Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Slavko_Kojic
Participant

Failed to enforce VPN policy (11)

Hello Checkmates, 

Customer has request  to establish a VPN tunnel over an existing VPN tunnel ( two miktotiks over existing VTI tunnel between CheckPoint R80.40 and Juniper).

When tunnel is initiated from Miktrotik behind CP, the IKE packet is dropped from CP with message:
"Failed to enforce VPN policy (11)".

Regard, sk106241. 

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

I've changed setting fw ctl set int encrypt_non_gw_rdp_ike 1 , but without success

Please, do you have some suggestions about this problem, or is TAC necessary for this. 

 

0 Kudos
3 Replies
_Val_
Admin
Admin

Yes, please raise a TAC case. Also, the mentioned SK does not seem to be related to your specific case.

_Val_
Admin
Admin

Actually, it is relevant. the second case "Site to Site" seems to be your situation. Did you try setting up VPN debug, as SK recommends?

0 Kudos
Slavko_Kojic
Participant

Hi Val, thank you for answer, sorry for late response, meanwhile client has decided for other better solution. If we have same request in future, we will take debug.