Reset a VPN via script
From Tech-Wiki
More actions
Check Point VSX example for clearing IKE/IPsec security associations for a specific peer.
Validation status
Reviewed for migration on 27 September 2026. Tunnel-deletion syntax and VSX context are release-specific.
This interrupts live VPN state
Confirm the VS ID and peer address before deleting SAs. Active sessions can be interrupted and the peer must renegotiate.
Original technical reference
This script will change context to your VSX system then clear the IPsec SA for the specific peer
#!/bin/sh source /etc/profile.d/vsenv.sh vsenv 2 vpn shell /tunnels/delete/IKE/peer/[peer ip] vpn shell /tunnels/delete/IPsec/peer/[peer ip]