Hello All,
I am having an issue with the Traditional mode VPN not coming up when we replace our old 3200 appliance on R80.20, with a new one and install R81.10 with the exact same config. this is not in cluster mode, its just an active and a cold spare gateway.
Description:
Check Point 3200 appliance (cold spare) was prepared with R81.10 fresh install and the latest JHF installed.
It replaced the old 3200 appliance which had R80.20 and Traditional mode VPNs in the policy.
SIC was established and after policy installation (no changes were made to the policy), the VPN does not come up.
Local traffic capture shows packets being encrypted and routed through the correct interface.
Remote peer (gateway managed by the same SMS and on R80.20) capture does not show any packets being received at all. Nothing in logs and zdebug drop.
Local VPN debug (ike.elg) does not populate anything after starting the debug using “vpn debug ikeon”
Remote VPN debug (ike.elg) shows only packets before the migration.
When we switch back to the old firewall, VPN comes up fine after SIC reset and Policy install.
Not sure if the traditional mode VPN configuration is supported on R81.10, but I did not find any such statement. so there must be something that we are missing. may be vpn configuration file that has been edited?
Management Server is on R81.10.