Skip to content

stronswang tunnel/part of tunnel hang issue with checkpoint fw or checkpoint cluster fw #2170

Answered by tobiasbrunner
EeroV asked this question in Q&A
Discussion options

You must be logged in to vote

I am having issues with checkpoint firewall as sometimes tunnel or part of tunnel (one subnet) just hangs with even with dpdaction=clear

Why would that be related to dpdaction?

rightsubnet=x/32,z/32,c/32,b/32

Are you sure Check Point supports this? It doesn't according to our old wiki. You might better configure separate conn entries.

Another weird issue is that when I run ipsec statusall, lines are not showing dpdaction=clear.

That's because internally clear means "take no further action", which results in what you see in the status output.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by EeroV
Comment options

You must be logged in to vote
2 replies
@tobiasbrunner
Comment options

@EeroV
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants