- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi,
We just set up a VPN community for both CheckPoints for two remote sites.
Both CheckPoints are managed by the same SMS.
We find that even we configure the permanent tunnel for the community and install the policy package for it to both CPs.
The site to site VPN between CheckPoint just won't bring up automatically after reboot
Now, we have to get the Smartview and manually reset the Tunnel to bring it up...
How to fix this?
By the way, we have another three VPN tunnels' communities connecting to Fortigate and PaloAlto, and no the same issue was found...
What version/JHF?
What messages appear in the firewall logs?
Anything odd in $FWDIR/log/vpnd.elg?
What version/JHF?
the latest.
What messages appear in the firewall logs?
Seems no error?
I will just reset / reinstall the policy package then the VPN will up again,
Anything odd in $FWDIR/log/vpnd.elg?
Nope.
Ok, so if its brand new community, we know for sure it never worked before...phoneboy made a good point, usually vpnd* files in $FWDIR/log would give some indication about possible failures...have you tried running vpn debug ikeon and vpn debug ikeoff when this occurs and then examine ike.elg file?
The latest version is R81.10 which doesn’t have a JHF yet.
Is this what you are running?
If not, please state the precise version/JHF you are running.
Might want to look at the general VPN debug steps here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
In General, the more information you provide, the more likely we can help you.
How to check the version/JHF?
cpinfo -y all from expert mode
This command can not be used for SMB model.
No "-y"
For SMB, you can see the exact version and build in the WebUI, which should have been provided at the beginning of this thread.
In general the more information you can provide us about your environment, the easier it is for us to help you.
The general VPN debugging SK I linked to earlier should still be helpful on SMB.
See also: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Version:
1570 GW: R80.20.25
Which Build, 992002136 ?
I would suggest to involve TAC !
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY