<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn tunnel active but no trafic flowing through in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/vpn-tunnel-active-but-no-trafic-flowing-through/m-p/202914#M4549</link>
    <description>&lt;P&gt;I think you are right, first step here should be upgrading the Azure gw latest recommended JHF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;79 is fairly old and probably some behavior changes were introduced in later takes that are producint this issue&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 11:36:46 GMT</pubDate>
    <dc:creator>Machine_Head</dc:creator>
    <dc:date>2024-01-12T11:36:46Z</dc:date>
    <item>
      <title>vpn tunnel active but no trafic flowing through</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vpn-tunnel-active-but-no-trafic-flowing-through/m-p/202905#M4548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;having something strange...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup site-to-site vpn, onse side VSX cluster instance running R81.10 take 110, other side azure single fw running R81.10 take 78.&lt;/P&gt;&lt;P&gt;We see several vpn tunnels between the two are up.&amp;nbsp; But sometimes we get complaints that there is no trafic flowing through.&amp;nbsp; Typically this feedback comes from developers who are accessing some database in the specified subnet in Azure.&lt;/P&gt;&lt;P&gt;The issue appears and dissappears by itself.&amp;nbsp; The source and destination subnets are not always the same.&lt;/P&gt;&lt;P&gt;An fw monitor shows us the trafic arrives on the VSX.&amp;nbsp; But does not arrive on the azure gw.&lt;/P&gt;&lt;P&gt;Yesterday, i remarked that the affected tunnel started working again, at what i expect&amp;nbsp; is the same time the tunnel is actually expiring (or what i believe is an ike renegotiation taking place?).&lt;/P&gt;&lt;P&gt;There's nothing being blocked, dropped or rejected in the logs.&amp;nbsp; This environment has been running for at least ten years btw (altough upgraded, and the azure cloud connection was introduced a few years ago).&lt;/P&gt;&lt;P&gt;We use permanent tunnels, and seperate tunnels per subnet.&lt;/P&gt;&lt;P&gt;I suspect the issue popped up after we upgraded the vsx environment from take 66 to take 110.&lt;/P&gt;&lt;P&gt;Does this ring a bell with anyone?&amp;nbsp; I'm thinking of upgrading the azure gw to take 110.&amp;nbsp; Or restoring a snapshot to take 66 on one of the vsx members.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, we have an open support ticket.&amp;nbsp; So far no bug has been found.&amp;nbsp; But i also wanted to check here if there are people running a similar environment on take 110 and have seen this issue before or not?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;__PRESENT&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 09:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vpn-tunnel-active-but-no-trafic-flowing-through/m-p/202905#M4548</guid>
      <dc:creator>pnobels</dc:creator>
      <dc:date>2024-01-12T09:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tunnel active but no trafic flowing through</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vpn-tunnel-active-but-no-trafic-flowing-through/m-p/202914#M4549</link>
      <description>&lt;P&gt;I think you are right, first step here should be upgrading the Azure gw latest recommended JHF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;79 is fairly old and probably some behavior changes were introduced in later takes that are producint this issue&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 11:36:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vpn-tunnel-active-but-no-trafic-flowing-through/m-p/202914#M4549</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2024-01-12T11:36:46Z</dc:date>
    </item>
  </channel>
</rss>

