Hi experts,
Today it was imposible to setup a VPN S2S between a SG 6000 and a SMB SG 1500. The SG 6000 was managed by a SMS, and the SG 1500 was a standalone deployment. I configured the meshed VPN community on SG 6000, how do I define the SG 1500 object? As a interoperable device? Check Point Host? Gateway? Or externally managed VPN Gateway? I defined it as a interoperable device, and used a shared secret, as it was a third party VPN device, is this correct? Because I didn't find an option to use their CPX certificates. The tunnel remained in Phase 1:
![monitortunnel.PNG monitortunnel.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/20180iE030B81ADA3EBCE1/image-size/large?v=v2&px=999)
A strange thing is with the "vpn tu" command, I saw an unknown peer (192.168.50.1), who is this peer?
![vpntu.PNG vpntu.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/20184i9DED3EFC7CE1B617/image-size/large?v=v2&px=999)
At the SMB SG 1500 I saw this log:
![ikefailureensmb.PNG ikefailureensmb.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/20185i82B46719986BA2E5/image-size/large?v=v2&px=999)
And the strange thing is in the SG 6000, I see traffic I made with ping tests going through the VPN tunnel, which is fine, but the tunnel remains in phase 1:
![pingvieneasanvicente.PNG pingvieneasanvicente.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/20183i30B739DB9AAEA1BC/image-size/large?v=v2&px=999)
Maybe the SMB SG 1500 device is not properly configured, I never configured one of them and it has some VPN options I didn't understand (i. e. peer ID for IKEv2).
Can someone shed some light on this? Please your help.
Regards,
Julián