Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LostBoY
Advisor
Jump to solution

R81.20 IPSEC Tunnel with Zscaler

I setup an IPSEC Tunnel in Fortinet FWs with Zscaler and it works fine. Now i am trying to do the same in a similar environment with CP 81.20 Cluster.IPSEC tunnel is not working and one problem i noticed is that once i enable the VPN Community i no longer can ping Zscaler endpoints with which the tunnel needs to be stablished. They ping perfectly fine from the GW when i remove the CP CLuster from VPN Community.

Is this expected behaviour in Checkpoint ? Shouldnt the endpoints be reachable even if they are part of the community ? is there any other step i need to do in order to reach the Zscaler endpoints.

Thanks

0 Kudos
1 Solution

Accepted Solutions
LostBoY
Advisor

Thankfully i figured out the problem..as it turned out NAT-T is enabled by default on VPN domain.

As my Cluster isnt behind any NAT device it was unable to negotiate ike phase 2 with NAT-T on.. as soon as i turned it off Tunnel was established successfully.

Thanks to everyone who replied to this topic.

View solution in original post

(1)
6 Replies
the_rock
Legend
Legend

You may want to do captures or zdebung to see why it fails, but sounds like it could be one of the scenarios from below sk.

Andy

https://support.checkpoint.com/results/sk/sk108600

LostBoY
Advisor

I m trying to find the scenario which is relevant to me but one thing i dont understand is why i am not able to ping the zscaler endpoint once i put my cluster in the vpn community. 

0 Kudos
PhoneBoy
Admin
Admin

I presume you set this up per: https://support.checkpoint.com/results/sk/sk174848?

0 Kudos
LostBoY
Advisor

Yes..i followed this precisely

0 Kudos
LostBoY
Advisor

Thankfully i figured out the problem..as it turned out NAT-T is enabled by default on VPN domain.

As my Cluster isnt behind any NAT device it was unable to negotiate ike phase 2 with NAT-T on.. as soon as i turned it off Tunnel was established successfully.

Thanks to everyone who replied to this topic.

(1)
the_rock
Legend
Legend

Good job ✔👍

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events