- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
i tried to bring up a ikev1 tunnel with a ASA but no luck.
Essentially, the encryption domain is:
Local: 172.16.0.0/12 Remote: 192.168.151.0/24
but after the tunnel is established there is no traffic and this is likely the main reason:
basically it seems the opposite problem about the famous supernetting
any suggestion?
R81.10 take110
thanks
What does an IKE debug say? That's the final word in which side is doing the wrong thing.
it says that CP is going to propose the smaller subnet....
i already saw this behavoir in other deployment with asa
sorry forgot to mention R81.10 take110
set below values to FALSE in guidbedit, push policy -> test
Andy
ike_enable_supernet
ike_p2_enable_supernet_from_R80.20
ike_use_largest_possible_subnets
I seen that sk before...its good reference, for sure, though I never had that sort of problem with any customer.
Andy
sounds good... i will investigate, already seen that sk but not considered until now....ty
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY