• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Checkpoint VPN

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    ggts
    last edited by Feb 8, 2007, 9:40 AM Feb 8, 2007, 9:09 AM

    I am using pfsense 1.0.1 with IPsec passthru enabled in the web gui.  I am using checkpoint VPN (VPN-1 secure client R 56 Build no. 619) on my lan clients to connect to remote servers.  My connections go through fine, but after a period (typically 15 mins to 1 hour), the VPN client disconnects.

    I doubt if this is a Checkpoint client/server problem because if I connect through an alternate (FortiGate) gateway in my network, my connections never drop.

    Can someone please help me troubleshoot the problem?

    Thanks in advance.

    1 Reply Last reply Reply Quote 0
    • H
      hoba
      last edited by Feb 18, 2007, 9:26 PM

      sounds like some idle timeout. Have a look at the firewallstates for these connections (best viewed at the shell/ssh as you see the timeouts there). Do you see them timing out? If yes try to add some firewallrules for this traffic with higher state timeouts.

      1 Reply Last reply Reply Quote 0
      • G
        ggts
        last edited by Feb 19, 2007, 7:05 AM

        Hoba, thanks for suggestions!

        I've already "set optimization conservative" through the webgui.  None
        of the other connections are dropping.

        Further, the VPN connection drops even when there is activity, so I
        don't think it's an timeout issue.  As you suggest, I will check out
        the state table entries when the connection drops and report back.

        If you have successfully used a Checkpoint VPN client through a
        pfSense gateway, I'd be very happy if you can share your configuration
        with me.

        Screenshots of my config are posted here.

        Thanks!!

        1.PNG
        1.PNG_thumb
        2.PNG
        2.PNG_thumb
        3.PNG
        3.PNG_thumb
        4.PNG
        4.PNG_thumb
        5.PNG
        5.PNG_thumb
        6.PNG
        6.PNG_thumb
        7.PNG
        7.PNG_thumb
        8.PNG
        8.PNG_thumb
        9.PNG
        9.PNG_thumb
        10.PNG
        10.PNG_thumb
        11.PNG
        11.PNG_thumb
        12.PNG
        12.PNG_thumb
        13.PNG
        13.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by Feb 19, 2007, 9:59 AM

          I have not yet used a checkpoint client yet.  :(

          Oh, any chance you have a lifetime mismatch somewhere between the concentrator and the clients?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received