<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: on prem to cloudguard Azure site to site vpn in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238014#M5183</link>
    <description>&lt;P&gt;Extra SK's to check but I suspect it is not the issue but worth to check&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk138012" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk138012&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk129112" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk129112&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108975" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108975&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2025 19:04:53 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-01-08T19:04:53Z</dc:date>
    <item>
      <title>on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238007#M5181</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to establish a test site-to-site vpn from my on premise checkpoint appliance (R81.20 3000 appliance) to my test cloudguard instance in azure (R81.20). I've tried it as a star and a mesh, neither work.&lt;/P&gt;&lt;P&gt;Following all the help I got yesterday on getting access to the objects behind the gateway, the vpn is still not playing ball.&lt;/P&gt;&lt;P&gt;I've got it configured as per my other s2s vpns, except I've set the link selection to a static nat address using the azure public ip, but whatever I try, it logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[iked0 14027 4066955712]@cloudguardtestfw[8 Jan 17:24:26] GetEntryIsakmpObjectsHash: received ipaddr: xx.xx.xx.xx as key, found fwobj: GATEWAYNAME&lt;BR /&gt;[iked0 14027 4066955712]@cloudguardtestfw[8 Jan 17:24:26] fwipsechost_from_ipxaddr: calling GetEntryXIsakmpObjectsHash for xx.xx.xx.xx returned obj: 0x8d96f7c&lt;BR /&gt;[iked0 14027 4066955712]@cloudguardtestfw[8 Jan 17:24:26] GetEntryCommunityHashX: called before hash initialization, could be because this entity is not in a community&lt;BR /&gt;[iked0 14027 4066955712]@cloudguardtestfw[8 Jan 17:24:26] FindCommonCommunity: Did not find common community for GATEWAYNAME&lt;BR /&gt;[iked0 14027 4066955712]@cloudguardtestfw[8 Jan 17:24:26][ikev2] getConfiguredIkeVersion: could not find community for GATEWAYNAME.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;which is odd - it's taking the policy ok, and resolves the gateway object names etc correctly so it's odd. A look at the checkpoint kb hasn't turned anything up for this version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas gratefully received.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 17:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238007#M5181</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-01-08T17:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238013#M5182</link>
      <description>&lt;P&gt;Are you useing the link selection option on the gateway object itself or in the vpn community (last one will not work).&lt;/P&gt;
&lt;P&gt;Also are both systems managed by the same mgmt?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 18:58:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238013#M5182</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-08T18:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238014#M5183</link>
      <description>&lt;P&gt;Extra SK's to check but I suspect it is not the issue but worth to check&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk138012" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk138012&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk129112" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk129112&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108975" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108975&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 19:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238014#M5183</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-08T19:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238015#M5184</link>
      <description>&lt;P&gt;is it failing on phase 1 or 2? I cant tell 100% based on those logs. If you run vpn tu and option 3 for ike SAs, it would tell us if even phase 1 is completing.&lt;/P&gt;
&lt;P&gt;See if below post I made helps you, as I pretty much listed all the steps needed to make this work using VTIs.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Mind you, this type of tunnel can also be domain based.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 19:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238015#M5184</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-08T19:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238074#M5186</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Unfortunately I don't even get phase 1.&lt;/P&gt;&lt;P&gt;Your post is brilliant, but I am trying to do what I thought would be simple. CP and management on prem to CP cloudguard in azure, both managed by the on prem management, so it's all configured from there. That's partly why I am surprised it doesn't work and&amp;nbsp; thinks there isn't a community given it's all pushed from management. The on premise gateway I am using is a quantum 3000 appliance which is already participating in some VPNs and has been for some time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, whilst writing this, I've spotted the problem.. and I feel bad now. The policy deployed to the Azure Cloudguard has 'traditional mode vpn' selected. No wonder nothing worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies for wasting people's time.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 10:47:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238074#M5186</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-01-09T10:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238077#M5187</link>
      <description>&lt;P&gt;Dont look at it like that Ian. We are always here to help, no matter what. Glad its working, great job!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 12:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238077#M5187</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-09T12:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238082#M5188</link>
      <description>&lt;P&gt;Though this is always now by default, if you ever have this issue again, just make sure below is ticked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29138i8DA3C158DAC88242/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 12:59:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238082#M5188</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-09T12:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: on prem to cloudguard Azure site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238092#M5189</link>
      <description>&lt;P&gt;Thank you, i suspect it is because the mgmt was built R65 or earlier and has been upgraded and upgraded and upgraded to R81.20 !&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 14:51:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/on-prem-to-cloudguard-Azure-site-to-site-vpn/m-p/238092#M5189</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-01-09T14:51:52Z</dc:date>
    </item>
  </channel>
</rss>

