<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC phase2 per subnet still creating per host in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108640#M14694</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you share example of the log where this happens? Yes, there are some supernetting guidbedit things that changed in R80, compared to before in R77. There is also file on mgmt server called crypt.def for excluding certain IP ranges, but does not sound you even have that configured. Is it only one tunnel with this issue or multiple? If its one, you can simply reset it via vpn tu command on gateway, but if its multiple, sounds like it could be global issue. Happy to do remote session and see if I can help you fix it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jan 2021 04:08:23 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-01-24T04:08:23Z</dc:date>
    <item>
      <title>IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108590#M14658</link>
      <description>&lt;P&gt;I have a GAIA R77.30 gateway.&amp;nbsp; We recently upgraded our management station to R80.40.&amp;nbsp; Since then we are noticing that tunnels that we have created for per subnet are having issues.&amp;nbsp; When we examine the logs we noticed that the gateway is actually attempting to create a per host tunnel.&amp;nbsp; We are noticing multiple SA's in phase 2 when we should only see one since all our clients are on the same /24 network.&amp;nbsp; Does anyone have any suggestions.&lt;/P&gt;&lt;P&gt;Thank you for whatever help you can offer.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 06:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108590#M14658</guid>
      <dc:creator>jtorella-chsli</dc:creator>
      <dc:date>2021-01-23T06:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108591#M14659</link>
      <description>&lt;P&gt;Could be this issue:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39679&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39679&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 06:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108591#M14659</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-23T06:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108633#M14687</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;Thank you but we are not using exclusions in our encryption domain for this community,&amp;nbsp; We created a group with just the subnets that are needed in the encryption domain.&amp;nbsp; We did try "One tunnel per gateway pair" with no luck.&amp;nbsp; This problem seem to only start when we updated our management station to R80.40 and the gateways are still R77.30.&amp;nbsp; &amp;nbsp;Could there be an incompatibility between the management station and gateways?&amp;nbsp; Also I know that the management station R80.40 supports "user defined" domain for each community but does the R77.30 gateways support it?&amp;nbsp; When I pushed policy I didn't get any errors so i assumed it works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:01:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108633#M14687</guid>
      <dc:creator>jtorella-chsli</dc:creator>
      <dc:date>2021-01-24T03:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108636#M14690</link>
      <description>&lt;P&gt;R80.40 can manage R77.30 gateways.&lt;BR /&gt;However, R77.30 is End of Support.&lt;/P&gt;
&lt;P&gt;As far as I know, the VPN Domain Per Community feature does not require gateways to also be on R80.40+.&lt;BR /&gt;However, at least for SMB appliances running R77.20.x, it doesn't appear to work:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-40-Question-about-encryption-domain-per-VPN-community/td-p/82738" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/R80-40-Question-about-encryption-domain-per-VPN-community/td-p/82738&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can open a TAC case here, but support will only be provided on best-effort basis.&lt;BR /&gt;Upgrading to a supported release is definitely recommended.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:12:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108636#M14690</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-24T03:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108640#M14694</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you share example of the log where this happens? Yes, there are some supernetting guidbedit things that changed in R80, compared to before in R77. There is also file on mgmt server called crypt.def for excluding certain IP ranges, but does not sound you even have that configured. Is it only one tunnel with this issue or multiple? If its one, you can simply reset it via vpn tu command on gateway, but if its multiple, sounds like it could be global issue. Happy to do remote session and see if I can help you fix it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 04:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108640#M14694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T04:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108676#M14705</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; We did open a TAC case already and they cant explain it either.&amp;nbsp; We have it set to per subnet but it is clearly doing per host.&amp;nbsp; As a temporary fix we asked our partner to set their side (ASA) to per host and things are working.&amp;nbsp; Our partner does want to leave the tunnel as per host permanently and would like us to resolve so they can set it back to per subnet.&amp;nbsp; We will continue to push TAC to looking it further.&amp;nbsp; Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 18:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/108676#M14705</guid>
      <dc:creator>jtorella-chsli</dc:creator>
      <dc:date>2021-01-24T18:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC phase2 per subnet still creating per host</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/187075#M34448</link>
      <description>&lt;P&gt;i all, anyone did fix this issue?&lt;/P&gt;
&lt;P&gt;this is causing random outage to traffic flow inside the vpn in a one-direction way:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="peersa1.JPG" style="width: 379px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21825i0CC61905D1DA62A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="peersa1.JPG" alt="peersa1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;r81.10 t79&lt;/P&gt;
&lt;P&gt;the fix is not the one in&amp;nbsp;sk39679&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-phase2-per-subnet-still-creating-per-host/m-p/187075#M34448</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-07-20T13:55:31Z</dc:date>
    </item>
  </channel>
</rss>

