<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Troubles after installing R80.30 Take 228... in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115149#M16157</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24246"&gt;@Thomas_Eichelbu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We upgraded couple of HA clusters from R80.20 to R80.40 with the latest jumbo 94 and almost of all them which use ISP redundancy have VPN issues. For instance when we check "List all IPsec SAs for a given peer (GW) or user (Client)" with vpn tu for problematic peer we have the following:&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;968dda368fda4b4e,242e1e63727f3a1c&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;7d6c24dcd3e9697d,9a9edc436fae11df&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;d0fbeb6e8966e95d,6bcdc87e88e5c311&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;e0549c9dc402adc6,3e0eb30596d67909&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;0aa6e7b39c18bd61,a02b4a5168a19a4d&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;05943b6d1a73fe36,8d6613131c033a59&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we reset the tunnel everything comes back to normal and after some random period the problem starts again. The issue exists for the VPNs between gateways part of the same management, together with other Check Point devices which are part of another management. We tried to turn off fwaccel but the result was the same. Case is opened to TAC, but they need the results from "heavy VPN debug" which could overload the devices. Please give some updates if you have something useful from TAC.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 02 Apr 2021 14:23:52 GMT</pubDate>
    <dc:creator>mk1</dc:creator>
    <dc:date>2021-04-02T14:23:52Z</dc:date>
    <item>
      <title>VPN Troubles after installing R80.30 Take 228...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115138#M16153</link>
      <description>&lt;P&gt;Hello Check Pointers ...&lt;/P&gt;&lt;P&gt;Question:&lt;BR /&gt;We did some upgrades on&amp;nbsp; R80.30 clusters from &lt;EM&gt;&lt;STRONG&gt;Take 196&lt;/STRONG&gt;&lt;/EM&gt; to &lt;EM&gt;&lt;STRONG&gt;Take 228&lt;/STRONG&gt;&lt;/EM&gt; and encountered an increase of VPN issues ...&lt;BR /&gt;They are hard to grasp in total, but we saw a big increase of outage warnings by our monitoring systems.&lt;BR /&gt;&lt;BR /&gt;for example we saw this is /var/log/message -&amp;gt; but thousends and thousends of them!!!&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[fw4_27];FW-1: cphwd_crypt_upd_link_selection_stat_cb: link selection update API failed &lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[fw4_6];FW-1: cphwd_crypt_upd_link_selection_stat_cb: link selection update API failed &lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[fw4_6];FW-1: cphwd_crypt_upd_link_selection_stat_cb: link selection update API failed&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN&gt;[fw4_13];cphwd_update_crypto_info_and_resume_chain: failed to get sxl_devvfw4_13];FW-1:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and this here.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;[fw4_0];cphwd_update_crypto_info_and_resume_chain: corr info (sxl_dev_id:0) - app opaque (sxl_dev_id:32) mismatch&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[fw4_0];cphwd_update_crypto_info_and_resume_chain: failed to get sxl_dev&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;there is an SK for this message -&amp;gt;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk160612" target="_blank" rel="noopener"&gt;sk160612&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;but does not help.&lt;BR /&gt;&lt;BR /&gt;other issues are, Client VPN it sometimes just disconnects, many Stateful Inspection issues in VPN and just instability.&lt;BR /&gt;so very unprecise it total.&lt;BR /&gt;&lt;BR /&gt;also i see this messages also on R80.40 Take 94.&lt;BR /&gt;&lt;BR /&gt;and yes we use IPSec Link Selection with LS and ISP Redundancy with Internet and MPLS lines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;gt; TAC cases are opened also ... lets see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 09:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115138#M16153</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-04-02T09:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Troubles after installing R80.30 Take 228...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115149#M16157</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24246"&gt;@Thomas_Eichelbu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We upgraded couple of HA clusters from R80.20 to R80.40 with the latest jumbo 94 and almost of all them which use ISP redundancy have VPN issues. For instance when we check "List all IPsec SAs for a given peer (GW) or user (Client)" with vpn tu for problematic peer we have the following:&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;968dda368fda4b4e,242e1e63727f3a1c&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;7d6c24dcd3e9697d,9a9edc436fae11df&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;d0fbeb6e8966e95d,6bcdc87e88e5c311&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;e0549c9dc402adc6,3e0eb30596d67909&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;0aa6e7b39c18bd61,a02b4a5168a19a4d&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;05943b6d1a73fe36,8d6613131c033a59&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we reset the tunnel everything comes back to normal and after some random period the problem starts again. The issue exists for the VPNs between gateways part of the same management, together with other Check Point devices which are part of another management. We tried to turn off fwaccel but the result was the same. Case is opened to TAC, but they need the results from "heavy VPN debug" which could overload the devices. Please give some updates if you have something useful from TAC.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 14:23:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115149#M16157</guid>
      <dc:creator>mk1</dc:creator>
      <dc:date>2021-04-02T14:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Troubles after installing R80.30 Take 228...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115152#M16159</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have seen that too ... i updated a cluster from R80.30 to R80.40 Take 94 ...&lt;BR /&gt;Link Selection in HA and ISP Redundany were configured ...&lt;/P&gt;&lt;P&gt;all tunnel to the&amp;nbsp; remote sites were off after installing both machines ...&amp;nbsp;&lt;BR /&gt;the tunnel went on and off in a rapid manner ...&amp;nbsp;&lt;BR /&gt;but client vpn worked and safed my day &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;a tunnel reset for all tunnels had helped ...&amp;nbsp;&lt;BR /&gt;now all is stable ... perhaps a one time wonder ..&lt;BR /&gt;but the messages from /var/log/messages are still present.&lt;BR /&gt;&lt;BR /&gt;-&amp;gt; TAC is already working on the log entries ... i keep you updated!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 14:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Troubles-after-installing-R80-30-Take-228/m-p/115152#M16159</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-04-02T14:37:21Z</dc:date>
    </item>
  </channel>
</rss>

