T enabled. This has been the default for a very long time.
show run all
will show hidden defaults.
I had a similar issue on a GRE tunnel that was not coming up between 2 GRE routers, that were communicating over an IPSec tunnel.
Creating a specific rule that allowed the GRE service (nevertheless there was an "allow any over IPSec" rule below it) solved it.
Hi Jochen,
Hope you are doing well, i have a similar setup with the customer, where he has Mikrotik routers in DC doing gre over ipsec with microtik on the remote sites.
did you connect the cisco router behind the checkpoint on lan or you directly connected them, could you share the rule and NAT config for the same as well ?
Hi Karan,
The routers were connected at both sides behind the LAN port of the CP FW's. Between both CP's, an IPSec tunnel was implemented. Then, within the IPSec tunnel, a GRE tunnel between the routers was build (without NAT etc). In order to fix the gre issue, an explicit rule with service "gre" accept was created.
KR, jochen
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
11 | |
6 | |
6 | |
6 | |
6 | |
6 | |
4 | |
3 | |
3 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY