- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good morning everyone,
I am setting up IPsec over the Public Internet with many partners around the world. One of my partners uses a Cisco ASA, and there was a problem with that. CheckPoint send traffic selector 0.0.0.0. Cisco rejects the request and IPsec does not up. Has anyone encountered such a problem?
I use CheckPoint 1800 on cluster.
Thanks!
Sounds like both ends disagree on what the encryption domain is and/or you've configured your end to establish a single tunnel for all traffic (0.0.0.0) and the other end isn't configured to accept this.
Hi PhoneBoy!
I need configure connection between local network 185.xx.xx.xx/29 (my CP) and 91.xx.xx.xx/30 (Cisco).
I added network 185.xx.xx.xx/29 to VPN->Site to Site -> Advanced -> Local ecryption domain is defined manualy...
But CheckPoint on Phase 2 sending traffic selector 0.0.0.0/0. Another firewall (PfSense, Strongswan, Huawei) normal to accept it. The problem is only with Cisco ASA.
Can you show how you configured your VPN domain on CP side? The issue is, CP only sends 0.0.0.0/0 if the VPN domain is empty.
And i thought, it's defined in the tunnel management.
Config on screens:
In case you configured the domain to select it's proxy id per pair of gateways, it surely sends 0.0.0.0/0 what is expected behavior.
On the ASA side there should be something like this:
crypto map outside_map 10 match address VPN-Traffic
crypto map outside_map 10 set peer <Peer_IP_Address>
! Define the ACL for interesting traffic
access-list VPN-Traffic extended permit ip any4 any4
This is how i configured that long time ago
IPSec is up if configure the following on the Cisco:
>>access-list VPN-Traffic extended permit ip any4 any4
But in this case, all traffic will be sent via IPSec.
Just configure it as permanent tunnel using VTIs and set option @Vincent_Bacher advised in the community. I had done this many times and works without any issues. If you need help, just ping me.
Andy
Just to clarify the "one tunnel per gateway pair" is sometimes called "double quad zeroes" or a "universal tunnel" by some vendors if it helps locate their proper documentation for this setup.
Super valid point...I know Fortinet calls it that all the time, not sure about Cisco, but its probably the same thing.
Andy
Interesting. I configured masses of VPN tunnels at FortiGate devices and never heard that wording 😄
Now you have 😉
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 16 | |
| 13 | |
| 12 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY