- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I've worked with a cluster running R81.20 Take 119 which has a single IPSEC to an interoperable device which has been working for years.
Today, I wanted to manually reset the tunnel for some checks as we changed some topology and so on.
I used the well known vpn tu and the Smartview with the "Reset Tunnel" button.
Nothing happened. In the logs, I didn't see the Key Install events except those agreed by the community timers.
In CLI, the tunnel times remained those as well then checking the list of established tunnels.
I tried multiple times, using either vpn tu with option 7 or vpn tu del x.x.x.x and so on, same thing, the VPN doesn't reset and there are no logs, traffic doesn't lose a single packet.
Now it's not a huge issue as it works and I can wait the next interval for checks, but I wonder if it would be a known issue.
According to R&D, it should work and has been tested by QA to function properly in R82.10 (not yet released).
This may indicate a degradation introduced by a JHF or something specific to your environment.
Therefore, I recommend opening a ticket with TAC.
I haven't found "vpn tu del <ip>" to really do the job, either. However, "vpn tu del all" WILL delete everything.. but it's EVERYTHING. If you can afford that result, then go for it. For those of us with dozens of VPN sessions, that's a bit aggressive (although I have done it at acceptable times).
It's the first time I observed this command doing just nothing at all. This is quite inconvenient when trying to make controlled resets of VPN with third parties.
I tried first command once and it did work. vpn tu del all definitely works. I find below ones usually work fine:
I've sent your post to relevant owner in R&D.
Will update when I have heard back.
Thanks
Before you run vpn tu option 7 do you see any ike/ sa id for the vpn tunnel at all? If there are none there is nothing to reset and could indicate a different issue. Sounds obvious but I felt for this once 😉
vpn tu list shows all associations, as well as dedicated options in vpn tu, I checked independently phase 1 and 2 and everything's there. I mean, the tunnel works.
Option 7 and vpn tu del didn't do anything and the tunnel rekeyed at the agreed timers.
Maybe one of these features which stopped working after a given version is installed, like cppcap for instance.
According to R&D, it should work and has been tested by QA to function properly in R82.10 (not yet released).
This may indicate a degradation introduced by a JHF or something specific to your environment.
Therefore, I recommend opening a ticket with TAC.
Thanks for taking the time to investigate this.
I upgraded another environment to R81.20 T119 and didn't experience this issue, so very likely something local to that implementation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY