<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Decrypted in community&amp;quot; vs &amp;quot;Traffic Accepted&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89115#M11064</link>
    <description>&lt;P&gt;Did you verify the traffic actually came over a VPN (like with a tcpdump or similar)?&lt;/P&gt;
&lt;P&gt;Accept in this context implies "not encrypted."&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 03:25:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-06-19T03:25:33Z</dc:date>
    <item>
      <title>"Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89108#M11063</link>
      <description>&lt;P&gt;I've brought up two site-to-site IPSec VPNs between a Cisco IOS router and two different CheckPoint R80.30 gateway clusters in GCP.&amp;nbsp; &amp;nbsp;The tunnels are route-based, and both showing up/up on the Cisco end with valid 0.0.0.0/0 SAs generated.&amp;nbsp; However, while the first VPN is passing traffic just fine, the second is not.&amp;nbsp; I see the traffic leaving the Cisco going over the tunnel interface but never making it to be server behind the checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the working tunnel, the CheckPoint logs show the VPN -&amp;gt; Decrypt with "Decrypted in community" and the name of the VPN community in the message.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the non-working tunnel, CheckPoint logs show Firewall -&amp;gt; Accept.&amp;nbsp; Almost as if the traffic never went through a VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've double-checked settings both on the Gateway and also the VPN Communities - they look the same.&amp;nbsp; I've also verified VPN domains on the gateways and they look correct.&amp;nbsp; What could explain this difference?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 23:13:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89108#M11063</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2020-06-18T23:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89115#M11064</link>
      <description>&lt;P&gt;Did you verify the traffic actually came over a VPN (like with a tcpdump or similar)?&lt;/P&gt;
&lt;P&gt;Accept in this context implies "not encrypted."&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 03:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89115#M11064</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-19T03:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89119#M11065</link>
      <description>&lt;P&gt;On the other side (Cisco ISR), I can see the packets being sent over the tunnel interface and the "pkts encaps" in the IPSec SA incrementing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the CheckPoint, if I do a tcpdump on eth0 (external/internet interface) I see activity.&amp;nbsp; But on eth2 (Internal interface) I see nothing.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 03:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89119#M11065</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2020-06-19T03:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89243#M11066</link>
      <description>You need to more precisely describe "activity" here.</description>
      <pubDate>Fri, 19 Jun 2020 21:04:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89243#M11066</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-19T21:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89249#M11067</link>
      <description>&lt;P&gt;"activity" meaning udp/4500 traffic on the CheckPoint's external interface.&amp;nbsp; A simple ping going over the tunnel shows up like this:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[Expert@gcp-checkpoint-member-a:0]# tcpdump -i eth0 -n port not 80 and port not 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;21:44:49.376705 IP 203.0.113.251.ipsec-nat-t &amp;gt; 172.16.2.26.ipsec-nat-t: UDP-encap: ESP(spi=0xcd7c75b7,seq=0x12b), length 132&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;21:44:50.410255 IP 203.0.113.251.ipsec-nat-t &amp;gt; 172.16.2.26.ipsec-nat-t: UDP-encap: ESP(spi=0xcd7c75b7,seq=0x12c), length 132&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;21:44:51.449244 IP 203.0.113.251.ipsec-nat-t &amp;gt; 172.16.2.26.ipsec-nat-t: UDP-encap: ESP(spi=0xcd7c75b7,seq=0x12d), length 13&lt;/FONT&gt;2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 21:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89249#M11067</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2020-06-19T21:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89254#M11068</link>
      <description>Ok, so the traffic is getting to the gateway, clearly, but it's most likely getting dropped.&lt;BR /&gt;What does fw ctl zdebug drop say?&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Jun 2020 23:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89254#M11068</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-19T23:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89264#M11069</link>
      <description>&lt;P&gt;Now that's useful...&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;@;2147206;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 192.168.1.19:33860 -&amp;gt; 10.22.33.44:80 dropped by fw_first_packet_xlation Reason: Dynamic object is already being resolved;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Due to how routing works inside GCP and some dependencies beyond our control, this flow is NAT'd to the gateway's first internal network (3rd NIC) using a &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI1915&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;dynamic object&lt;/A&gt;, which had not been created on this particular gateway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I &lt;A href="https://layer77.net/2020/03/05/using-checkpoint-dynamic-objects-to-source-nat-flows/" target="_self"&gt;created the dynamic object&lt;/A&gt; and traffic is flowing now.&amp;nbsp; In SmartConsole, I see "Decrypted in Community" which is expected with VPN traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2020 01:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89264#M11069</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2020-06-20T01:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: "Decrypted in community" vs "Traffic Accepted"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89270#M11070</link>
      <description>Nice, glad you found the issue.</description>
      <pubDate>Sat, 20 Jun 2020 04:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Decrypted-in-community-quot-vs-quot-Traffic-Accepted-quot/m-p/89270#M11070</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-20T04:02:40Z</dc:date>
    </item>
  </channel>
</rss>

