VPN Recovery Instructions

In case VPN connection does not work, recovery should start from investigating why VPN tunnel is not established. Examining logging in detail gives indication of the underlying problem. Basic steps to follow are described below

Note: More detailed IPsec VPN messages will be logged after Diagnostics logging has been enabled for IPsec facility. To enable more detailed logging, right-click the Engine, select Options > Diagnostics then under VPN, select IPsec VPN. Click OK to close the dialog box.
  • Check for certificate validity:
    • Verify that certificates of local or external VPN Gateway have not expired.
    • Verify that certificates of local or external VPN Gateway have not been revoked if revocation checking has been configured.
    • If revocation checking is configured, check that revocation information can be accessed.
  • VPN negotiation issues:
    • IPsec VPN negotiation issues happen mostly between Engine and external VPN Gateway tunnel negotiations due to mismatched definitions. The main thing to keep in mind when troubleshooting VPN negotiation issues is making sure settings match:
      • IKE version
      • IKE SA cipher algorithm
      • IKE SA message digest algorithm
      • IKE SA Diffie-Hellman group
      • IKE SA authentication method
      • IPsec SA type (ESP or AH)
      • IPsec SA cipher algorithm
      • IPsec SA message digest algorithm
      • IPsec SA compression algorithm (none or deflate)
      • IPsec SA granularity (SA per net or SA per host)
      • (Optional) IPsec SA Diffie-Hellman group if PFS is used
      • IPsec SA site definitions (traffic selectors / proxy IDs)
      • Trusted VPN Certificate Authority configuration
      • VPN endpoint identity configuration
        • Phase-1 ID Type and ID Value
If VPN negotiation fails, IPsec logs must be checked as the first step:
  1. Log in to SMC using the SMC Client or using SMC Web Access.
  2. Right-click the Engine related to the VPN problem on the Home / Dashboard page, and then select Monitoring > Logs by Sender.
    Note: If the VPN is failing between two engines managed by the same SMC, you can select both firewalls by holding the Ctrl button down.
  3. In the Logs view Query panel use the drop-down menu to select VPN.
    Note: If you do not see the VPN option, click the Select button, scroll down, click to select the VPN.
  4. Click the Apply button on the Query panel.
  5. (Optional) Add a filter as needed.
  6. Check what logs (especially the Information Message field) indicate as the reason for the VPN failure.
When checking logs, keep in mind the following:
  • You should have access to logs from both the gateways as IPsec standard does not permit sending exact error message to peer gateway.
  • If Engine logs show only generic No proposal chosen without more details, check logs from the External VPN Gateway as logging on that gateway will likely have more details.
  • Each IPsec tunnel negotiation is composed of an initiator and a responder:
    • The initiator is the gateway which receives the traffic, i.e. traffic that should be sent through the tunnel, while the tunnel is not yet established, and thus initiated the negotiation.
    • The responder is the gateway which responds to a negotiation request from the peer (initiator) gateway.
    • Negotiation usually fails on the responder side.
  • If Engine is the initiator, and you do not have access to External VPN Gateway logs, try initiating new negotiation from the host behind the External VPN Gateway so that Engine will be the responder, and thus more detailed error should be seen in the Engine IPsec logs to which you have access.
    Note: A mismatch in VPN settings might not trigger the same error when the initiator changes. If possible, when troubleshooting IPsec negotiation between Engine and External VPN Gateway, try and access both the gateways' logs to see both perspectives.
After identifying the issue, adjust the configuration as needed.
  • Refer to VPN Certificates for VPN certificate management section.
  • Refer to Create VPN Profile elements for VPN settings section.

Refresh the policies of all firewalls involved in the VPN to activate the new configuration.