- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
After upgrading the central firewall to R81.10, the tunnel stays in phase-1. There is status information below.
In some places, it is written that I need to create traffic. Does anyone have any information?
Central FW: version R81.10 Hotfix: 110. Cluster
Branch FW: 1530 appliance, version: R80.20.30
VPN tunnel monitor log:
Tunnel centralfw<=> sideA
State Up - Phase1
Community sideAVPNSite
Type Regular
From sideA
To centralfw
State Up - Phase1
Peer IP X.X.X.14
Next Hop IP N/A
Interface N/A
Source IP N/A
Link Priority Primary
Prob State N/A
Peer Type Regular
UDP Encapsulation None
MEP participants
Thanks for your replying.
Hi,
My problem has solved. I checked all VPN comunity configuration. I see sideA WAN IP address is wrong. when change it true IP address tunnel is connected and status up.
Is this configured as permanent tunnel?
Andy
Hi,
My problem has solved. I checked all VPN comunity configuration. I see sideA WAN IP address is wrong. when change it true IP address tunnel is connected and status up.
Good job!
Kind of strange, after upgrade it is not working.
But after your checking, found out to be wrong configuration?
Hi @just13pro
Yeah, that is strange. I wrote that it was solved briefly due to workload. I will now give a detailed explanation.
2 months ago, we made an ip change in the region where we used the 1530 series device. After this change, 1530 was reconnected to the central management according to the new WAN IP address (with SIC.)
After so much time passed, we realized that there was no ping from the center to the sideA. that not only ping but also IP phone etc. nothing works.
When I checked, I saw that it was so, but ping is coming from sideA. When I looked at the logs, I saw these logs.
@;65686661;[cpu_0];[fw4_1];fw_log_drop_ex: Packet proto=1 10.99.5.20:2048 -> 172.16.0.10:16972 dropped by fw_ipsec_encrypt_on_tunnel_instance Reason: No error - tunnel is not yet established;
When I monitored the tunnel, I saw the above output (tunnel monitoring output). I realized that the tunnel was one-way UP. Then it occurred to me to check the community settings. (I think this was the first thing I should have done. sometimes this happens unfortunately. ) There was no problem with the community settings. When I looked at the 1530 firewall object, I realized that the WAN IP address was different. After changing the WAN IP address to the current one, the tunnel was up.
I don't understand how the tunnel worked for so long and ping, IP phone continued to work. As a result, the process worked like this. as a result, it is a fact that there is a STRANGE situation. or if there is an explanation, if anybody writes and enlightens this situation, I will learn something.
Thanks..
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY