Checkpoint does not support negotiation of protocol based SA's. To restrict the traffic in the tunnel to TCP use the "no sysopt connection permit-ipsec" command and attach an access-list to the interface which points to the checkpoint firewall. Allow only TCP from the remote IP's in the access-list.
regards Michel
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.