<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Established but incoming traffic is rejected in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144038#M22393</link>
    <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;That cannot be the case since I see that the ASA is encrypting traffic but I can't see encrypted replies from the checkpoint.&lt;/P&gt;&lt;DIV class=""&gt;Please check the attached image which is a print screen on the ASA.&lt;BR /&gt;I'm have access to both devices by the way.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2022 12:32:34 GMT</pubDate>
    <dc:creator>Carlos</dc:creator>
    <dc:date>2022-03-17T12:32:34Z</dc:date>
    <item>
      <title>VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/143810#M22369</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I have a VPN set up between a CHECKPOINT R80.40 and a CISCO ASA&amp;nbsp;Version 9.16(1)&lt;/P&gt;&lt;P&gt;and I can't have traffic to go from one side to the other successfully as I see traffic being blocked at checkpoints side.&lt;/P&gt;&lt;P&gt;The tunnel is up...&lt;BR /&gt;This is what I get on the logs&lt;/P&gt;&lt;P&gt;This is from checkpoint to ASA&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkpoint to ASA.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15709iC3B4149B3A3977CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Checkpoint to ASA.png" alt="Checkpoint to ASA.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is from the ASA to the checkpoint&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ASA to CheckPoint.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15710iF2F496775EDBFE2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ASA to CheckPoint.png" alt="ASA to CheckPoint.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 23:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/143810#M22369</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-15T23:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/143836#M22373</link>
      <description>&lt;P&gt;Looks like the remote end isn't encrypting traffic to us.&lt;BR /&gt;I'd check the configuration on the ASA side.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 04:13:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/143836#M22373</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-16T04:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144038#M22393</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;That cannot be the case since I see that the ASA is encrypting traffic but I can't see encrypted replies from the checkpoint.&lt;/P&gt;&lt;DIV class=""&gt;Please check the attached image which is a print screen on the ASA.&lt;BR /&gt;I'm have access to both devices by the way.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 12:32:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144038#M22393</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-17T12:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144039#M22394</link>
      <description>&lt;P&gt;There’s not enough information being shown in the log screenshots you’ve provided.&lt;BR /&gt;Please show a full log card for one of the drops.&lt;BR /&gt;Also, we’ll need to see what the precise rulebase in question is.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 13:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144039#M22394</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-17T13:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144071#M22399</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;As you can see on the images the first one is the rule allowing bidirectioanl traffic.&amp;nbsp; The second one is traffic from checkpoint side to ASA. And the third one traffic from ASA to CheckPoint.&lt;BR /&gt;I don't know what you mean by: precise rulebase in question is.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Regras.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15758i8D941D8F5B6CEEB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Regras.PNG" alt="Regras.PNG" /&gt;&lt;/span&gt;As you can &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FROM checkpoint to ASA.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15759i63C39F1992A1DE13/image-size/large?v=v2&amp;amp;px=999" role="button" title="FROM checkpoint to ASA.PNG" alt="FROM checkpoint to ASA.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ASA TO CHECKPOINT.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15760i2B482AA3278ECBE8/image-size/large?v=v2&amp;amp;px=999" role="button" title="ASA TO CHECKPOINT.PNG" alt="ASA TO CHECKPOINT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 14:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144071#M22399</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-17T14:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144091#M22405</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Double click on one of the drop logs (ASA to CheckPoint), go to matching rules tab and check which rule is being applied. According to the screenshots i only can imagine network 192.168.52.0/X is not properly configured on your AUPEC_NET_52 or MINFIN_AUPEC_NET object, the one that is supposed to be the remote encryption domain. Also check drop reason on the log card.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 17:45:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144091#M22405</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-03-17T17:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144105#M22407</link>
      <description>&lt;P&gt;Hi RS_Daniel,&lt;/P&gt;&lt;P&gt;Please see the image below.&lt;/P&gt;&lt;P&gt;It does not say which rule dropped it.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DROP.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15767i900D54308D56E145/image-size/large?v=v2&amp;amp;px=999" role="button" title="DROP.PNG" alt="DROP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 19:14:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144105#M22407</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-17T19:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144110#M22408</link>
      <description>&lt;P&gt;Spoofing drop, probably caused by defining the entire 192.168.0.0/12 supernet on the topology of your internal interface which is a common mistake.&amp;nbsp; Exclude 192.168.52.0/24 from the topology of your external interface (bond0.10) on the firewall/cluster object and it should start working.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 19:33:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144110#M22408</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-03-17T19:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144122#M22409</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Is the exclusion done as in the image below? If so, I have done it and it still not working. Sorry for my ignorance as I'm new to checkpoint and this is my first time setting up a VPN tunnel on checkpoint gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.png" style="width: 967px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15769iE21EF89585183B2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Topology.png" alt="Topology.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 22:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144122#M22409</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-17T22:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144175#M22421</link>
      <description>&lt;P&gt;Appears to be a routing problem as you have "Calculate topology automatically based on routing" set.&amp;nbsp; Uncheck that and properly define External/Internal &amp;amp; the correct topology manually on all your interfaces.&amp;nbsp; This is probably your issue.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 15:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144175#M22421</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-03-18T15:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144177#M22422</link>
      <description>&lt;P&gt;Yes, thats where you would do it. So, just to be sure, what I would do is this...set spoofing to detect on internal interface and also add external IP of the Cisco into option on external interface "dont check packets from", push policy and test.&lt;/P&gt;
&lt;P&gt;You can also refer to below links for the reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/Local-interface-address-spoofing/td-p/15099" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/Local-interface-address-spoofing/td-p/15099&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 15:51:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144177#M22422</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-18T15:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144204#M22431</link>
      <description>&lt;P&gt;Thanks every one it's working now. The issue was the anti-spoofing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Mar 2022 18:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144204#M22431</guid>
      <dc:creator>Carlos</dc:creator>
      <dc:date>2022-03-19T18:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Established but incoming traffic is rejected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144217#M22433</link>
      <description>&lt;P&gt;Glad we could help!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2022 12:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Established-but-incoming-traffic-is-rejected/m-p/144217#M22433</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-20T12:54:53Z</dc:date>
    </item>
  </channel>
</rss>

