Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Oreoluwa
Explorer

Traffic Dropped with error failed to resolve VPN MEP gateway

Hello,

I have a site-to-site VPN connection between an on-prem Checkpoint security gateway and two AWS gateways within the same VPN community. 

We see drops in traffic passing through this VPN tunnel which impacts on prem user's experience accessing applications deployed in our AWS environment. We usually have to remove one of the AWS gateways in the VPN community before traffic gets accepted through the tunnel. 

Please advise how to resolve this.

I have also attached a screenshot of the error. 

 

 

 

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

The best way to do this with AWS is with Route-Based VPN, which shouldn't involve MEP.
See: https://support.checkpoint.com/results/sk/sk108958 

0 Kudos
Oreoluwa
Explorer

Hello PhoneBoy,

Thank you for your response. This sk looks good. However, I see a bit of the configuration requiring some settings to be done on GAIA portal - Allow import of routes advertised by AWS: and Advertise local routes to AWS. I use a VSX appliance, which does not have configurable objects on GAIA portal. Is there some other way to configure these highlighted above instead of using the GAIA portal, say using the CLI?

0 Kudos
PhoneBoy
Admin
Admin

Believe this is possible through the CLI, yes.
However, will admit I am not familiar with the exact syntax for this.

0 Kudos
Wolfgang
Authority
Authority

@Oreoluwa yes, all you need to configure can be done via clish. See Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish and Configuring IPv4 Route Redistribution to BGP in Gaia Clish 

Please note, if you use VSX you have to configure this in the environment of the correct VS.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events