<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to enforce VPN policy (11) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/135067#M20329</link>
    <description>&lt;P&gt;Hi Val, thank you for answer, sorry for late response, meanwhile client has decided for other better solution. If we have same request in future, we will take debug.&lt;/P&gt;</description>
    <pubDate>Sat, 27 Nov 2021 23:42:46 GMT</pubDate>
    <dc:creator>Slavko_Kojic</dc:creator>
    <dc:date>2021-11-27T23:42:46Z</dc:date>
    <item>
      <title>Failed to enforce VPN policy (11)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134127#M20060</link>
      <description>&lt;P&gt;Hello Checkmates,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer has request&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;to establish a VPN tunnel over an existing VPN tunnel ( two miktotiks over existing VTI tunnel between CheckPoint R80.40 and Juniper).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When tunnel is initiated from Miktrotik behind CP, the IKE packet is dropped from CP with message:&lt;BR /&gt;"Failed to enforce VPN policy (11)".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regard, sk106241.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106241#Scenario%202" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106241#Scenario%202&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've changed setting &lt;EM&gt;fw ctl set int encrypt_non_gw_rdp_ike 1&lt;/EM&gt;&amp;nbsp;, but without success&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please, do you have some suggestions about this problem, or is TAC necessary for this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134127#M20060</guid>
      <dc:creator>Slavko_Kojic</dc:creator>
      <dc:date>2021-11-16T08:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to enforce VPN policy (11)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134353#M20127</link>
      <description>&lt;P&gt;Yes, please raise a TAC case. Also, the mentioned SK does not seem to be related to your specific case.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 09:13:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134353#M20127</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-18T09:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to enforce VPN policy (11)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134356#M20128</link>
      <description>&lt;P&gt;Actually, it is relevant. the second case "Site to Site" seems to be your situation. Did you try setting up VPN debug, as SK recommends?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 09:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/134356#M20128</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-18T09:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to enforce VPN policy (11)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/135067#M20329</link>
      <description>&lt;P&gt;Hi Val, thank you for answer, sorry for late response, meanwhile client has decided for other better solution. If we have same request in future, we will take debug.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Nov 2021 23:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-enforce-VPN-policy-11/m-p/135067#M20329</guid>
      <dc:creator>Slavko_Kojic</dc:creator>
      <dc:date>2021-11-27T23:42:46Z</dc:date>
    </item>
  </channel>
</rss>

