- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Site to site VPN drops with Dynamic DNS
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to site VPN drops with Dynamic DNS
Greetings,
I'm wondering what can cause this issue, I have 2 appliances (locally managed) from Check Point 700 Appliance family (730 & 790). On both of them, there is DDNS feature enabled (because those two are DAIP gateways - don't have static WAN IP), provider is no-ip.com and domains *.ddns.net successfully point to proper dynamic IPs.
When my friends and I try to establish site to site vpn between those peers, when we put IP addresses (dynamic ones) everything seems fine. However, when we put host names instead of those IPs, tunnel won't go up.
Has anyone run into the same problem?
P.S. Other settings are default ones (authentication: pre-shared secret; encryption: default etc.)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you follow this sk: sk109048: How to create Site-to-Site VPN between 2 locally managed DAIP 1100/600 Appliances ?
This one is newer: sk112213: How to configure Certificate based Site to Site VPN between two locally managed SMB Applia...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Honestly I didn't try this certificate based configuration (as I said, all other gateways are configured via pre-shared key for s2s vpn), but what I did after reading those 2 articles/guides was reinitializing certificates and now I have 2 scenarios..
There is always green checkmark (tunnels are up), but..
When I put hostname for the first gateway, and dynamic IP for the second gateway everything works fine.
However, if I put hostnames for both gateways, there is still green checkmark (signalizing that tunnel is up), but it's not working..
Any ideas why this happens? I mean configurations are almost same as other gateways from same appliances family.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could be a NAT-T issue, see sk167116: In locally managed appliances, the parameter "vpn_force_nat_t" does not force NAT-T if the remote site is configured using a hostname. Refer to sk162472 for more information.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks mate, I will take a look at those SKs and provide more information.
P.S. When I type
[Expert@appliance]# fw ctl get int vpn_force_nat_t
vpn_force_nat_t = 0
it's disabled on every appliance.
