<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC PHASE2 not coming up in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129614#M18985</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;Thanks for responding. Yes in PA i removed the subnet and defined /32 host IP and on CP i did few changes in database tools (snaps attached). This worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2021 04:19:37 GMT</pubDate>
    <dc:creator>Nick_Shah</dc:creator>
    <dc:date>2021-09-17T04:19:37Z</dc:date>
    <item>
      <title>IPSEC PHASE2 not coming up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129210#M18896</link>
      <description>&lt;P&gt;I have built a IPSEC tunnel between PA and CP. When i initiate traffic from PC sitting behind CP, phase 1 comes up on both FW. But phase 2 fails, i tried every possible modification in phase 2 settings(same on both end), changed intresting traffic (subnet) coming to CP as well. But i couldn't succeed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CA has10.168.1.0/24&lt;/P&gt;&lt;P&gt;PA has 200.1.1.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below logs i captured.&lt;/P&gt;&lt;P&gt;PHASE1:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PHASE1" style="width: 629px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13673i63EDD5911BC0FDCB/image-dimensions/629x407?v=v2" width="629" height="407" role="button" title="CP_phase1_capture.PNG" alt="PHASE1" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;PHASE1&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PHASE2:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PHASE2 FAILED LOG" style="width: 601px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13672i3924109E24A95069/image-dimensions/601x368?v=v2" width="601" height="368" role="button" title="CP_phase2_capture.PNG" alt="PHASE2 FAILED LOG" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;PHASE2 FAILED LOG&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA PHASE 1 shows UP" style="width: 816px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13674i27E0610514D9CEA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="PA_phase1.PNG" alt="PA PHASE 1 shows UP" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;PA PHASE 1 shows UP&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tcpdump" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13675iC2E14D14AF697E67/image-size/large?v=v2&amp;amp;px=999" role="button" title="tcpdump.PNG" alt="tcpdump" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;tcpdump&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reset the tunnel and initiated traffic from PA and i am able to ping. If there was config mismatch i shouldn't be able to reach from PA as well.&lt;/P&gt;&lt;P&gt;Router#ping 10.168.1.1 rep 100&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 100, 100-byte ICMP Echos to 10.168.1.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;Success rate is 100 percent (100/100), round-trip min/avg/max = 24/31/44 ms&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 12 Sep 2021 16:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129210#M18896</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2021-09-12T16:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PHASE2 not coming up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129217#M18897</link>
      <description>&lt;P&gt;It’s a configuration issue if you can initiate a VPN connection in one direction but not the other.&lt;BR /&gt;A full set of debugs will be helpful:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk63560" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk63560&lt;/A&gt;&lt;BR /&gt;Many common issues with third party VPNs are listed here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Sep 2021 18:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129217#M18897</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-12T18:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PHASE2 not coming up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129325#M18916</link>
      <description>&lt;P&gt;Need to see the two ID fields decoded in&amp;nbsp; QM packet 1 when the Check Point is the initiator.&amp;nbsp; Whatever is there does not match the Palo Alto which uses a universal tunnel (double 0.0.0.0/0's) by default, but the Palo can be configured to mimic a domain-based VPN via the configuration of Proxy-IDs.&amp;nbsp; Did you configure that on the Palo side?&amp;nbsp; If so they must EXACTLY match what the Check Point is proposing in Phase 2, a subset will not work.&amp;nbsp; But a subset will be accepted by the Check Point if the Palo is proposing which is why it works in that direction.&lt;/P&gt;
&lt;P&gt;If the Palo receives a Phase 2 proposal that doesn't match its configuration the Palo will just discard it and not answer (which is what the tcpdump shows), same as Juniper.&amp;nbsp; Funny I seem to recall a lawsuit awhile back about these coincidental similarities...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 19:43:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129325#M18916</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-09-13T19:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PHASE2 not coming up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129614#M18985</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;Thanks for responding. Yes in PA i removed the subnet and defined /32 host IP and on CP i did few changes in database tools (snaps attached). This worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 04:19:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-PHASE2-not-coming-up/m-p/129614#M18985</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2021-09-17T04:19:37Z</dc:date>
    </item>
  </channel>
</rss>

