<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec S2S VPN issue - IKEV2 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134567#M20180</link>
    <description>&lt;P&gt;No my issue was not related to that one.&lt;/P&gt;&lt;P&gt;In S2S VPN, Checkpoint negotiating internal IP address as IKE ID to remote side but actually it should negioate with external internet facing IP address.&lt;/P&gt;&lt;P&gt;Even after we have chosen Link selection to use external IP address, still it use internal one. This was observed at remote side network engineer and after he changed remote identity match from actual our gateway external IP to our gateway internal IP, it started working fine.&lt;/P&gt;&lt;P&gt;After 4 months, customer told that VPN connection was stopped working and this was happened just after we installed R81 hotfix take 36. Vendor side engineer checked and confirmed that he now could see IKE ID as our gateway external IP address. Even though this would be correct way, I am wondering how it switching between internal or external IP address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 20 Nov 2021 08:30:00 GMT</pubDate>
    <dc:creator>Nandhakumar</dc:creator>
    <dc:date>2021-11-20T08:30:00Z</dc:date>
    <item>
      <title>IPsec S2S VPN issue - IKEV2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134217#M20088</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Our side gateway - Checkpoint R81&lt;/P&gt;&lt;P&gt;Remote side gateway - Cisco ASR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We built tunnel to remote side and it was working fine for some days and it stopped working since last 3 days. I have checked logs in smart console and observed peer is getting authenticated successfully. After that our gateway sending reject message with "Informational exchange: Exchange failed: timeout reached".&lt;/P&gt;&lt;P&gt;Can someone please advise here, what can we check in this case from our side to make sure nothing caused block from checkpoint end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134217#M20088</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-11-17T07:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec S2S VPN issue - IKEV2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134473#M20154</link>
      <description>&lt;P&gt;Might try:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157473&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157473&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 08:17:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134473#M20154</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-19T08:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec S2S VPN issue - IKEV2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134567#M20180</link>
      <description>&lt;P&gt;No my issue was not related to that one.&lt;/P&gt;&lt;P&gt;In S2S VPN, Checkpoint negotiating internal IP address as IKE ID to remote side but actually it should negioate with external internet facing IP address.&lt;/P&gt;&lt;P&gt;Even after we have chosen Link selection to use external IP address, still it use internal one. This was observed at remote side network engineer and after he changed remote identity match from actual our gateway external IP to our gateway internal IP, it started working fine.&lt;/P&gt;&lt;P&gt;After 4 months, customer told that VPN connection was stopped working and this was happened just after we installed R81 hotfix take 36. Vendor side engineer checked and confirmed that he now could see IKE ID as our gateway external IP address. Even though this would be correct way, I am wondering how it switching between internal or external IP address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Nov 2021 08:30:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134567#M20180</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-11-20T08:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec S2S VPN issue - IKEV2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134575#M20187</link>
      <description>&lt;P&gt;If you were to run this command on your gateway, what do you see:&lt;/P&gt;
&lt;P&gt;tcpdump -nni any host x.x.x.x and proto 50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;where x.x.x.x is external remote IP address&lt;/P&gt;</description>
      <pubDate>Sat, 20 Nov 2021 14:08:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-S2S-VPN-issue-IKEV2/m-p/134575#M20187</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-20T14:08:06Z</dc:date>
    </item>
  </channel>
</rss>

