<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling &amp;quot;support Nat-t&amp;quot; on Gatewa in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109278#M14830</link>
    <description>&lt;P&gt;Oh, you have a 5100 ! I just worked 20min to answer your question as if you had a 1500 SMB &lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;. Bad place, to post it on SMB...&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 11:33:48 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-01-29T11:33:48Z</dc:date>
    <item>
      <title>site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109267#M14829</link>
      <description>&lt;P&gt;So I have a site to site VPN with a Cisco ASA device from my Clustered 5100 firewalls.&amp;nbsp; The tunnel comes up, but they cannot see any traffic coming from my side.&amp;nbsp; I believe the issue is with IKEV2 and the "support Nat-t" on Gateway according to SK5390.&lt;/P&gt;&lt;P&gt;I have about 40 site to site VPNS configured and only this one is using IKEv2. We also have checkpoint mobile clients connecting in to our 5100.&amp;nbsp; What is the impact if I disable the option to "Support NAT-T" on the gateway for the checkpoint mobile clients?&amp;nbsp; Is there a way to disable NAT-T for just one site to site VPN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 10:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109267#M14829</guid>
      <dc:creator>Daniel_Bourne</dc:creator>
      <dc:date>2021-01-29T10:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109278#M14830</link>
      <description>&lt;P&gt;Oh, you have a 5100 ! I just worked 20min to answer your question as if you had a 1500 SMB &lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;. Bad place, to post it on SMB...&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 11:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109278#M14830</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-29T11:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109284#M14831</link>
      <description>&lt;P&gt;Sorry, I thought that was the correct area.&amp;nbsp; Not sure how to change that or delete the post unfortunately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 12:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109284#M14831</guid>
      <dc:creator>Daniel_Bourne</dc:creator>
      <dc:date>2021-01-29T12:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109291#M14832</link>
      <description>&lt;P&gt;My recommendation for interoperable VPNs is to try IKEv2 with them, but do not hesitate to return to IKEv1 if there are any problems.&amp;nbsp; I'm not sure where you got that SK number, but I think this is the one you want:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165003&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk165003: When Security Gateway initiates VPN tunnel with 3rd Party peer using &lt;STRONG&gt;IKEv2&lt;/STRONG&gt;, VPN tunnel is forced to &lt;STRONG&gt;NAT-T&lt;/STRONG&gt; and traffic fails&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also possible that your situation is a known bug on the Cisco side, see here:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_2_3f747a7d22d34f_1dfb44" class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/General-Topics/VPN-issue-with-IKEv2-and-Cisco-ASA/m-p/64830?search-action-id=21506175181&amp;amp;search-result-uid=64830" target="_blank"&gt;VPN issue with IKEv2 and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="lia-search-match-lithium"&gt;Cisco&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ASA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 13:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109291#M14832</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-01-29T13:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109292#M14833</link>
      <description>&lt;P&gt;Message me privately, we can do remote session...I hope I would be able to help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 13:52:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109292#M14833</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-29T13:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109331#M14840</link>
      <description>&lt;P&gt;Has been relocated thanks to &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; i guess 8)&lt;/img&gt; -&amp;nbsp; that is how it is done...&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 09:47:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109331#M14840</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-30T09:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN, IKEv2 and Nat-T issue, Impact of disabling "support Nat-t" on Gatewa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109504#M14928</link>
      <description>&lt;P&gt;Yes, threads can only be moved by admins &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 22:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/site-to-site-VPN-IKEv2-and-Nat-T-issue-Impact-of-disabling-quot/m-p/109504#M14928</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-01T22:51:37Z</dc:date>
    </item>
  </channel>
</rss>

