- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Site to Site VPN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Site VPN
We have facing the Error in Site to Site VPN Tunnel,
Scenario is : We have Two Site , Site A and Site B, Both the Site we have installed Checkpoint Firewall Device With HA & Both Site Management server are Same is located on Site A.
When we are Trying to Establish the VPN Tunnel Between Both Site , Then Site B Device is Stop the Responding and Policy Installation is Goes to Failed , ( Means That remote Site Device is Stop to Communicate With Management server ) Note : we have added Remote Customer With Public Ip Address In Our Exiting Management server .
Regards
KP
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you really need to read that guide mate:
https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/htm...
and/or
https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/htm...
hope it helps 🙂 if not - shout loud here!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you follow Site to Site VPN Administration Guide R80.30 ? Which kind of VPN Community is used ? Please check that the Management Connections still go over internet when VPN is enabled (see excluded services!).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you really need to read that guide mate:
https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/htm...
and/or
https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/htm...
hope it helps 🙂 if not - shout loud here!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you follow Site to Site VPN Administration Guide R80.30 ? Which kind of VPN Community is used ? Please check that the Management Connections still go over internet when VPN is enabled (see excluded services!).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This will be because as others stated and suggested is that you have a Site to Site VPN between the 2 sites.
When you establish a Site to Site VPN between Check Point Gateways/Clusters then it includes the External Interfaces in the Encryption Domain.
As such when the Management Server that is likely part of Site A Enc Domain tries to communicate with the Site B Cluster then tries to go over the Site to Site VPN.
Easiest way I find to solve this is with
To exclude the Site B Gateway and Cluster IP from the VPN.
Will be the $FWDIR/lib/crypt.def file that edit if all on the same software version
Is the SK article that states what the location of crypt.def file is depending on Management and Software version.
This ensures that the Check Point Management Traffic does not attempt to go via the VPN and also that any Platform Management, ie WebUI, SSH etc also does not go over the VPN.
This traffic is all encrypted anyway and means that if the VPN is down then can still connect.
