<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111439#M15393</link>
    <description>&lt;P&gt;The Azure side of the VPN will also need to know about the Office Mode subnet (i.e. it needs a route back).&lt;BR /&gt;I believe an fw monitor will show the traffic going towards the Azure VPN endpoint and back.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Feb 2021 18:47:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-02-21T18:47:26Z</dc:date>
    <item>
      <title>Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111244#M15355</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hello everyone,&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have been trying to setup a VPN between a Checkpoint R80.30 Cluster and Azure Virtual Network Gateway following sk101275 .&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I am trying with a very standard IKEv1 Policy Based IPsec tunnel.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Private subnets behind Azure (10.10.0.0/21 and 10.20.0.0/21)&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Private subnets behind Azure (172.30.0.0/24, 172.30.102.0/24, 172.30.24.0/24 etc.) (around 30 subnets)&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have specified the exact remote subnets for each side.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Made sure Phase1 and Phase2 parameters match.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;The VPN seems to get established immediately. The Azure side shows as Connected and Checkpoint sees the Tunnel state as up. On checkpoint I run "vpn tu" and can see Phase1 and Phase2 SAs established.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have a security policy allowing the traffic between the subnets.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Problem is we can't pass traffic.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;When I try sending ICMP from a IP behind the checkpoint 172.30.0.51 to 10.10.2.4 I get a Reject log with the following info:&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Reject Category: IKE Failure&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;VPN Failure: IKE&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Encryption failure: Error occurred&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Also I believe after a few minutes the tunnel flaps and gets re-established. I noticed that twice in around 20min.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;When I filter for the IP I am trying to ping.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;A href="https://imgur.com/ZEllznb" target="_blank" rel="noopener nofollow ugc"&gt;https://imgur.com/ZEllznb&lt;/A&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;A href="https://imgur.com/G3BBDrn" target="_blank" rel="noopener nofollow ugc"&gt;https://imgur.com/G3BBDrn&lt;/A&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;When I filter for remote peer public IP&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;A href="https://imgur.com/ScejoTZ" target="_blank" rel="noopener nofollow ugc"&gt;https://imgur.com/ScejoTZ&lt;/A&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;A href="https://imgur.com/SFjgwRD" target="_blank" rel="noopener nofollow ugc"&gt;https://imgur.com/SFjgwRD&lt;/A&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I can provide more information if needed.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 00:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111244#M15355</guid>
      <dc:creator>InfraNinja</dc:creator>
      <dc:date>2021-02-19T00:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111271#M15361</link>
      <description>&lt;P&gt;You’ll need to do some deeper debugs.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110348&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110348&amp;amp;partition=Advanced&amp;amp;product=Mobile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 07:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111271#M15361</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-19T07:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111431#M15389</link>
      <description>&lt;P&gt;Thanks, I went through the document but not sure how this is relevant to the issue I am facing.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 14:29:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111431#M15389</guid>
      <dc:creator>InfraNinja</dc:creator>
      <dc:date>2021-02-21T14:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111438#M15392</link>
      <description>&lt;P&gt;Okay I manged to fix this using Route Based IKEv2 VPN.&lt;/P&gt;&lt;P&gt;My goal now is to route traffic from my Remote Access VPN to that new Azure VPN. Is that possible?&lt;BR /&gt;I have added the subnet that is behind Azure to the VPN community for Remote access, so now when I connect to Client VPN I get a route for the subnet that is behind Azure in my local route table.&lt;BR /&gt;Is that the only thing that needs to be done?&lt;/P&gt;&lt;P&gt;When I initiate traffic from my VPN user pool to network behind Azure I get a log for the traffic arriving from Remote Access VPN, but no log for the traffic afterwards being sent over the Azure VPN tunnel. Is there any way I can confirm if it actually is being sent correctly?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 18:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111438#M15392</guid>
      <dc:creator>InfraNinja</dc:creator>
      <dc:date>2021-02-21T18:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111439#M15393</link>
      <description>&lt;P&gt;The Azure side of the VPN will also need to know about the Office Mode subnet (i.e. it needs a route back).&lt;BR /&gt;I believe an fw monitor will show the traffic going towards the Azure VPN endpoint and back.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 18:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111439#M15393</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-21T18:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111453#M15400</link>
      <description>&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;I ran an Ping from my laptop connected to remote VPN (laptop IP: 172.30.102.25) towards host in Azure (10.10.2.4) while running fw monitor.&lt;/P&gt;&lt;P&gt;Attached is the output. I don't expect ICMP to go through, just doing it to test the routing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I'm still not sure if the traffic is passing through the VPN or not.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 22:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111453#M15400</guid>
      <dc:creator>InfraNinja</dc:creator>
      <dc:date>2021-02-21T22:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from Check Point R80.30 to Azure Virtual Network Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111631#M15435</link>
      <description>&lt;P&gt;I was able to sort this out using Route Based IKEv2 VPN&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 13:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-from-Check-Point-R80-30-to-Azure-Virtual/m-p/111631#M15435</guid>
      <dc:creator>InfraNinja</dc:creator>
      <dc:date>2021-02-23T13:44:19Z</dc:date>
    </item>
  </channel>
</rss>

