<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79654#M19875</link>
    <description>Yes, I have the rules allowing connectivity to Fortinet.</description>
    <pubDate>Wed, 25 Mar 2020 09:30:41 GMT</pubDate>
    <dc:creator>fcecilia</dc:creator>
    <dc:date>2020-03-25T09:30:41Z</dc:date>
    <item>
      <title>IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79487#M19867</link>
      <description>&lt;P&gt;Hi!,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem creating a VPN between checkpoint and fortinet. The VPN is up but I only have traffic (for example ping) in the direction of Fortinet towards checkpoint.&lt;/P&gt;&lt;P&gt;The rules is well created as other community VPNs that work fine.&lt;BR /&gt;Do you know if there is any special configuration so that there is traffic on the VPN in the direction Checkpoint-&amp;gt; Fortinet?&lt;/P&gt;&lt;P&gt;The community VPN configuration of the checkpoint is the same as that installed with other FWs such as Dlinks firewalls and Dlink works fine.&lt;/P&gt;&lt;P&gt;My checkpoint model is 5600 Appliance, running 80.10 Gaia SO.&lt;/P&gt;&lt;P&gt;My configuration:&lt;/P&gt;&lt;P&gt;-Destination firewallL: IP public&lt;/P&gt;&lt;P&gt;-Ike v1&lt;/P&gt;&lt;P&gt;-main mode&lt;/P&gt;&lt;P&gt;-encryption AES.&lt;/P&gt;&lt;P&gt;-VPN tunnel per subnet&lt;/P&gt;&lt;P&gt;- local and remote network are /24 mask&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 08:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79487#M19867</guid>
      <dc:creator>fcecilia</dc:creator>
      <dc:date>2020-03-24T08:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79529#M19868</link>
      <description>&lt;P&gt;Look for drop logs. If nothing, fw ctl zdebug drop.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, check routes. Fortinet VPN domain should be routed to the external interface of your CP FW.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 10:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79529#M19868</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-24T10:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79537#M19869</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Fortinet VPN domain should be routed to the external interface of your CP FW&lt;/STRONG&gt;. -&amp;gt; This is done moreover, &lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I configure IPSEC vpn between two fortis with the policies and routes and it works well. (attach photo).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;fw ctl zdebug drop -&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I will try this command but in the tracert window Gaia I get the packets with encrypted VPN accepted.&lt;/SPAN&gt; &lt;SPAN&gt;Should I run that command out of production?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I have read that it could lower the performance of the Fw.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Thanks and Regards!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 11:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79537#M19869</guid>
      <dc:creator>fcecilia</dc:creator>
      <dc:date>2020-03-24T11:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79540#M19870</link>
      <description>&lt;P&gt;You keep sending me pictures from Forti. There is no point.&lt;/P&gt;
&lt;P&gt;If I understand you correctly, with the tunnel up, you can reach CP VPN domain from Forti side, but the opposite does not work. Is it correct?&lt;BR /&gt;&lt;BR /&gt;If yes, check what happens with the traffic on Check Point side. Is it sent to the tunnel? Is it dropped? Is it routed somewhere else, clear text? Depending on the answer, we can point a finger to the issue and fix&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 11:41:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79540#M19870</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-24T11:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79544#M19871</link>
      <description>CP VPN domain is up also but I cant ping to fortinet subnet.&lt;BR /&gt;&lt;BR /&gt;Ok I going to run fw ctl zdebug tool.</description>
      <pubDate>Tue, 24 Mar 2020 12:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79544#M19871</guid>
      <dc:creator>fcecilia</dc:creator>
      <dc:date>2020-03-24T12:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79551#M19872</link>
      <description>&lt;P&gt;On CP, do you have FW rules allowing connectivity to the remote VPN site?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 12:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79551#M19872</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-24T12:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79566#M19873</link>
      <description>&lt;P&gt;The Fortinet can successfully initiate to the Check Point because when the Check Point is the responder it is not picky about getting an exact match for the IKE Phase 2 subnets/Proxy-IDs proposed by the Fortinet, as long as the proposed subnets fall completely within the defined VPN domains for both peers the Check Point will accept it.&lt;/P&gt;
&lt;P&gt;However when the Check Point is the initiator, as the responder the Fortinet is VERY PICKY and its subnets configuration must exactly match what is being proposed by the Check Point or it will fail.&amp;nbsp; Everything including subnet mask length must match exactly.&amp;nbsp; See my response in this thread for how to force the Check Point to propose exactly what the Fortinet wants so it will match exactly:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-fortigate-v5-6-and-CheckPoint-R80-10/m-p/10062" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-fortigate-v5-6-and-CheckPoint-R80-10/m-p/10062&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Alternatively, if you are using R80.40+ on both management and gateway, there is a new capability to create user-defined VPN domains for both participating gateways on a per-community basis that will give you the granularity needed to match what the Fortinet is expecting in the Phase 2 proposal from the Check Point.&amp;nbsp; You will also experience this same "picky" behavior with Juniper and Sonicwall among others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 15:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79566#M19873</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-03-24T15:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79653#M19874</link>
      <description>The remote subnet (192.168.0.X/24) and the local subnet (10.190.0.X/24) are correctly configured with mask / 24 both. I will try to do the configuration proposed in Scenario 1 of sk108600 and see if it works. My version is R80.10.&lt;BR /&gt;Thanks!</description>
      <pubDate>Wed, 25 Mar 2020 09:29:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79653#M19874</guid>
      <dc:creator>fcecilia</dc:creator>
      <dc:date>2020-03-25T09:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79654#M19875</link>
      <description>Yes, I have the rules allowing connectivity to Fortinet.</description>
      <pubDate>Wed, 25 Mar 2020 09:30:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/79654#M19875</guid>
      <dc:creator>fcecilia</dc:creator>
      <dc:date>2020-03-25T09:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Checkpoint R80.10 and Fortinet issue. Only traffic in one direction.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/133556#M19876</link>
      <description>&lt;P&gt;Hi, I have a similar problem with a fortinet. Attach you an image. The VPN issue is about IKE when I need connect the checkpoint to Fortinet. I followed all instructions from&amp;nbsp;&lt;SPAN&gt;How to set up a Site-to-Site VPN with a 3rd-party remote gateway. Can you help me?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 22:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Checkpoint-R80-10-and-Fortinet-issue-Only-traffic-in-one/m-p/133556#M19876</guid>
      <dc:creator>oscars</dc:creator>
      <dc:date>2021-11-08T22:50:02Z</dc:date>
    </item>
  </channel>
</rss>

