- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Site-To-Site connectivity and application acce...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site-To-Site connectivity and application access
Hi
After migration to checkpoint firewall 5900 (R80.10) at two geographically separated sites, network access from one site to another does not work, when the tunnel terminating on the edge routers of the two sites is in place. But as soon as the tunnel is removed between the two edge routers network access is enabled and applications across the sites become accessible.
Kindly help to fix the issue.
Thanks
BS Bhatia
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I'm understanding this correctly, you have routers between the two Check Point gateways doing an IPSec tunnel between the two sites, correct?
Generally, that's going to cause MTU issues.
What I suspect is happening is the following:
- Large packet comes through Gateway A with the Don't Fragment Bit set
- When that large packet hits the router and it tries to go through the IPsec tunnel, the packet + IPsec header will be larger than the MTU
- The router is sending back an ICMP message back saying "Fragmentation Needed" which is getting dropped at the firewall
The end result is traffic doesn't work.
You can easily confirm all of the above with tcpdump or similar.
The solution is pretty simple: configure the access policy to allow ICMP Fragmentation Needed packets from the router.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Bhatia,
Would you mind sharing with us a basic diagram of your topology?
Many thanks.
Nicholas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The topology diagram is attached as file "Diagram.docx".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I'm understanding this correctly, you have routers between the two Check Point gateways doing an IPSec tunnel between the two sites, correct?
Generally, that's going to cause MTU issues.
What I suspect is happening is the following:
- Large packet comes through Gateway A with the Don't Fragment Bit set
- When that large packet hits the router and it tries to go through the IPsec tunnel, the packet + IPsec header will be larger than the MTU
- The router is sending back an ICMP message back saying "Fragmentation Needed" which is getting dropped at the firewall
The end result is traffic doesn't work.
You can easily confirm all of the above with tcpdump or similar.
The solution is pretty simple: configure the access policy to allow ICMP Fragmentation Needed packets from the router.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks a lot for the solution.
After reducing the MTU on firewall interface connected to the edge router at both the ends (to 1320), network access across the sites is working fine.
