?
Solved

Cisco ASA Checkpoint firewall Site to Site Tunnel

Posted on 2016-09-09
10
Medium Priority
?
61 Views
Last Modified: 2016-10-05
Hello EE
Have anyone of you folks ever had any issues with traffic not passing through randomly between a cisco asa 5510 8.2(5) and a checkpoint FW?
I dont have access to the checkpoint firewall nor do i know much about the appliance.

Just to clarify the tunnel from the cisco side shows everything is peachy but once a month or so traffic will stop flowing for about 30 mins. then it magically fixes it self. During the outage running "show crypto isakmp sa" and show crypto ipsec sa" shows everything is fine.
i have another tunnel to another cisco asa and it's totally fine.

I am stumped on this but ran across this post on the cisco forums that is very identical to my issue.

https://supportforums.cisco.com/discussion/11327601/cant-fix-problem-between-asa-checkpoint-vpn

any input or second opinions are welcome
Thanks
0
Comment
Question by:El Fierro
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
10 Comments
 
LVL 14

Expert Comment

by:SIM50
ID: 41791734
It's hard to tell with the info you provided. During the outage,  when you do sh cry ipsec sa, do you see encaps but no decaps or decaps but no encaps? Are there any related messages in the syslog? Is the other side up? Do you have DPD setup?
0
 
LVL 4

Author Comment

by:El Fierro
ID: 41791752
its an oddity because from both ends it seems fine from whatt the heckpoint fw guy said. hes pointing the finger at cisco of course....would super netting or the simplified /traditional cuz routing issues on the checkpoint cause this? during one of the outages a couple of servers were accessible via rdp and icmp from the asa to checkpoint...just trying to get some feedback.
0
 
LVL 14

Expert Comment

by:SIM50
ID: 41791777
during one of the outages a couple of servers were accessible via rdp and icmp from the asa to checkpoint...just trying to get some feedback.

Check encaps and decaps. If you see encaps but no decaps, something happened to the traffic on the other side. It doesn't necessary have to be a vpn issue. It could be routing, server down and etc.
0
Are You Using the Best Web Development Editor?

The worlds of web hosting and web development are constantly evolving. Every year we see design trends change, coding standards adapt and new frameworks/CMS created. With such a quick pace of change it’s easy to get lost trying to keep up.

See if your editor made the list.

 
LVL 4

Author Comment

by:El Fierro
ID: 41791880
when i ran the "sh crypto ipsec sa peer x.x.x.x" i did see encaps, the only decaps i saw was for the 2 servers that were up but within 15 mins they were unavailable.the checkpoint guy said it looks like the traffice isnt getting encrypted on your end. he pointed at my asa but i was able to get to my other tunnel perfectly fine....sporadically happens so i will have to wait and see when it happens again.
0
 
LVL 14

Assisted Solution

by:SIM50
SIM50 earned 2000 total points
ID: 41791890
If you see encaps, it means your traffic is being encrypted and sent through the tunnel.
0
 
LVL 4

Author Comment

by:El Fierro
ID: 41791898
right, here is a kicker ...during that period when everything on that end is unreachable i can't get any icmp replies and the trace route dies. i can ping and access resources my other tunnels resources,internet is up and running fine. btw the other tunnels end is a asa. that's why i am wondering what kind of tweaking must be done on each end.
0
 
LVL 14

Expert Comment

by:SIM50
ID: 41794235
during one of the outages a couple of servers were accessible via rdp and icmp from the asa to checkpoint

during that period when everything on that end is unreachable i can't get any icmp replies and the trace route dies

So is it completely unreachable or only some IP's?

Ask Checkpoint admin to provide you with relevant logs and ask him to also do a packet capture.
0
 
LVL 4

Author Comment

by:El Fierro
ID: 41794308
we gradually noticed when those outages have happened not everything goes out at once, one server/resource at at time to the point that all ips/servers in this tunnel are unreachable for a small time window. i don't do anything but wait and it fixes it self...they said that they saw a several phase 2 ike errors.don't know how old, but they cleared them...during one of their log checks for traffic activity they didnt see any rdp in their logs yet our dba guy was rdp'd onto the server,he even disconnected and reconnected fine.....they told me to call cisco which i think is a cop out imo.they say everything is fine on our end from they see. i've never encountered something like this and i've set up cisco to sonicwall a few times aside from cisco to cisco which has been over a dozen times. ...there has to be some kind of policy or route summarization that may be causing this.
0
 
LVL 4

Accepted Solution

by:
El Fierro earned 0 total points
ID: 41824284
we reset both sides of the tunnel to make sure both sides matched phase 1 and 2 security
0
 
LVL 4

Author Closing Comment

by:El Fierro
ID: 41829517
because we had to reset both sides of the vpn tunnel configs
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
Make the most of your online learning experience.
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question