Issue with VPN tunnel between Checkpoint R77.30 and Cisco ASA
Jan 16, 2013 Creating Site-to-Site VPN Policies Optionally, you can configure a static route to be used as a secondary route in case the VPN tunnel goes down. The Allow VPN path to take precedence option allows you to create a secondary route for a VPN tunnel. By default, static routes have a metric of one and take precedence over VPN traffic. [SOLVED] MTU issues in VPN connections - Networking Apr 18, 2012 High ping times on a site to site vpn - Networking
The issue occurs when the server or the client send relatively big packets as they are not aware of the MTU on the path. MTU on the path may be lower (due to the tunnel overhead), than what is configured on their local interfaces (usually client and server will have Ethernet interface with MTU of 1500 bytes).
Solved: Viewing and Resetting VPN tunnels in R80 - Check
vpn tu del ipsec ip-addr . vpn tu del ipsec ip-addr username . vpn tu del all . vpn tu del ip-addr . vpn tu del ip-addr username. I was thinking since smart monitor can do this from the manager why not also being able to do so from the mgmt API? We have a lot if ipsec vpn which on Remote site have a lte router in front of a Cisco router.
In a VPN tunnel one Phase1 will be established and then one Phase2 per subnet pair. If you have two /24 subnets on each side of the tunnel that need to speak to each other, that is 4x Phase2. Check Point will create as few subnets as possible and therefore it will create one /23 subnet instead of 2x /24 if possible. Reset an Azure VPN gateway to reestablish IPsec tunnel