- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am facing a problem with PFsence site to site VPN. The config. matched on both sides. same everything and the encyption domains.
Although the problem, the S2S VPN will work but after a while it stops. The only way to make work again is by resting the VPN then it works again.
I tried to debug the issue found some weird things. Like many SAs peer connection and it keeps adding till the connection stops.
After reset start all again. also the IPSEC phase 2 many inbounds and outbounds . Any ideas what to check or where to start ?
Looking at the debug, it is failing on "Create Child SA". This appears to be a larger tunnel with 16 IKE SA's from your screenshot.
What does your encryption domain look like, are these all subnets? How often are you re-keying Phase2? What version are you running on?
The encryption domain has multi subnet, Client VPN net and some pcs.
Renegotiate phase 2 : 3600 Sec.
FW : R81.10 - Build 062 Take 139
You don't need those hosts in the encryption domain, the 10.148.8.0/22 encompasses them, I would remove them.
Your screenshot shows 16 SA's, based on the encryption domain you provided, I would only expect 8 after removing the hosts and 12 before, that makes it seem like the tunnels are not building properly.
I would do a "vpn tu tlist -p <IP of PFsense>" from the GW CLI to validate all of the subnets are building properly, because that seems like the culprit.
actually it does not matter what we do it will keep adding SA's till i have to reset the VPN to make it work again. I see by other VPNs only one SA's although the ED has many networks. I dont know how relevant is that..
To me, it looks like the subnets are not defined properly on the PFsense side.
Looking back at the debug you posted, the failed "Created Child SA" is an inbound request, as in the PFsense is sending a subnet the Check Point does not like. You should be able to see those in the "TSi" and "TSr" fields.
Under the VPN community you have SA per host, per subnet or per gateway?
What version you running? share cpinfo -y all output from relevant vpn gateway
How often tunnel breaks? Does this match either the p1 or p2 timer?
It is per Subnet,
Ver : FW : R81.10 - Build 062 Take 139.
I had to restart it every day cuz it works for a couple of hours then it does not work till i reset the VPN
Check what Casey typed before, you have to check further into the debugs:
"Looking back at the debug you posted, the failed "Created Child SA" is an inbound request, as in the PFsense is sending a subnet the Check Point does not like. You should be able to see those in the "TSi" and "TSr" fields."
Also regarding software, search here for '"VPN' and check if any bugs match. You should check everything above take 139.
No ipsec sa clearly tells us its phase 2 issue. How do you have tunnel management seclected? per host, subnet or gateway? If you arew only using subnets, then subnet should be selected, but if its combo of both hosts/subnets, then select per gateway.
Also, do vpn domains match properly on both ends?
Andy
it's actually per Subnet. It not the first time i add hosts and subnets to ED with VPN Sharing per subnet. It always worked fine. I dont know also if this is an issue on the other side the Pfsense. Although it is worth to try .
Well, if it worked before, maybe you just got lucky, but technically, if its combo of hosts/subnets, it should be set per gateway.
Andy
Now it looks different :
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY