<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure S2S VPN Responder Only? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107314#M14366</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is an sk that works with DAIP SMB devices. It's SK101911. Not sure if it works with 3rd party peers but you can try.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jan 2021 17:43:23 GMT</pubDate>
    <dc:creator>Jose_Manuel_Gar</dc:creator>
    <dc:date>2021-01-08T17:43:23Z</dc:date>
    <item>
      <title>How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107307#M14365</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Have a bit of a strange issue I'm hoping someone has an answer for.&lt;/P&gt;&lt;P&gt;Basically we have a situation where there is a 3rd party NAT device breaking VPN connectivity to a peer.&lt;/P&gt;&lt;P&gt;If the peer initiates the tunnel then the VPN comes up&lt;/P&gt;&lt;P&gt;If our side attempts it then it all goes wrong.&lt;/P&gt;&lt;P&gt;There is 0% chance of any config changes to the remote peer side so we are stuck with this.&lt;/P&gt;&lt;P&gt;There are also other VPNS terminating on our Check Points.&lt;/P&gt;&lt;P&gt;A fudge-fix is to stop our side attempting to bring up the tunnel and respond only but I cant find any articles how to do this on a Check Point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone point me to a relevant article?&lt;/P&gt;&lt;P&gt;Is Responder Mode supported on a Check Point?&lt;/P&gt;&lt;P&gt;Is if it is it global or can it be peer-limited?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 16:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107307#M14365</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2021-01-08T16:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107314#M14366</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is an sk that works with DAIP SMB devices. It's SK101911. Not sure if it works with 3rd party peers but you can try.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 17:43:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107314#M14366</guid>
      <dc:creator>Jose_Manuel_Gar</dc:creator>
      <dc:date>2021-01-08T17:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107337#M14369</link>
      <description>&lt;UL class="listbullet"&gt;
&lt;LI class="listbullet"&gt;&lt;STRONG class="bold"&gt;IKE Initiation Prevention&lt;/STRONG&gt; - By default, when a valid IKE SA is not available, a DPD request message triggers a new IKE negotiation. To prevent this behavior, set the property &lt;STRONG class="menuoptions"&gt;dpd_allowed_to_init_ike&lt;/STRONG&gt; to &lt;STRONG class="menuoptions"&gt;false&lt;/STRONG&gt;.
&lt;P class="listcontinue"&gt;Edit the property in GuiDBedit Tool (see &lt;A class="tpjumpexternaltemplate" title="" href="http://supportcontent.checkpoint.com/solutions?id=sk13009" target="_blank" rel="noopener"&gt;sk13009&lt;/A&gt;) &amp;gt; &lt;STRONG class="menuoptions"&gt;Network Objects&lt;/STRONG&gt; &amp;gt; &lt;STRONG class="menuoptions"&gt;network_objects&lt;/STRONG&gt; &amp;gt; &lt;STRONG class="menuoptions"&gt;&amp;lt;gateway Name&amp;gt; &lt;/STRONG&gt;&amp;gt; &lt;STRONG class="menuoptions"&gt;VPN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 09 Jan 2021 01:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107337#M14369</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-09T01:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107582#M14402</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DAIP&amp;nbsp;object is the answer:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36968" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36968&lt;/A&gt;&lt;/P&gt;&lt;P&gt;By configuring the 3rd party as a DIAP we force the Check Point to responder mode only.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 11:15:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/107582#M14402</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2021-01-12T11:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/109682#M14966</link>
      <description>&lt;P&gt;Hi Dameon,&lt;BR /&gt;&lt;BR /&gt;Regarding S2S Responder Only.&amp;nbsp; Would it be an option to increase P1 lifetime just on ckp side?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116615&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116615&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;According to this sk at least.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;All my engineer life i've tried to match both values on both ends but it seems now to be a value only valid locally?&lt;/P&gt;&lt;P&gt;Or maybe is it just for IkeV2 implementations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Azure also states:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/vpn-gateway/ipsec-ike-policy-howto" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/vpn-gateway/ipsec-ike-policy-howto&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"The SA lifetimes are local specifications only, do not need to match."&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 12:55:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/109682#M14966</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2021-02-03T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/109772#M14988</link>
      <description>&lt;P&gt;I would say: try it and report back.&lt;BR /&gt;Yes, historically we've suggested that VPN parameters should match, and in some cases they need to.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 05:39:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/109772#M14988</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-04T05:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/214116#M40879</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;We are also facing the same issue with our VPN.&lt;BR /&gt;&lt;BR /&gt;Is the property change "&lt;STRONG&gt;dpd_allowed_to_init_ike&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;false&lt;/STRONG&gt;&lt;SPAN&gt;." specific to a peer or is it global?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 07:24:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/214116#M40879</guid>
      <dc:creator>raj_p</dc:creator>
      <dc:date>2024-05-14T07:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure S2S VPN Responder Only?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/214236#M40892</link>
      <description>&lt;P&gt;It is specific to the peer on which it is configured in GUIdbedit.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 21:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-S2S-VPN-Responder-Only/m-p/214236#M40892</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-14T21:47:43Z</dc:date>
    </item>
  </channel>
</rss>

