<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internet Traffic from VPN being blocked in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114462#M16014</link>
    <description>&lt;P&gt;Hello forum!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hoping to get some fresh eyes on an issue im am dealing with currently.&lt;/P&gt;&lt;P&gt;I have a firewall in Azure connected back to us (HQ) over ipsec VPN. Virtual machines can communicate with HQ with no issues, however, they cannot get to the internet. I see in the logs the traffic is being dropped by my FW. Here is the exact error i am receiving:&lt;/P&gt;&lt;P&gt;Id: c0a801c9-1611-7109-605b-3a433ba90001&lt;BR /&gt;Marker: @A@@B@1616558409@C@2612367&lt;BR /&gt;Log Server Origin: x.x.x.x&lt;BR /&gt;Time: 2021-03-24T13:10:27Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth1-02&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 179&lt;BR /&gt;Log ID: 404821&lt;BR /&gt;Source: 10.0.100.5&lt;BR /&gt;Source Port: 50529&lt;BR /&gt;Destination: 20.60.132.4&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Scheme: IKE&lt;BR /&gt;Methods: ESP: AES-128 + SHA1 + PFS (group 14)&lt;BR /&gt;VPN Peer Gateway: x.x.x.x&lt;BR /&gt;Encryption Failure: According to the policy the packet should not have been decrypted&lt;BR /&gt;VPN Feature: VPN&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Connection&lt;BR /&gt;Policy Name: HB-Custom-Policy&lt;BR /&gt;Policy Management: cpman&lt;BR /&gt;Db Tag: {3138C08A-7834-2645-8B4F-36751CECDF37}&lt;BR /&gt;Policy Date: 2021-03-18T19:00:14Z&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Origin: HBFW1&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;File Size: 0&lt;BR /&gt;Interface: eth1-02&lt;BR /&gt;Description:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 10.0.100.5 is the VM that is trying to access windows updates&amp;nbsp;20.60.132.4 in the log details above.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have the subnet 10.0.100.0 in the route table pointing to our gateway&lt;/LI&gt;&lt;LI&gt;I have a network object for 10.0.100.0/23 in the internet allowed out policy&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I can ping from 10.0.100.5 our GW&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any direction here would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 13:28:30 GMT</pubDate>
    <dc:creator>Fabian_Maldonad</dc:creator>
    <dc:date>2021-03-24T13:28:30Z</dc:date>
    <item>
      <title>Internet Traffic from VPN being blocked</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114462#M16014</link>
      <description>&lt;P&gt;Hello forum!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hoping to get some fresh eyes on an issue im am dealing with currently.&lt;/P&gt;&lt;P&gt;I have a firewall in Azure connected back to us (HQ) over ipsec VPN. Virtual machines can communicate with HQ with no issues, however, they cannot get to the internet. I see in the logs the traffic is being dropped by my FW. Here is the exact error i am receiving:&lt;/P&gt;&lt;P&gt;Id: c0a801c9-1611-7109-605b-3a433ba90001&lt;BR /&gt;Marker: @A@@B@1616558409@C@2612367&lt;BR /&gt;Log Server Origin: x.x.x.x&lt;BR /&gt;Time: 2021-03-24T13:10:27Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth1-02&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 179&lt;BR /&gt;Log ID: 404821&lt;BR /&gt;Source: 10.0.100.5&lt;BR /&gt;Source Port: 50529&lt;BR /&gt;Destination: 20.60.132.4&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Scheme: IKE&lt;BR /&gt;Methods: ESP: AES-128 + SHA1 + PFS (group 14)&lt;BR /&gt;VPN Peer Gateway: x.x.x.x&lt;BR /&gt;Encryption Failure: According to the policy the packet should not have been decrypted&lt;BR /&gt;VPN Feature: VPN&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Connection&lt;BR /&gt;Policy Name: HB-Custom-Policy&lt;BR /&gt;Policy Management: cpman&lt;BR /&gt;Db Tag: {3138C08A-7834-2645-8B4F-36751CECDF37}&lt;BR /&gt;Policy Date: 2021-03-18T19:00:14Z&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Origin: HBFW1&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;File Size: 0&lt;BR /&gt;Interface: eth1-02&lt;BR /&gt;Description:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 10.0.100.5 is the VM that is trying to access windows updates&amp;nbsp;20.60.132.4 in the log details above.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have the subnet 10.0.100.0 in the route table pointing to our gateway&lt;/LI&gt;&lt;LI&gt;I have a network object for 10.0.100.0/23 in the internet allowed out policy&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I can ping from 10.0.100.5 our GW&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any direction here would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 13:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114462#M16014</guid>
      <dc:creator>Fabian_Maldonad</dc:creator>
      <dc:date>2021-03-24T13:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Traffic from VPN being blocked</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114642#M16040</link>
      <description>&lt;P&gt;Hi Fabian.&lt;/P&gt;&lt;P&gt;Which routing configuration you're using for the VPN Community?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The message&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;According to the policy the packet should not have been decrypted&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;indicates that the source machines are trying to reach an encryption domain that is not exchanged by the two gateways. You should configure routing in the community or manually add&amp;nbsp;&lt;SPAN&gt;20.60.132.4&amp;nbsp;to your encryption domain exchanged between both devices.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 17:04:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114642#M16040</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2021-03-25T17:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Traffic from VPN being blocked</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114661#M16045</link>
      <description>&lt;P&gt;First, test connectivity from Azure CP GW to the Internet (ping &lt;A href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt; or curl_cli -k &lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Then check if you are preventing NAT between your Azure hosts and on-premises.&lt;/P&gt;
&lt;P&gt;THen check if you are NATing your hosts to "Hide behind Gateway's IP" on their way to the Internet and enable that if it is not done yet.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 21:28:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114661#M16045</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-03-25T21:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Traffic from VPN being blocked</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114674#M16049</link>
      <description>&lt;P&gt;Vladimir is correct...that type of error may indicate nat issues, but it also could be related to vpn domain as well. Could you do ike debug when trying this, as that would show you exactly where its failing, phase 1 or 2 and what packet exactly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 23:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internet-Traffic-from-VPN-being-blocked/m-p/114674#M16049</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-25T23:30:23Z</dc:date>
    </item>
  </channel>
</rss>

