sk180530 - NAT-T traffic from VPN clients does not match implied rule

NAT-T traffic from VPN clients does not match implied rule

Product

Endpoint Security - Remote Access VPN

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

Last Modified

2023-07-19

Symptoms

Cause

Entry for NAT-T port (4500) is removed from the natt_port table.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.