> Source: [sk182243](https://support.checkpoint.com/results/sk/sk182243)

# sk182243 - Harmony SASE: Troubleshooting Common Errors in IPSec Site-to-Site Connection Setup

| Property | Value |
|----------|-------|
| Solution ID | sk182243 |
| Date Created | 2024-04-24 |
| Last Modified | 2024-04-28 |
| Technical Level | Advanced |
| Products | SASE |
| Versions | Cloud |

## Symptoms

- Harmony SASE Administrator Portal shows these on the Networks page:

* Tunnel is down.
* Tunnel is up but unable to access internal resources.

## Cause

### **Tunnel Down Issue**

* Mismatchin IKE Mode and shared secret (PSK) between Harmony SASE Management Platform and the firewall/router.  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182243/AdvancedSettings202404241245191.png)
* Incorrect Public IP/Remote ID, Harmony SASE Gateway Proposal Subnet, and Remote Gateway Proposal Subnet.

<br />

### **Inability to Access Resources**

* **Inadequate Route Table Configuration**: The Inbound and Outbound rules do not allow traffic flow between the Harmony SASE subnet and the internal network.
* **Firewall Rules/Security Group Issues**: Insufficient configuration to allow UDP ports 4500 and 500 for both inbound and outbound traffic.
* **Subnet Overlaps**: Overlapping subnets cause interference with traffic flow.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
