- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
someone had this problem.
I have one VPN between Check Point R80.40 and Aruba..
The symptoms are .. duplicate IKE phase 1 in the Checkpoint and some times VPN goes down.
Duplicate IKE Phase 1 isn't exactly a problem depending on the precise configuration.
In any case, you'd probably need to debug the issue further: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Error 404 on link
That sk is not available anymore - try the following and the included links:
https://support.checkpoint.com/results/sk/sk40114
The SK that replaces the one I linked to previously is: https://support.checkpoint.com/results/sk/sk180488
Never really set up tunnel between CP and Aruba personally, but can ask one of my colleagues who is really good with Aruba to see if there are any known settings/issues to be aware off. Did the tunnel ever work right or you had problem since the beginning? As @PhoneBoy said, debugging this is a really good idea on CP side.
This is what I usually do, super easy process...on CP fw, rune below commands from expert mode:
vpn debug trunc
vpn degug ikeon
generate some traffic
vpn debug ikeoff
Get vpnd.elg file, as well as ike,elg from %FWDIR/log
Use ikeview utility (free to download off google) to examine ike.elg file and look for the entry for Aruba public IP in there and see whats happening. Also, vpnd.elg can give some insights as well.
We are facing IPsec vpn tunnel unstable issue its down and up automatically every half a hour (don't make any changes on firewall)happening checkpoint to Prisma cloud tunnel
till now we don't find anything what is the issue
You'll need to debug it: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
See also scenario 4 and 6 in: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Tunnel going up/down like that is likely a mismatch between the various timer settings.
did you fix the issue?
Hello, my friend.
The file that should be obtained after the debugging you suggest, for the IKEv2, what would it be?
I understand that it is not the same as the one in this post, right?
Regards
Ola bro,
Just do below from expert:
cd $FWDIR/log & ls -lh *ike
It will show you all ike files, including ikev2
Andy
Hi, Andy.
Is this "file" the one to be read, in the IKEView?
File -> ikev2.xmll
Does this file "show" you both Phase1 and Phase2, or only Phase1?
Cheers.
I believe phase2 only, but could be mistaken.
Andy
IKEv2 doesn't have quite the same phase 1 > phase 2 structure IKEv1 has. ikev2.xmll has all of the IKEv2 negotiation information.
Hello,
The file -> ikev2.xmll has the same content as the file "legacy_ikev2.xmll", at least for Troubleshooting????
I can use any of the 2 without any problem?
Greetings.
I believe they are different, legacy_ike2.xmll is phase 1 for IKEv2.
You can use IKEView to open the file search the SK for the IKEView software.
Thats sounds right.
Not sure this relates, but could this be related to IKEv2 narrowing?
If you do a 'vpn tu tlist' it should show the tunnels; your looking for the wording 'narrow' or 'eclipsed'.
Hi all,
i'm experience the same problem on R81.10 T79 with third-party peers:
not all traffic inside vpn is affected
Moreover, i have this drops:
Moreover, i tried to clean tunnel information by vpn tu but the command is so bad, information continues to be shown in vpn tu tlist, and i suspect that still they are there traffic is affected
i tried to clean some tables, meta_sas, local_meta_sas, ikesa_out_spi, but no way on how to delete a single entry
Is it all 3rd party peers or just random ones? Can you give an example...any logs, screenshot?
Cheers,
Andy
just updated the post, sorry lost some information after the publish
What version are you on?
Like i said i'm on R81.10 T79
Sorry mate, missed that, my bad. I have R81.20 lab with few tunnels, so let me do some digging and see if the issue is there. Is this something new that happened or how long has it been a problem?
Andy
new installation, the customer started to move VPNs from another device
Maybe if you can give exact commands you ran, I will verify in the lab...so far, dont see any issues like that.
Andy
fw tab -t ikesa_out_spi -x -e (allvaluedisplayed in fw tab -t ikesa_out_spi )
I dont see any errors when running those.
Did you ever resolve the instability challenges between Prisma Cloud and your Checkpoint gateway?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
16 | |
12 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY