- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I setup an IPSEC Tunnel in Fortinet FWs with Zscaler and it works fine. Now i am trying to do the same in a similar environment with CP 81.20 Cluster.IPSEC tunnel is not working and one problem i noticed is that once i enable the VPN Community i no longer can ping Zscaler endpoints with which the tunnel needs to be stablished. They ping perfectly fine from the GW when i remove the CP CLuster from VPN Community.
Is this expected behaviour in Checkpoint ? Shouldnt the endpoints be reachable even if they are part of the community ? is there any other step i need to do in order to reach the Zscaler endpoints.
Thanks
Thankfully i figured out the problem..as it turned out NAT-T is enabled by default on VPN domain.
As my Cluster isnt behind any NAT device it was unable to negotiate ike phase 2 with NAT-T on.. as soon as i turned it off Tunnel was established successfully.
Thanks to everyone who replied to this topic.
You may want to do captures or zdebung to see why it fails, but sounds like it could be one of the scenarios from below sk.
Andy
https://support.checkpoint.com/results/sk/sk108600
I m trying to find the scenario which is relevant to me but one thing i dont understand is why i am not able to ping the zscaler endpoint once i put my cluster in the vpn community.
I presume you set this up per: https://support.checkpoint.com/results/sk/sk174848?
Yes..i followed this precisely
Thankfully i figured out the problem..as it turned out NAT-T is enabled by default on VPN domain.
As my Cluster isnt behind any NAT device it was unable to negotiate ike phase 2 with NAT-T on.. as soon as i turned it off Tunnel was established successfully.
Thanks to everyone who replied to this topic.
Good job ✔👍
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY