<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC site to site VPN fails after R80.20 upgrade in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/69637#M12665</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15325"&gt;@Scott_Paisley&lt;/a&gt;&amp;nbsp;did you find the root cause of this? Could it have been that after upgrade that PFS was turned off?&lt;/P&gt;&lt;P&gt;I just saw similar behaviour going from R80.10 to R80.30. Im pretty sure I had PFS enabled before upgrade. It was disabled after upgrade I think. I reenabled, and it looks more stable.&lt;/P&gt;</description>
    <pubDate>Sun, 08 Dec 2019 14:55:28 GMT</pubDate>
    <dc:creator>OL</dc:creator>
    <dc:date>2019-12-08T14:55:28Z</dc:date>
    <item>
      <title>IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54836#M12662</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have a large number of IPSEC VPN tunnels between our R77.30 gateway clusters.&lt;/P&gt;&lt;P&gt;Yesterday we upgraded one of the remote clusters to R80.20. After the upgrade the tunnel was still working fine, until we pushed policy to the R77.30 cluster late last night.&lt;/P&gt;&lt;P&gt;Now the tunnel will not stay up. If I push the R80.20 cluster it comes up briefly, then fails again.&lt;/P&gt;&lt;P&gt;The error message is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;Auth exchange: Sending notification to peer: Authentication failed MyAuthMethod: Certificates&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;I have support ticket open, but is there something simple and obvious I am missing?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 11:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54836#M12662</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2019-06-01T11:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54850#M12663</link>
      <description>Do make sure to push the policy on the R77.30 again. We have seen many times during a R77.30 to R77.30 migration, a couple of years ago, that when we had VPN's we needed to at least push twice to those gateways to make sure the tunnels came back.</description>
      <pubDate>Sun, 02 Jun 2019 11:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54850#M12663</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-02T11:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54854#M12664</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;I removed the R80.20 gateway from the VPN, pushed to both gateways, added it back in and pushed again, and now the tunnel is up.&lt;/P&gt;&lt;P&gt;Checkpoint recommendation is to renew the cert, but each of our gateways is involved in multiple VPNs, so we will end up pushing to the whole estate eventually.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 12:23:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/54854#M12664</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2019-06-02T12:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/69637#M12665</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15325"&gt;@Scott_Paisley&lt;/a&gt;&amp;nbsp;did you find the root cause of this? Could it have been that after upgrade that PFS was turned off?&lt;/P&gt;&lt;P&gt;I just saw similar behaviour going from R80.10 to R80.30. Im pretty sure I had PFS enabled before upgrade. It was disabled after upgrade I think. I reenabled, and it looks more stable.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 14:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/69637#M12665</guid>
      <dc:creator>OL</dc:creator>
      <dc:date>2019-12-08T14:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/69690#M12666</link>
      <description>&lt;P&gt;it turned out to be an unrelated issue. The Remote gateways were not able to reach the management server to check the validity of the certs. Once that was resolved the tunnels came up&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 08:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/69690#M12666</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2019-12-09T08:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC site to site VPN fails after R80.20 upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/264360#M51948</link>
      <description>&lt;P&gt;I know this post is a little bit old, but this worked for me. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 14:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-site-to-site-VPN-fails-after-R80-20-upgrade/m-p/264360#M51948</guid>
      <dc:creator>CrociStrike030</dc:creator>
      <dc:date>2025-12-04T14:16:21Z</dc:date>
    </item>
  </channel>
</rss>

