stronswang tunnel/part of tunnel hang issue with checkpoint fw or checkpoint cluster fw #2170
-
Hi All, I am having issues with checkpoint firewall as sometimes tunnel or part of tunnel (one subnet) just hangs with even with dpdaction=clear Snippet of config: conn xxxxx It works fine on other vendors than checkpoint. tunnel always fixes when I terminate it. I assume that this can be related to checkpoint cluster failover, but not on all times. How to get strongswan working reliable with checkpoint? I am running latest strongswan on debian 12 on aws cloud. Another weird issue is that when I run ipsec statusall, lines are not showing dpdaction=clear. ex: ipsec statusall | grep -i dpd Please help. I will offer free beer to first one to resolve this issue. thanks. Same config works fine with all other vpn vendors. Eero |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Why would that be related to
Are you sure Check Point supports this? It doesn't according to our old wiki. You might better configure separate conn entries.
That's because internally |
Beta Was this translation helpful? Give feedback.
-
Hi @tobiasbrunner and thanks. I think that following settings fixed my checkpoint issues.
I will deliver big beer to you. please give your paypal email, so will deliver cash to buy that one. thanks a lot. Eero |
Beta Was this translation helpful? Give feedback.
Why would that be related to
dpdaction
?Are you sure Check Point supports this? It doesn't according to our old wiki. You might better configure separate conn entries.
That's because internally
clear
means "take no further action", which results in what you see in the status output.