<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint VPN as responder only in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64348#M12320</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in the midst of troubleshooting a VPN between Checkpoint (R80.10) and Paloalto firewall. This site to site tunnel is configured to use certificate for authentication.&lt;/P&gt;&lt;P&gt;During the course of our troubleshooting there was a unknown bug identified in Palo alto firewall due to which it has to initiator of the tunnel till the time a fix is available. Issue pops up whenever Checkpoint becomes the initiator instead and Palo alto firewall stops responding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now coming to the requirement, is there a way I can force Checkpoint to always be just the responder in a VPN tunnel? I am not talking about DPD responder, but at the level of negotiation. Basically at any point of time, I do not want Checkpoint initiate a request to bring up the VPN either due to inactivity or idle timeout.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2019 08:46:56 GMT</pubDate>
    <dc:creator>Udupi_krishna</dc:creator>
    <dc:date>2019-10-04T08:46:56Z</dc:date>
    <item>
      <title>Checkpoint VPN as responder only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64348#M12320</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in the midst of troubleshooting a VPN between Checkpoint (R80.10) and Paloalto firewall. This site to site tunnel is configured to use certificate for authentication.&lt;/P&gt;&lt;P&gt;During the course of our troubleshooting there was a unknown bug identified in Palo alto firewall due to which it has to initiator of the tunnel till the time a fix is available. Issue pops up whenever Checkpoint becomes the initiator instead and Palo alto firewall stops responding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now coming to the requirement, is there a way I can force Checkpoint to always be just the responder in a VPN tunnel? I am not talking about DPD responder, but at the level of negotiation. Basically at any point of time, I do not want Checkpoint initiate a request to bring up the VPN either due to inactivity or idle timeout.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 08:46:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64348#M12320</guid>
      <dc:creator>Udupi_krishna</dc:creator>
      <dc:date>2019-10-04T08:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN as responder only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64349#M12321</link>
      <description>&lt;P&gt;Apologies I did not realize that I was under Threat prevention forum. I did not find a way to move it to the right section either&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 08:48:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64349#M12321</guid>
      <dc:creator>Udupi_krishna</dc:creator>
      <dc:date>2019-10-04T08:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN as responder only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64369#M12322</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As long as you don't initiate traffic from your side and the permanent tunnel option is not set the VPN tunnel shouldn't come up by it's own. By defect if there is no activity the tunnel will shut down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 13:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64369#M12322</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-04T13:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN as responder only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64414#M12323</link>
      <description>Don't worry, I can fix moving it to the right place. &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;As for the question you asked, unless you've got a permanent tunnel configured, what determines whether or not the VPN connection is initiated is the initiation of traffic.&lt;BR /&gt;If you want to ensure the Palo side is initiating the VPN, something on that side of the connection should be generating regular traffic (e.g. ping) through the VPN.</description>
      <pubDate>Sat, 05 Oct 2019 04:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64414#M12323</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-05T04:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint VPN as responder only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64429#M12324</link>
      <description>&lt;P&gt;Thanks for the fix :).&lt;/P&gt;&lt;P&gt;Ping was definitely an option suggested to client. Problem is there are chances that servers behind Checkpoint can attempt to initiate traffic as part of an application automation.&lt;/P&gt;&lt;P&gt;The only goal i was trying to look for is if Checkpoint would never attempt to become an initiator regardless of where the traffic comes from. For e.g. Palo Alto within VPN configuration has an option called passive mode, which basically forces it not to become the initiator during a negotiation phase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2019 16:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-VPN-as-responder-only/m-p/64429#M12324</guid>
      <dc:creator>Udupi_krishna</dc:creator>
      <dc:date>2019-10-05T16:43:22Z</dc:date>
    </item>
  </channel>
</rss>

