<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site2Site VPN AWS Setup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/70261#M11839</link>
    <description>&lt;P&gt;Have a look here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk64060&amp;amp;partition=Advanced&amp;amp;product=IPSec" data-hasqtip="28" aria-describedby="qtip-28" target="_blank"&gt;sk64060: 'Encryption Failure: &lt;STRONG&gt;according&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt; &lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;been&lt;/STRONG&gt; decrypted' log in SmartView Tracker for VPN Tunnel Test &lt;STRONG&gt;packet&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97612&amp;amp;partition=Advanced&amp;amp;product=IPSec" data-hasqtip="29" aria-describedby="qtip-29" target="_blank"&gt;sk97612: Site to Site VPN going down frequently with error "encryption failure: &lt;STRONG&gt;According&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt;&lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;be&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106627&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk106627: "&lt;STRONG&gt;According&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt; &lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;been&lt;/STRONG&gt; &lt;STRONG&gt;decrypted&lt;/STRONG&gt;" drop while using Route Based VPN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106837&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk106837: Troubleshooting Overlapping Encryption Domains Issues&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2019 11:19:24 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-12-12T11:19:24Z</dc:date>
    <item>
      <title>Site2Site VPN AWS Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/70259#M11838</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have just configured our first vpn with vti's to aws as described in sk100726.&lt;/P&gt;&lt;P&gt;The tunnels are up and running. Traffic from aws to our location goes through the tunnels.&lt;/P&gt;&lt;P&gt;So far so good. But our gw drops the packets with&lt;/P&gt;&lt;P&gt;"dropped by vpn_drop_and_log Reason: According to the policy the packet should not have been decrypted"&lt;/P&gt;&lt;P&gt;Any ideas or hints are highly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanx in advance&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 10:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/70259#M11838</guid>
      <dc:creator>Technical_Servi</dc:creator>
      <dc:date>2019-12-12T10:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN AWS Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/70261#M11839</link>
      <description>&lt;P&gt;Have a look here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk64060&amp;amp;partition=Advanced&amp;amp;product=IPSec" data-hasqtip="28" aria-describedby="qtip-28" target="_blank"&gt;sk64060: 'Encryption Failure: &lt;STRONG&gt;according&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt; &lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;been&lt;/STRONG&gt; decrypted' log in SmartView Tracker for VPN Tunnel Test &lt;STRONG&gt;packet&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97612&amp;amp;partition=Advanced&amp;amp;product=IPSec" data-hasqtip="29" aria-describedby="qtip-29" target="_blank"&gt;sk97612: Site to Site VPN going down frequently with error "encryption failure: &lt;STRONG&gt;According&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt;&lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;be&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106627&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk106627: "&lt;STRONG&gt;According&lt;/STRONG&gt; to the &lt;STRONG&gt;policy&lt;/STRONG&gt; the &lt;STRONG&gt;packet&lt;/STRONG&gt; &lt;STRONG&gt;should&lt;/STRONG&gt; not &lt;STRONG&gt;have&lt;/STRONG&gt; &lt;STRONG&gt;been&lt;/STRONG&gt; &lt;STRONG&gt;decrypted&lt;/STRONG&gt;" drop while using Route Based VPN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106837&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk106837: Troubleshooting Overlapping Encryption Domains Issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 11:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/70261#M11839</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-12-12T11:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN AWS Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/72053#M11840</link>
      <description>&lt;P&gt;OK, we are one step further!&lt;/P&gt;&lt;P&gt;We fixed one problem&lt;BR /&gt;&lt;EM&gt;"dropped by vpn_drop_and_log Reason: According to the policy the packet should not have been decrypted"&lt;/EM&gt;&lt;BR /&gt;The peer name in the GAIA vpn tunnel interface and the object name in SmartConsole must exactly match!&lt;/P&gt;&lt;P&gt;But as I said above, we are just one stop further. We got another problem.&lt;BR /&gt;Tunnels are still up and running.&lt;BR /&gt;A packet from AWS to our site reaches its final destination. But the answer is dropped on the CP with&lt;BR /&gt;&lt;EM&gt;"dropped by vpn_encrypt_chain Reason: Could not change connection vpn interface"&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-VPN-AWS-Setup/m-p/72053#M11840</guid>
      <dc:creator>Technical_Servi</dc:creator>
      <dc:date>2020-01-10T13:18:48Z</dc:date>
    </item>
  </channel>
</rss>

