Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
eltadmin
Explorer

Continuous Email Notifications Regarding VPN Tunnel Down

Hello community,

I wanted to share an issue we've encountered after updating the (we have 5x Quantum Spark 1550 Appliance) firewall firmware directly from version R80.20.15 (992001653) to R81.10.08 (996001683). We've set up a IKEv1 Side-to-Side VPN between Side-A (Cisco Meraki MX100) and Side-B (CheckPoint 1550). These are brand new devices replacing the old Cisco RV160. During the initial deployment with version R80, we did not receive any notifications regarding VPN issues. However, you should be aware that they were operational for only one day before we switched to R81. Also, keep in mind that I'm not very clear on what I'm doing, and until now, I haven't worked with CheckPoint.

We have 5 subnets in Encrypted Domain Network Topology 4 /24 and one /23

Post-update, we've started receiving notifications every 5 minutes regarding a VPN tunnel disruption, even though there is no actual packet loss during a ping test. The notification content is as follows:

"A VPN tunnel is down: site name: sofia, from: BB.BB.BB.BB, site IP: AA.AA.AA.AA, my tunnel subnet: BB.BB.BB.BB, peer tunnel subnet: 192.168.146.0/23."

The same information is reflected in the Notifications section under System and Security Events.

Also - Quick Mode Received Notification from Peer: invalid hash information

We've meticulously verified the configuration, ensuring it's a 1:1 match on both sides. We've experimented with different configurations to rule out the possibility of conflicts, yet the outcome remains consistent with no change.

In reality, the tunnel continues to function seamlessly, maintaining uninterrupted communication. Despite this, the notifications persist. We're seeking insights or suggestions from the community to resolve this notification anomaly while ensuring the VPN remains operational.

Thank you for your assistance!

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Sounds like a bug and you should consult with TAC: https://help.checkpoint.com 

0 Kudos
Amir_Ayalon
Employee
Employee

Hi

You can open an SR and ask for a task for us to look at, or you can install a new R81.10.10 EA firmware and test if the issue happens there.

please notice, this is an EA firmeare.

thanks

http://downloads.checkpoint.com/fileserver/ID/130943/FILE/fw1_vx_dep_R81_10_10_996002688.img

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events