sk180530 - NAT-T traffic from VPN clients does not match implied rule
NAT-T traffic from VPN clients does not match implied rule
Product
Endpoint Security - Remote Access VPN
Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified
2023-07-19
Symptoms
NAT-T traffic may stop matching the implied rule after policy installation and is dropped with "
IKE_NAT_TRAVERSAL Traffic Dropped from x.x.x.x to y.y.y.y" message in SmartLog.VPN clients cannot connect to the gateway and fail with "
Negotiation with site failed" message.The "
fw tab -t natt_port -u -f" command does not show entry for NAT-T port. In working situation, it should show an entry with 1194 (HEX for port 4500)IKED debug shows IKED gets killed with signal 6 (SIGABRT). During the cleanup and exit it clears the natt_port table and restarts automatically
Issue can happen after creating LDAP group object from Smart Console and pushing policy with the change
Cause
Entry for NAT-T port (4500) is removed from the natt_port table.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 8
- Jumbo Hotfix Accumulator for R81.10 starting from Take 95
- Jumbo Hotfix Accumulator for R81 starting from Take 82
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.