<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Both RAVPN and S2S VPN between the same pair of gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115372#M16214</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;this is not as uncommon as you might think.&lt;/P&gt;&lt;P&gt;The main reason for the failing of the RA VPN is that the RA GW sees the IKE packet coming from the peer GW, which it knows is in a VPN community, and tries to create a new S2S tunnel.&lt;/P&gt;&lt;P&gt;Therefore it doesn't try to match the IPSec packet with the RA process and that's why the client connection fails.&lt;/P&gt;&lt;P&gt;In the cases I've encountered this, I took another free public IP on (in your case) GW A and created a hide NAT with this public IP Address for the client networks and the destination the RA GW B.&lt;/P&gt;&lt;P&gt;This way, the client RA VPN Traffic arrives on GW B with a different source IP as the S2S communities GW A and the RA VPN will be established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
    <pubDate>Tue, 06 Apr 2021 10:43:40 GMT</pubDate>
    <dc:creator>Markus_Genser</dc:creator>
    <dc:date>2021-04-06T10:43:40Z</dc:date>
    <item>
      <title>Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115369#M16213</link>
      <description>&lt;P&gt;I have one unusual scenario where two gateways, lets say GW A and GW B, have established S2S VPN tunnel, but still I&amp;nbsp; have a requirement from some customers located behind GW A to have RAVPN connectivity to some servers located behind GW B. S2S VPN is running smoothly, but RAVPN could not be established. I tried to exlude HTTPS and IKE services from the S2S VPN community, but without any success. I checked the logs where I see GW B is rejecting the phase 1 from RAVPN saying:&lt;/P&gt;&lt;P&gt;Main Mode Failed to match proposal: Transform: AES-256, SHA1, Pre-shared secret, Group 2 (1024 bit); Reason: Wrong value for: Authentication Method&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RAVPN is using different proposal than S2S and it seems that GW B cannot differentiate between IKE messages generated by GW A and between IKE generated by side-A customers since they are coming from the same public IP address.&lt;/P&gt;&lt;P&gt;I know this is quite unusual to have such scenario, but I am wondering is there some kind ow workaround have to handle such a situation?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115369#M16213</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2021-04-06T10:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115372#M16214</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;this is not as uncommon as you might think.&lt;/P&gt;&lt;P&gt;The main reason for the failing of the RA VPN is that the RA GW sees the IKE packet coming from the peer GW, which it knows is in a VPN community, and tries to create a new S2S tunnel.&lt;/P&gt;&lt;P&gt;Therefore it doesn't try to match the IPSec packet with the RA process and that's why the client connection fails.&lt;/P&gt;&lt;P&gt;In the cases I've encountered this, I took another free public IP on (in your case) GW A and created a hide NAT with this public IP Address for the client networks and the destination the RA GW B.&lt;/P&gt;&lt;P&gt;This way, the client RA VPN Traffic arrives on GW B with a different source IP as the S2S communities GW A and the RA VPN will be established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115372#M16214</guid>
      <dc:creator>Markus_Genser</dc:creator>
      <dc:date>2021-04-06T10:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115390#M16219</link>
      <description>&lt;P&gt;Just curious, what is the actual error on RA side? Does it even create a site or that fails as well?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 14:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115390#M16219</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-04-06T14:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115396#M16221</link>
      <description>&lt;P&gt;S2S VPN tunnel is forming OK, but RAVPN is not forming because RAVPN GW is trying to establish a new S2S tunnel as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23009"&gt;@Markus_Genser&lt;/a&gt;&amp;nbsp;already described in details. I will test his proposal, I believe it is very good idea.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 14:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115396#M16221</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2021-04-06T14:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115397#M16222</link>
      <description>&lt;P&gt;In a vpn debug on the RA/S2S GW, you can see an entry, that the public IP from the client RA connect belongs to a peer GW for a VPN community and it tries to establish a S2S tunnel.&lt;/P&gt;&lt;P&gt;That pointed me in the past to the conclusion that the RA GW misinterprets the RA connect with the S2S and lead to the workaround with the second hide NAT.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 15:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115397#M16222</guid>
      <dc:creator>Markus_Genser</dc:creator>
      <dc:date>2021-04-06T15:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115401#M16224</link>
      <description>&lt;P&gt;Ah ok, I see now what you are saying. One thing I find sort of odd is that I did exactly same config with 2 customers and did not see this issue at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 15:13:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115401#M16224</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-04-06T15:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115466#M16237</link>
      <description>&lt;P&gt;In my logs I saw that RA GW is actually trying to setup another S2S as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23009"&gt;@Markus_Genser&lt;/a&gt;&amp;nbsp; explained.&amp;nbsp; Very nice idea to use hide NAT as a workaround. I will try it today and keep you posted.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 05:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115466#M16237</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2021-04-07T05:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Both RAVPN and S2S VPN between the same pair of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115473#M16238</link>
      <description>&lt;P&gt;It is working, thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23009"&gt;@Markus_Genser&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 07:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Both-RAVPN-and-S2S-VPN-between-the-same-pair-of-gateways/m-p/115473#M16238</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2021-04-07T07:22:41Z</dc:date>
    </item>
  </channel>
</rss>

