<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC VPN With Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-VPN-With-Azure/m-p/32278#M3809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Dear Team ,&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I got one support call ,&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site 2 site IPsec vpn configured with Azure Microsoft and its configured properly and two way communication is working fine .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer side checkpoint and they have Active directory server and one server is hosted on Microsoft side .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our cloud engineer wanted to add that server in domain of customer side .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO , He configured ip address and DNS (active directory of customer side ) of &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;Microsoft azure server&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Microsoft azure active directory ip address is reachable though icmp but dns resolution was not woring .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we tried to do ns lookup from Microsoft azure side server that not getting resolve and getting error.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So , below troubleshooting steps we have taken &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--- Both tunnel side configuration check and in topology subnet is proper and policy also configured proper&lt;/P&gt;&lt;P&gt;--- we have check customer side lan network object found configured with hide behind gateway - created no &lt;SPAN&gt;nat&lt;/SPAN&gt; policy in &lt;SPAN&gt;nat&lt;/SPAN&gt; policy &lt;/P&gt;&lt;P&gt;--- In tracker from azure to customer side &lt;SPAN&gt;triaffic&lt;/SPAN&gt; seen but customer side to azure side dns traffic not seen in tracker &lt;/P&gt;&lt;P&gt;----in TCP Dump traffic found from customer side to azure side &lt;/P&gt;&lt;P&gt;--- in &lt;SPAN&gt;fw&lt;/SPAN&gt; monitor traffic also found customer side to azure side &lt;/P&gt;&lt;P&gt;---- &lt;SPAN&gt;fw&lt;/SPAN&gt; &lt;SPAN&gt;ctl&lt;/SPAN&gt; &lt;SPAN&gt;zdebug&lt;/SPAN&gt; command no drop found &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We &lt;SPAN&gt;azume&lt;/SPAN&gt; that checkpoint side no traffic is blocking so raised case with azure &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help if anyone know about this same think happen previously so I can get exact idea .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Feb 2018 18:15:44 GMT</pubDate>
    <dc:creator>Harmesh_Yadav</dc:creator>
    <dc:date>2018-02-26T18:15:44Z</dc:date>
    <item>
      <title>IPSEC VPN With Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-VPN-With-Azure/m-p/32278#M3809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Dear Team ,&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I got one support call ,&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site 2 site IPsec vpn configured with Azure Microsoft and its configured properly and two way communication is working fine .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer side checkpoint and they have Active directory server and one server is hosted on Microsoft side .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our cloud engineer wanted to add that server in domain of customer side .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO , He configured ip address and DNS (active directory of customer side ) of &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;Microsoft azure server&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Microsoft azure active directory ip address is reachable though icmp but dns resolution was not woring .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we tried to do ns lookup from Microsoft azure side server that not getting resolve and getting error.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So , below troubleshooting steps we have taken &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--- Both tunnel side configuration check and in topology subnet is proper and policy also configured proper&lt;/P&gt;&lt;P&gt;--- we have check customer side lan network object found configured with hide behind gateway - created no &lt;SPAN&gt;nat&lt;/SPAN&gt; policy in &lt;SPAN&gt;nat&lt;/SPAN&gt; policy &lt;/P&gt;&lt;P&gt;--- In tracker from azure to customer side &lt;SPAN&gt;triaffic&lt;/SPAN&gt; seen but customer side to azure side dns traffic not seen in tracker &lt;/P&gt;&lt;P&gt;----in TCP Dump traffic found from customer side to azure side &lt;/P&gt;&lt;P&gt;--- in &lt;SPAN&gt;fw&lt;/SPAN&gt; monitor traffic also found customer side to azure side &lt;/P&gt;&lt;P&gt;---- &lt;SPAN&gt;fw&lt;/SPAN&gt; &lt;SPAN&gt;ctl&lt;/SPAN&gt; &lt;SPAN&gt;zdebug&lt;/SPAN&gt; command no drop found &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We &lt;SPAN&gt;azume&lt;/SPAN&gt; that checkpoint side no traffic is blocking so raised case with azure &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help if anyone know about this same think happen previously so I can get exact idea .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 18:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-VPN-With-Azure/m-p/32278#M3809</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2018-02-26T18:15:44Z</dc:date>
    </item>
  </channel>
</rss>

