<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Protocol 50 (ESP) traversing GW do not reach destination in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107792#M14459</link>
    <description>&lt;P&gt;Yes, gateway does have VPN blade enabled and it is required.&lt;/P&gt;
&lt;P&gt;enabled_blades&lt;BR /&gt;fw vpn ips identityServer mon&lt;/P&gt;
&lt;P&gt;I found&amp;nbsp;&lt;SPAN&gt;sk167973, but this is not exactly our case. We do not NAT this traffic and we are running higher JHF than mentioned in SK.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 07:16:15 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2021-01-14T07:16:15Z</dc:date>
    <item>
      <title>Protocol 50 (ESP) traversing GW do not reach destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107703#M14430</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;R80.40 latest JHF&lt;/P&gt;&lt;P&gt;I have an issue where CP gateway is in the middle between nodes establishing site to site vpn tunnel. Access is opened as per requirements, but some tunnels go down and up sporadically. I was able to narrow down to strange traffic for ESP. Comparing working/not working tunnel I find the following difference&lt;/P&gt;&lt;P&gt;working:&lt;/P&gt;&lt;P&gt;vs_0][ppak_0] x:id[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:iD[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:i[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:I[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:o[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:O[44]: site1 -&amp;gt; site2_IP1 (50) len=204 id=44641&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not working:&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:id[44]: site1 -&amp;gt; site2_IP2 (50) len=172 id=22516&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:iD[44]: site1-&amp;gt; site2_IP2 (50) len=172 id=22516&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] x:i[44]: site1-&amp;gt; site2_IP2 (50) len=172 id=22516&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw ctl zdebug + drop |grep "site1" doesn't reveal anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas, besides TAC, which is already involved.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 11:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107703#M14430</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-01-13T11:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol 50 (ESP) traversing GW do not reach destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107763#M14451</link>
      <description>&lt;P&gt;Does the gateway in question even have VPN enabled?&lt;BR /&gt;If so, does it need to?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 22:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107763#M14451</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-13T22:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol 50 (ESP) traversing GW do not reach destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107792#M14459</link>
      <description>&lt;P&gt;Yes, gateway does have VPN blade enabled and it is required.&lt;/P&gt;
&lt;P&gt;enabled_blades&lt;BR /&gt;fw vpn ips identityServer mon&lt;/P&gt;
&lt;P&gt;I found&amp;nbsp;&lt;SPAN&gt;sk167973, but this is not exactly our case. We do not NAT this traffic and we are running higher JHF than mentioned in SK.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 07:16:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/107792#M14459</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-01-14T07:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol 50 (ESP) traversing GW do not reach destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/108318#M14603</link>
      <description>&lt;P&gt;Any idea how to check why traffic is not passing from small "i" to big "I"?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 16:19:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/108318#M14603</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-01-20T16:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol 50 (ESP) traversing GW do not reach destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/108322#M14605</link>
      <description>&lt;P&gt;The debug in that SK doesn't seem to show a drop message. Have you tried that debug vs just doing a drop? I would also send output to a file then grep that file or turn on line buffering in grep just to be safe.&lt;/P&gt;&lt;P&gt;Bandaid warning: Just throwing this out there. If you can get them to switch to NAT-T mode on the vpn tunnel you might be able to work around.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 16:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Protocol-50-ESP-traversing-GW-do-not-reach-destination/m-p/108322#M14605</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2021-01-20T16:34:07Z</dc:date>
    </item>
  </channel>
</rss>

