- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi,
We are hitting this limitations in Maestro architecture :
-------
-------
We are redirecting the remote access traffic to a site to site VPN.
Client VPN <====Remoteaccess===> 80.30SP< ====SITE 2 SITE VPN======> Azure GW <--VNET--> Server
SG don't like and break TCP session. It's not supported yet, there is an RFE coming.
However do you have an idea as a workaroud?
We were thinking NATting the remote access traffic behind a pool before sending it to the VPN ...
Thanks for your help
JB
i got the answer from Check Point, it's not supported on 80.30SP . A hotfix is needed with RFE...
sk147033
Thanks
Hi @jeanbruno
Very interesting. We also have a customer with a migrated Maestro installation with a setup similar to this you described.
We see packet drops after 50s (TCP End Timer value) on the packets coming from the server back to the client.
You can see it with "g_fw ctl zdebug drop | grep <hidenat-ip-fw>"
Strange is that the drops are intermittent.
Workaround for now is a incoming fw rule which allows any traffic from server to vpn-client.
Do you have the same behavior at your installation?
Thanks,
Peter
Hi Peter,
What version are you running?
I got bad TCP séquences,first SYN not seen. UDP seemed ok. i didnt do zdebug drop cause TAC confirmed the not supported topology.
Client to Site Traffic over Site to Site VPN Tunnel is supported only in 81.10 according to CP.
Hi @jeanbruno
Customer is using R80.30SP with JHF which exactly I cannot see since I have no access to the fw right now.
Ok maybe same troubles than us. If you want full VPN support on 80.30SP you need to contact your sales CP and ask for the hotfix though RFE
And it can be installed only on top of Jumbo take 47.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY