- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear All,
Good day,
The past 6 months I have been experiencing an issue with a VPN tunnel I have between two offices, Site A has a Checkpoint 1550 (R81.10.17 ) and site B has a Fortigate 80F (7.4.5 Build 2702). Users from site A need access to site B in order to access programs and folders they need(nothing special). Even though I have checked numerous times the configuration on both machines, and even though the tunnel appears to be active from both sides, I can't reach site A from site B and vice versa(ping, traceroute, RDP). The funny thing is, is that the problem fixes itself some of the times, either randomly or due to a reboot of the machines. I am not that familiar with firewalls in general, and that is why I came here to seek assistance from the experts. I can provide you with any information you might need, that will lead to a permanent solution.
Awaiting yours.
There should be corresponding log entries on both ends that correlate with the drops, which I suspect are caused by misconfigured settings on one or both ends.
This behavior, absent further details, sounds like the various timers are set differently on both ends; they need to agree.
General VPN debugging on the Check Point side: https://support.checkpoint.com/results/sk/sk180488
Common issues with Check Point and other vendors: https://support.checkpoint.com/results/sk/sk108600
Many thanks for the prompt reply, what logs would assist you? From which module should I draw the logs?
Hey @Dim134267
We are here to help, no worries. I had done many FGT to CP tunnels, so Im fairly familiar on that subject. For starters, lots of people may just leave fgt side as universal, 0.0.0.0/0. Is that how its configured? What about cp end? Is tunnel management in vpn community set per subnet, gw or host?
Any relevant logs you can share?
Andy
Many thanks for the prompt relpy.
Where do I check if the fgt or the cp side is universal?
Also, regarding the tunnel management where can I see how it is configured?
Finally, what kind of logs would assist you?
👏
I have fully licensed Fortigate in the lab, so can test bunch of this stuff.
Andy
@Dim134267 : Your description sounds familiar. The issue fixes itself when the other side establishes the VPN tunnel. Looks like only one of your VPN gateways is able to establish the VPN successfully.
I've created a HowTo for proper VPN configuration between a Check Point and a FortiGate. Enjoy.
Dear Danny,
Many thanks for the detailed answer, I will try to follow the instructions you have given and let you know of the result.
But the issue I have is that I don't know how to access the Smart Console, I only have access to main hub of the FW. Is it the same?
@Dim134267 : I see that you are locally managing a Check Point SMB 1550 Appliance via its Embedded Gaia WebUI. That's not the same as centralized management via SmartConsole, so you'll need to adopt the shown steps to your local WebUI configuration.
Dear Danny
Below you will find the current configuration of the firewalls.
From the WebGUI I don't know what logs to download, in order to send you the file and assist further.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 19 | |
| 14 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY