Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 

Site-to-Site VPN and 'packet should not have been decrypted'

New to CheckPoint firewalls and and helping troubleshoot an issue we're having on a new site-to-site VPN we have setup between us and JAMF for a MDM VPN solution.  Everything is working properly except for one server that we're trying to access and the only unique thing about this server is it's in one of the DMZs hanging off the firewall.  Everything else is on the internal network.  When I try and access the server over the tunnel, I get "According to the policy the packet should not have been decrypted" and it drops the packet.

 

Some basic info:

Gateways running Gaia R80.40.

Remote VPN Endpoint: 78.50.44.10

Local VPN Endpoint: 60.40.89.10

Trouble Server Real IP: 192.168.10.50

Trouble Server NAT IP: 60.40.89.50

VPN Domain: Main_Encrypt_Group

 

For the VPN community, the center gateway is the one I'm working on and the VPN Domain is a generic/general group that looks to be applied to all VPN communities and the gateway.  VPN routing is set to 'to center and to other satellites through center.'  NAT is disabled under advanced.  One VPN tunnel per gateway pair is checked.

 

One theory I have is that the server I'm having issues with is not in the 'Mai

...
TO READ THE FULL POST it's simple and free

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 07 Oct 2025 @ 09:30 AM (CEST)

    CheckMates Live Denmark!
    CheckMates Events