<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Issues - Check Point Cloudguard x AWS VPN Gateway in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Issues-Check-Point-Cloudguard-x-AWS-VPN-Gateway/m-p/277433#M6231</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I'm facing a problem I've seen occur in other scenarios. I configured a VPN between a Check Point (Cloudguard) with one peer and a VPN gateway (AWS) with two peers configured in the same community.&lt;/P&gt;&lt;P&gt;My Check Point gateway is version R81.20 JHF 120.&lt;/P&gt;&lt;P&gt;The configuration mode chosen for the VPN was based on routes with an unnumbered interface. I created the VTIs with the same names as the interoperable objects, routes with correct destinations, encryption, rules, everything is correct, but only one of the tunnels stays UP. The secondary tunnel doesn't even initiate communication with the remote peer. I don't see any attempts by the firewall to establish communication on port 500 or 4500 via tcpdump or firewall monitor. I also don't see any drops via firewall control zdebug, and VPN debug doesn't show any information about the secondary peer either. The smart console doesn't display any logs either.&lt;/P&gt;&lt;P&gt;Have you experienced something similar and could share or suggest something to understand what might be happening?&lt;/P&gt;&lt;P&gt;In an attempt to solve the problem:&lt;/P&gt;&lt;P&gt;1 - I changed the ikev1 version to ikev2&lt;BR /&gt;2 - I created another community only with the problematic peer and it remained the same, with no traffic.&lt;/P&gt;</description>
    <pubDate>Tue, 26 May 2026 13:47:33 GMT</pubDate>
    <dc:creator>jslimma_soloiro</dc:creator>
    <dc:date>2026-05-26T13:47:33Z</dc:date>
    <item>
      <title>VPN Issues - Check Point Cloudguard x AWS VPN Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Issues-Check-Point-Cloudguard-x-AWS-VPN-Gateway/m-p/277433#M6231</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I'm facing a problem I've seen occur in other scenarios. I configured a VPN between a Check Point (Cloudguard) with one peer and a VPN gateway (AWS) with two peers configured in the same community.&lt;/P&gt;&lt;P&gt;My Check Point gateway is version R81.20 JHF 120.&lt;/P&gt;&lt;P&gt;The configuration mode chosen for the VPN was based on routes with an unnumbered interface. I created the VTIs with the same names as the interoperable objects, routes with correct destinations, encryption, rules, everything is correct, but only one of the tunnels stays UP. The secondary tunnel doesn't even initiate communication with the remote peer. I don't see any attempts by the firewall to establish communication on port 500 or 4500 via tcpdump or firewall monitor. I also don't see any drops via firewall control zdebug, and VPN debug doesn't show any information about the secondary peer either. The smart console doesn't display any logs either.&lt;/P&gt;&lt;P&gt;Have you experienced something similar and could share or suggest something to understand what might be happening?&lt;/P&gt;&lt;P&gt;In an attempt to solve the problem:&lt;/P&gt;&lt;P&gt;1 - I changed the ikev1 version to ikev2&lt;BR /&gt;2 - I created another community only with the problematic peer and it remained the same, with no traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2026 13:47:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Issues-Check-Point-Cloudguard-x-AWS-VPN-Gateway/m-p/277433#M6231</guid>
      <dc:creator>jslimma_soloiro</dc:creator>
      <dc:date>2026-05-26T13:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issues - Check Point Cloudguard x AWS VPN Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Issues-Check-Point-Cloudguard-x-AWS-VPN-Gateway/m-p/277452#M6232</link>
      <description>&lt;P&gt;Is there a specific reason you're using an unnumbered VTI?&lt;BR /&gt;We have specific instructions that mention using numbered VTI:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108958" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108958&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2026 15:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Issues-Check-Point-Cloudguard-x-AWS-VPN-Gateway/m-p/277452#M6232</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-26T15:20:57Z</dc:date>
    </item>
  </channel>
</rss>

