- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: site to site vpn tunnel
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
site to site vpn tunnel
Hello Team,
I have a query. today my one of the working site to site vpn tunnel went down. while troubleshooting i found that phase 1 was down and it was getting failed on main mode packet 5. So i have reset the pre-shared key. And the tunnel came up. So my query is without making any changes what could be the possible reason of this changes.
there were no changes made on the gateway
OS version. R80.20
jumbo hotfix take_118
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That means either the pre-shares secret was wrong OR there is some other issue that was solved by doing a policy push.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
tunnel is between checkpoint to checkpoint
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IKE Phase 1 packet 5 is where the peers switch over to NAT-T if intervening NAT has been detected between them, did that happen?
If the shared secret was really wrong you should have seen a "payload malformed" message on one side or the other, if you didn't see that then the PSK was not the problem.
By default pushing policy clears all IKE Phase 1 SAs and forces them to renegotiate which is probably what fixed the tunnel.
Check that your IKE Phase 1 and IPSec Phase 2 lifetimes match.
Since you say your peer is another Check Point, if this keeps happening I'd recommend enabling Permanent Tunnels on both ends so that the VPN will recover itself within 60 seconds or so should this situation happen again.
CET (Europe) Timezone Course Scheduled for July 1-2
