- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
HI there,
newbie here, trying to establish a IPSEC VPN to 3rd party Fortigate FW.
below are the logs from Fortigate as i cant find anything much from CP debug IKE.ELG log.
Phase 1 passes except Phase 2(refer to pic or below).
peer proposal is : peer:0:192.168.1.251-192.168.1.251:0, me:0:192.168.200.0-192.168.200.255:0
is the ip in red should be my lan 192.168.220.254 address to correct the issue?
tried many settings but still get there error. where should i config to get the correct peer proposal?
My info:
External: 192.168.1.251, LAN: 192.168.220.254
Peer info:
External: 192.168.0.253, LAN: 192.168.200.1
Looks like the encryption domain on your gateway is blank (are you using route-based VPN's?) or is not matching what the FG expects.
One option might be to use the Encryption Domain per Community functionality, and make your encryption domain for this community contain something like 192.168.220.0/24 (assuming that's what you have configured on the FG side) and then see what the FG debugs say. Also try disabling NAT inside the community.
192.168.200.220.254 ???
Good catch, corrected. OP's LAN IP.
Hi,
i'm using domain-based VPN
See sk108600: VPN Site-to-Site with 3rd party for basic issues in CP to 3rd party VPN. I would suggest capturing the traffic and analyze using wireshark - see sk34467: Debugging Site-to-Site VPN.
HI,
I'm actually refer to sk108600 to setup these connection
You should rather refer to Site to Site VPN R81.10 Administration Guide p.41: VPN with Interoperable Device for configuration, sk108600 is for troubleshooting / debugging.
Hi,
Will lookup to it.
Thanks
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY