<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN issue with R80.40 JHFA Take 126 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135665#M20478</link>
    <description>&lt;P&gt;After working a bit with support, I reverted one gateway in the central cluster to JHFA Take 102. When I made that gateway the active, the tunnel came up. Switching the active back to gateway with Take 126, the tunnel failed to come up. I will be sending support more logs soon.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Dec 2021 18:55:27 GMT</pubDate>
    <dc:creator>David_C1</dc:creator>
    <dc:date>2021-12-06T18:55:27Z</dc:date>
    <item>
      <title>S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/134742#M20238</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I have VPN star community with Check Point R80.40 clustered gateway as center gateway, with 21 Check Point 1430s (locally managed) as satellite gateways. Since applying JHFA Take 126 to the center gateways, one of the VPN tunnels fails to establish from the center gateway to the satellite. The only unique aspect of this satellite gateway is that its "outside" address is NAT'd. In every other way it is configured the same as the 20 other satellite gateways, which still have VPN tunnels successfully established. The satellite gateways are running Gaia R77.20.87 (990173083).&lt;/P&gt;&lt;P&gt;I see JHFA take 126 has a few fixes for NAT-T issues, so I am thinking this is the cause. I do have a support case open, but TAC has been...busy? While I am waiting for them to respond, I thought I'd check in with the community to see if anyone else has a similar scenario.&lt;/P&gt;&lt;P&gt;-Dave&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 15:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/134742#M20238</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-11-23T15:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135186#M20353</link>
      <description>&lt;P&gt;What JHF were you running previously?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 20:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135186#M20353</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-29T20:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135191#M20356</link>
      <description>&lt;P&gt;I was previously running on Take 102&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 20:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135191#M20356</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-11-29T20:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135227#M20360</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10229"&gt;@David_C1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please a bit share more info about the topology? is the Cluster with JHF 126 is behind NAT and doing VPN against SMB device?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 07:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135227#M20360</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2021-11-30T07:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135253#M20362</link>
      <description>&lt;P&gt;The cluster with JHF 126 is NOT behind a NAT. The SMB device is behind a NAT. The cluster with JHF 126 is 20 or so other S2S VPNs with other SMB devices that are not behind NATs, it is only this one device that is behind a NAT and which the tunnel is failing to establish.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 13:45:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135253#M20362</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-11-30T13:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135254#M20363</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10229"&gt;@David_C1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see any outputs in dmesg? Any drops under fw ctl zdebug + drop?&lt;/P&gt;
&lt;P&gt;i guess the NAT device that doing NAT for the SMB is not CP device, correct?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135254#M20363</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2021-11-30T14:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135256#M20364</link>
      <description>&lt;P&gt;The device doing NAT for the SMB is a Check Point device, but not managed by me. I've uploaded VPN debugs to my case, but support has yet to respond...&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135256#M20364</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-11-30T14:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135257#M20365</link>
      <description>&lt;P&gt;can you share the case number?&lt;/P&gt;
&lt;P&gt;Do you know if the NAT device was also upgrade to this JHF?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:17:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135257#M20365</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2021-11-30T14:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135275#M20366</link>
      <description>&lt;P&gt;Case number is 6-0003061866.&lt;/P&gt;&lt;P&gt;The NAT device is on R80.20 with JHFA Take 141. It has not been updated recently.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 15:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135275#M20366</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-11-30T15:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135279#M20368</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10229"&gt;@David_C1&lt;/a&gt;&amp;nbsp; - Thank You, i will review it and do my best to push it so you can get answers from support.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 16:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135279#M20368</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2021-11-30T16:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN issue with R80.40 JHFA Take 126</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135665#M20478</link>
      <description>&lt;P&gt;After working a bit with support, I reverted one gateway in the central cluster to JHFA Take 102. When I made that gateway the active, the tunnel came up. Switching the active back to gateway with Take 126, the tunnel failed to come up. I will be sending support more logs soon.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 18:55:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-issue-with-R80-40-JHFA-Take-126/m-p/135665#M20478</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-12-06T18:55:27Z</dc:date>
    </item>
  </channel>
</rss>

