<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn tu tlist in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146245#M23175</link>
    <description>&lt;P&gt;Thanks ALbrecht,&lt;/P&gt;&lt;P&gt;in the process renegotiation IPsec SA status connection is always establish right? not interrupt the traffic?&lt;/P&gt;&lt;P&gt;can you share the document about renegotiation IPsec SA on CheckPoint.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2022 03:19:35 GMT</pubDate>
    <dc:creator>Ricki_Juntak</dc:creator>
    <dc:date>2022-04-14T03:19:35Z</dc:date>
    <item>
      <title>vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145927#M23096</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me how to configure the tunnel expiration on the capture have 1 hour and what the purpose off the tunnel created and tunnel expiration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@Internal-GW:0]# vpn tu tlist&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;BR /&gt;| Peer: 172.16.10.1 (cd6b8f0973d32146) | MSA: ffffc9001f624410 | i: 0 ref: -- 45/60 |&lt;BR /&gt;| Client public IP: 203.0.113.200 | | i: 1 ref: 4 |&lt;BR /&gt;| Authenticated at: Apr 11 01:36:22 | | i: 2 ref: -- 46/60 |&lt;BR /&gt;| Methods: ESP Tunnel 3DES SHA1 | | |&lt;BR /&gt;| My TS: 0.0.0.0/0 | | |&lt;BR /&gt;| Peer TS: 172.16.10.1 | | |&lt;BR /&gt;| User: test | | |&lt;BR /&gt;| MSPI: 800005 (i: 1, p: 0) | Out SPI: 6980210e | |&lt;BR /&gt;&lt;STRONG&gt;| Tunnel created: Apr 11 01:36:22 | NAT-T | |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;| Tunnel expiration: Apr 11 02:36:22 | | |&lt;/STRONG&gt;&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;/P&gt;&lt;P&gt;(0) Site-to-Site tunnels are up:&lt;BR /&gt;IPSEC 0&lt;BR /&gt;NAT-T 0&lt;/P&gt;&lt;P&gt;(1) Number of Active Clients:&lt;BR /&gt;NAT-T 1&lt;BR /&gt;Visitor Mode 0&lt;BR /&gt;SSL 0&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 05:41:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145927#M23096</guid>
      <dc:creator>Ricki_Juntak</dc:creator>
      <dc:date>2022-04-11T05:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145943#M23100</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104760&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk104760: &lt;STRONG&gt;ATRG&lt;/STRONG&gt;: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Core&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 08:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145943#M23100</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-11T08:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145949#M23103</link>
      <description>&lt;P&gt;Thanks Albrecht,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read the SK and confused to read the SK because I cant find mention about tunnel_expiration and tunnel created&lt;/P&gt;&lt;P&gt;I have try on the lab-&amp;gt; using checkmate lab,&lt;/P&gt;&lt;P&gt;I try to find the configuration for tunnel created and tunnel expiration and I try to change the vpn_table.def on SMS(r81.10)&lt;/P&gt;&lt;P&gt;#define ISAKMP_TABLE_TIMEOUT 3600 --&amp;gt; change to 300&lt;BR /&gt;#define SPI_TABLE_TIMEOUT 3600 --&amp;gt; change to 300&lt;BR /&gt;#define IKE_SA_TABLE_TIMEOUT 3600 -&amp;gt; cahnge to 300&lt;/P&gt;&lt;P&gt;after change, push policy.&lt;/P&gt;&lt;P&gt;but the result is same duration for tunnel still 1 hour.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 10:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/145949#M23103</guid>
      <dc:creator>Ricki_Juntak</dc:creator>
      <dc:date>2022-04-11T10:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146037#M23127</link>
      <description>&lt;TABLE border="1" cellpadding="5"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;IKE_SA_table&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;UL type="circle"&gt;
&lt;LI&gt;Contains information about all ISAKMP SAs.&lt;/LI&gt;
&lt;LI&gt;Entries from this table are used to conduct IKE Quick Mode negotiation of IPsec SA.&lt;/LI&gt;
&lt;LI&gt;Entries are extracted from this table when the vpnd daemon is trapped for IPsec SA renewal.&lt;/LI&gt;
&lt;LI&gt;Default expiration time is&amp;nbsp;&lt;SPAN&gt;3600 seconds&lt;/SPAN&gt;&lt;SPAN&gt;.= 1 hour !&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Synchronized in cluster.&lt;/LI&gt;
&lt;LI&gt;Table entry is:&lt;BR /&gt;either&lt;BR /&gt;&amp;lt;&lt;EM&gt;Peer_IP ,0 , CookieI, CookieR; IKE_SA, IKE_SA_flag, RenegotiationTime; Timeout&lt;/EM&gt;&amp;gt;&lt;BR /&gt;or&lt;BR /&gt;&amp;lt;&lt;EM&gt;Peer_IP, 0; IKE_SA, CookieI, CookieR, IKE_SA_flag, RenegotiationTime; Timeout&lt;/EM&gt;&amp;gt;&lt;BR /&gt;where:&lt;BR /&gt;
&lt;UL type="square"&gt;
&lt;LI&gt;Peer_IP - IP address of IKE peer&lt;/LI&gt;
&lt;LI&gt;CookieI - initiator cookie (8 bytes in host byte order)&lt;/LI&gt;
&lt;LI&gt;CookieR - responder cookie (8 bytes in host byte order)&lt;/LI&gt;
&lt;LI&gt;IKE_SA - ISAKMP SA data in Check Point code&lt;/LI&gt;
&lt;LI&gt;IKE_SA_flag - one of these values: 0x01=mobile, 0x02=initiator, 0x03=DAIP&lt;/LI&gt;
&lt;LI&gt;RenegotiationTime - The renegotiation time of the SA&lt;/LI&gt;
&lt;LI&gt;Timeout - How much time remained to expiration time&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 12 Apr 2022 06:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146037#M23127</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-12T06:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146043#M23131</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks Albrecht,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm using remote access community, its possible to set the duration tunnel created and tunnel created?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if renegotiation expired what happen with the connection is re-establish?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 07:01:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146043#M23131</guid>
      <dc:creator>Ricki_Juntak</dc:creator>
      <dc:date>2022-04-12T07:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146058#M23134</link>
      <description>&lt;P&gt;Every hour, re&lt;SPAN&gt;negotiation of IPsec SA happens.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 08:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146058#M23134</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-12T08:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146245#M23175</link>
      <description>&lt;P&gt;Thanks ALbrecht,&lt;/P&gt;&lt;P&gt;in the process renegotiation IPsec SA status connection is always establish right? not interrupt the traffic?&lt;/P&gt;&lt;P&gt;can you share the document about renegotiation IPsec SA on CheckPoint.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 03:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146245#M23175</guid>
      <dc:creator>Ricki_Juntak</dc:creator>
      <dc:date>2022-04-14T03:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146261#M23178</link>
      <description>&lt;P&gt;As this is standard, it is the same for all vendors:&amp;nbsp;&lt;A href="https://en.wikipedia.org/wiki/Internet_Key_Exchange" target="_blank"&gt;https://en.wikipedia.org/wiki/Internet_Key_Exchange&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 08:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146261#M23178</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-14T08:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: vpn tu tlist</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146978#M23410</link>
      <description>&lt;P&gt;Thanks Albrecht&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 13:04:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-tu-tlist/m-p/146978#M23410</guid>
      <dc:creator>Ricki_Juntak</dc:creator>
      <dc:date>2022-04-25T13:04:11Z</dc:date>
    </item>
  </channel>
</rss>

