- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello
I am facing a strange issue , one of my IP from the DC server is not able to communicate to the branch side. From the branch side the DC server IP is reachable.
I am getting the attached error " Encryption failure : Error occurred and rejected category: IKE failure"
Did anyone came across similar issue.
I have other IPs from the datacenter which is communicating to branch site without any issues.
Verified the Tunnel is up , Policies are in place, renegotiated the tunnel
OS version : R81 Take 65
Ok, so you are saying that vpn tunnel shows as up? If so, is this only traffic within it that is failing?
Andy
Yes, The tunnel is up and the traffic is passing without any issue for all other IPs.
For a specific IP i am getting the error. The strange part is the Server IP is reacheable from the branch.
There are no policy blocking the traffic.
Is there any specific debug that i can run to understand the reason for the block.
There is, follow below, you can leave it on for hours.
from expert mode:
vpn debug trunc
vpn debug ikeon
-generate traffic for problematic IP (s)
vpn debug ikeoff
Get ike.elg and vpnd.elg files from $FWDIR/log directory from fw and review to see if that IP gives any relevant info. Based on all you told us, to me logically, sounds like there is something with that server thats an issue and not vpn itself.
Just my 2 cents.
Andy
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY