<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R77.30 Ipsec VPN traffic hitting Clean up rule instead of accept rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69263#M11983</link>
    <description>&lt;P&gt;Hello Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing this issue with IPSec VPN configured with client end Fortigate firewall. The issue is the phase1 comes up only when I initiate (ping) some traffic to the peer end IP. Even when the user connected to Checkpoint initiating the flow the gateway is not negotiating for either phase1 and/or phase2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When client forcefully bring phase2 up (in fortigate under vpn monitor section) the phase2 also came up. But even after that the client traffic is getting dropped because of clean up rule even though an existing rule is there for this flow above clean up rule. It seems that rule is invisible for the gateway.&lt;/P&gt;&lt;P&gt;Also, after sometime the tunnel went down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to sum up:&lt;/P&gt;&lt;P&gt;1) Gateways not initiating Ipsec negotiation. Only after explicitly initiating the negotiation tunnel comes up.&lt;/P&gt;&lt;P&gt;2) Even when the tunnel is up, the traffic is getting drop by final clean up rule instead of allow rule which is above clean up rule.&lt;/P&gt;&lt;P&gt;Please help on this issue. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2019 12:13:17 GMT</pubDate>
    <dc:creator>ashish_verma</dc:creator>
    <dc:date>2019-12-06T12:13:17Z</dc:date>
    <item>
      <title>R77.30 Ipsec VPN traffic hitting Clean up rule instead of accept rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69263#M11983</link>
      <description>&lt;P&gt;Hello Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing this issue with IPSec VPN configured with client end Fortigate firewall. The issue is the phase1 comes up only when I initiate (ping) some traffic to the peer end IP. Even when the user connected to Checkpoint initiating the flow the gateway is not negotiating for either phase1 and/or phase2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When client forcefully bring phase2 up (in fortigate under vpn monitor section) the phase2 also came up. But even after that the client traffic is getting dropped because of clean up rule even though an existing rule is there for this flow above clean up rule. It seems that rule is invisible for the gateway.&lt;/P&gt;&lt;P&gt;Also, after sometime the tunnel went down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to sum up:&lt;/P&gt;&lt;P&gt;1) Gateways not initiating Ipsec negotiation. Only after explicitly initiating the negotiation tunnel comes up.&lt;/P&gt;&lt;P&gt;2) Even when the tunnel is up, the traffic is getting drop by final clean up rule instead of allow rule which is above clean up rule.&lt;/P&gt;&lt;P&gt;Please help on this issue. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 12:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69263#M11983</guid>
      <dc:creator>ashish_verma</dc:creator>
      <dc:date>2019-12-06T12:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 Ipsec VPN Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69280#M11984</link>
      <description>&lt;P&gt;Basic troubleshooting guide for such issues is&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;party&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 04 Dec 2019 10:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69280#M11984</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-12-04T10:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 Ipsec VPN Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69288#M11985</link>
      <description>&lt;P&gt;Hi Ashish,&lt;/P&gt;
&lt;P&gt;You can do basic troubleshooting for VPN and at last you can run debug and check ike.elg file.&lt;/P&gt;
&lt;P&gt;Are you generating ICMP traffic while testing tunnel? If so then please check setting "Accept ICMP Request" in general setting. It should be "before last".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 11:25:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69288#M11985</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-12-04T11:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: R77.30 Ipsec VPN Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69302#M11986</link>
      <description>&lt;P&gt;Hello Gaurav and G_W_Albrecht&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I will check the SK but what I found in ike.elg file is that after Phase2 message1, the cookies value are changed (Both init and responder) in message received by the responder as shown in "info" field in ike.elg file.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 12:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R77-30-Ipsec-VPN-traffic-hitting-Clean-up-rule-instead-of-accept/m-p/69302#M11986</guid>
      <dc:creator>ashish_verma</dc:creator>
      <dc:date>2019-12-04T12:27:57Z</dc:date>
    </item>
  </channel>
</rss>

