cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
255
Views
0
Helpful
1
Replies

Pix to Pix VPN behind a Checkpoint Firewall

bilbobaggins
Level 1
Level 1

Has anyone had any luck having VPN tunnel betweeen 2 pix firewalls and the one side sits behind a Check Point Firewall? It works fine in parallel with the checkppoint. Wondering about ports/encryption on checkpoint that needs addressing and any debugging commands that mught be helpful.

1 Reply 1

cocoy
Level 1
Level 1

1. The following should be open on the Checkpoint.

Protocol 50 (esp)

Protocol 51 (ahp)

UDP port 500 (isakmp)

2. Pix Ipsec will not work if its peer address is port translated (PAT).

3. debug crypto isakmp sa

debug crypto ipsec sa

both debugs will show you where and why tunnel is failing.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: