cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1884
Views
0
Helpful
4
Replies

Site to Site VPN problem between Cisco ASA and Checkpoint

LogicalTRC TRC
Level 1
Level 1

I am having a problem with a Site to Site VPN between my Cisco ASA  8.2(5) and Checkpoint (unknown version at this point).  VPN establishes okay, but the Check point has been dropping the VPN (I think) and we get the following on the ASA.

                

24  IKE Peer: 170.163.45.2

    Type    : L2L             Role    : responder

    Rekey   : no              State   : MM_REKEY_DONE_H2

25  IKE Peer: 170.163.45.2

    Type    : L2L             Role    : initiator

    Rekey   : yes             State   : MM_ACTIVE_REKEY 24  IKE Peer: 170.163.45.2
    Type    : L2L             Role    : responder
    Rekey   : no              State   : MM_REKEY_DONE_H2
25  IKE Peer: 170.163.45.2
    Type    : L2L             Role    : initiator
    Rekey   : yes             State   : MM_ACTIVE_REKEY

Once I clear the IKE SA, then VPN reestablishes.  I am looking to see if there is a fix for this.

Chuck Slayton

4 Replies 4

Azubuike Obiora
Level 1
Level 1

Hi Chuck,

Do you have access to the Checkpoint firewall? I am aware that in some version of Checkpoint software, there's an additional configuration needed to make the tunnel solid from the Cisco stand point.

From what I can see here, it's basically a phase 1 problem.

Teddy

I don't have direct access to it, but I'm working with an engineer that does.  Let me know what you need from the Check Point site of things, version, configuration, etc.

Chuck

The checkpoint FW is running Gaia R75.47.  Let me know the additional configuration needed to make the tunnel solid.

Chuck

any update on this? We're having the same issue

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: