Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Checkpoint VPN

    IPsec
    2
    4
    3656
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      ggts last edited by

      I am using pfsense 1.0.1 with IPsec passthru enabled in the web gui.  I am using checkpoint VPN (VPN-1 secure client R 56 Build no. 619) on my lan clients to connect to remote servers.  My connections go through fine, but after a period (typically 15 mins to 1 hour), the VPN client disconnects.

      I doubt if this is a Checkpoint client/server problem because if I connect through an alternate (FortiGate) gateway in my network, my connections never drop.

      Can someone please help me troubleshoot the problem?

      Thanks in advance.

      1 Reply Last reply Reply Quote 0
      • H
        hoba last edited by

        sounds like some idle timeout. Have a look at the firewallstates for these connections (best viewed at the shell/ssh as you see the timeouts there). Do you see them timing out? If yes try to add some firewallrules for this traffic with higher state timeouts.

        1 Reply Last reply Reply Quote 0
        • G
          ggts last edited by

          Hoba, thanks for suggestions!

          I've already "set optimization conservative" through the webgui.  None
          of the other connections are dropping.

          Further, the VPN connection drops even when there is activity, so I
          don't think it's an timeout issue.  As you suggest, I will check out
          the state table entries when the connection drops and report back.

          If you have successfully used a Checkpoint VPN client through a
          pfSense gateway, I'd be very happy if you can share your configuration
          with me.

          Screenshots of my config are posted here.

          Thanks!!


























          1 Reply Last reply Reply Quote 0
          • H
            hoba last edited by

            I have not yet used a checkpoint client yet.  :(

            Oh, any chance you have a lifetime mismatch somewhere between the concentrator and the clients?

            1 Reply Last reply Reply Quote 0
            • First post
              Last post