01-30-2014 01:40 PM
I am having a problem with a Site to Site VPN between my Cisco ASA 8.2(5) and Checkpoint (unknown version at this point). VPN establishes okay, but the Check point has been dropping the VPN (I think) and we get the following on the ASA.
24 IKE Peer: 170.163.45.2
Type : L2L Role : responder
Rekey : no State : MM_REKEY_DONE_H2
25 IKE Peer: 170.163.45.2
Type : L2L Role : initiator
Rekey : yes State : MM_ACTIVE_REKEY 24 IKE Peer: 170.163.45.2
Type : L2L Role : responder
Rekey : no State : MM_REKEY_DONE_H2
25 IKE Peer: 170.163.45.2
Type : L2L Role : initiator
Rekey : yes State : MM_ACTIVE_REKEY
Once I clear the IKE SA, then VPN reestablishes. I am looking to see if there is a fix for this.
Chuck Slayton
01-30-2014 02:34 PM
Hi Chuck,
Do you have access to the Checkpoint firewall? I am aware that in some version of Checkpoint software, there's an additional configuration needed to make the tunnel solid from the Cisco stand point.
From what I can see here, it's basically a phase 1 problem.
Teddy
01-30-2014 04:06 PM
I don't have direct access to it, but I'm working with an engineer that does. Let me know what you need from the Check Point site of things, version, configuration, etc.
Chuck
02-10-2014 10:44 AM
The checkpoint FW is running Gaia R75.47. Let me know the additional configuration needed to make the tunnel solid.
Chuck
05-12-2014 07:43 AM
any update on this? We're having the same issue
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide