Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Renjith_M_P
Contributor
Jump to solution

unknown traffic from VPN blade

Hi All,

could you please explain why VPN is initiating traffic to an unknown destination.(SC attached)

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

Your firewall is properly blocking it, there is nothing to be concerned about.  The attacker isn't going to get anywhere.

You can see the owner of the netblock sending these IKE requests here:

https://wq.apnic.net/static/search.html?query=164.52.36.247

I suppose you could try contacting the abuse email for that netblock, but in my experience with the specific country involved here you are just wasting your time.  It could also just be some kind of misconfiguration on their end but I highly doubt it.

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

4 Replies
G_W_Albrecht
Legend Legend
Legend

This is a rather nice wish - but only you do know what is configured here ! The peer GW must be included in a VPN Community, otherwise, no key install will be sent. At least, this VPN is not coming up, so if you do not want it, you could even leave it this way 😎

CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Timothy_Hall
Legend Legend
Legend

Based on the screenshot, your Check Point firewall is not the one initiating.  Your firewall is sending a response to 164.52.x.x who attempted to start an IKE Phase 1 negotiation with you; the full content of the sent notification is not shown in your screenshot but it is probably "Invalid ID".  This response is sent by a Check Point firewall when an unknown peer/IP address attempts to start a VPN negotiation; in a site to site setup VPN peer IP addresses must normally be known ahead of time.

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
Renjith_M_P
Contributor

Hi @Timothy_Hall ,

yes, that is my doubt. a VPN traffic is initiated to check point from an unknown IP which is not configured in my device, traffic got rejected by the device but after that a response is sending as key install. details are in attached screen shot. what kind of behavior is this.

we are getting lot of request from this unknown IP to some of the internal IP's. service is IKE ( Screen shot attached). we don't have any DAIP for this setup. as a precautionary  measure i have created an object and blocked this source IP in the policy.

is it a kind of attack. if yes how do i identity which device is originating this traffic and any helping hand from inside object.

Thank you for response.

0 Kudos
Timothy_Hall
Legend Legend
Legend

Your firewall is properly blocking it, there is nothing to be concerned about.  The attacker isn't going to get anywhere.

You can see the owner of the netblock sending these IKE requests here:

https://wq.apnic.net/static/search.html?query=164.52.36.247

I suppose you could try contacting the abuse email for that netblock, but in my experience with the specific country involved here you are just wasting your time.  It could also just be some kind of misconfiguration on their end but I highly doubt it.

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events