<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP SEC VPN - Problem with tunnel IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154065#M26029</link>
    <description>&lt;P&gt;Looks similar to&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165003&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk165003: When Security Gateway initiates &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnel with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;Party&lt;/STRONG&gt; peer using IKEv2, &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnel is forced to NAT-T and traffic fails&lt;/A&gt;&amp;nbsp;But this has been fixed in R81. So i would suggest to look at Scenario 3 in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;party&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jul 2022 10:52:01 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2022-07-28T10:52:01Z</dc:date>
    <item>
      <title>IP SEC VPN - Problem with tunnel IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154064#M26028</link>
      <description>&lt;P&gt;I have an ipsec vpn between a Fortinet firewall (Fortigate 100D version 6.2.10) and a Check Point firewall (version R81.10)&lt;BR /&gt;The problem I am having is the following:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In phase 2 the firewalls negotiate subnets 172.17.1.0/24 (Check Point side) and 172.17.2.0/24 (Fortigate side). Phase 2 goes up correctly and when calls are made from the Fortigate the connection is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, when the connection is initialized by Check Point even though tunnel 172.17.1.0/24 172.17.2.0/24 has been negotiated, Check Point tries to negotiate a new tunnel with the specific IP of the client that is trying the connection. The tunnel is rejected by Fortigate as it is not the one agreed upon and from the logs I receive the no response from peer error.&lt;/P&gt;&lt;P&gt;Is there a setting on the Check Point to eliminate this problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 10:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154064#M26028</guid>
      <dc:creator>Mando_92</dc:creator>
      <dc:date>2022-07-28T10:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: IP SEC VPN - Problem with tunnel IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154065#M26029</link>
      <description>&lt;P&gt;Looks similar to&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165003&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk165003: When Security Gateway initiates &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnel with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;Party&lt;/STRONG&gt; peer using IKEv2, &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnel is forced to NAT-T and traffic fails&lt;/A&gt;&amp;nbsp;But this has been fixed in R81. So i would suggest to look at Scenario 3 in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;party&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 10:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154065#M26029</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-28T10:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: IP SEC VPN - Problem with tunnel IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154110#M26046</link>
      <description>&lt;P&gt;Thanks for response!&lt;BR /&gt;&lt;BR /&gt;But the sk165003 and sk108600&amp;nbsp;indicate by you is NOT the problem encountered (NAT traversal) or Scenario 3 of second sk.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Although a tunnel for the entire subnet has been negotiated /24 Check Point tries to set up a new tunnel for specific ip belonging to that subnet.&lt;/P&gt;&lt;P&gt;What configuration parameters can I affect this thing ?&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;*****************************************************&lt;BR /&gt;*****************************************************&lt;BR /&gt;&lt;BR /&gt;I solved the problem by adding on the Fortigate (encryption domain) side the specific ip of the Check Point subnet that establish the connections&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 14:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-SEC-VPN-Problem-with-tunnel-IP/m-p/154110#M26046</guid>
      <dc:creator>Mando_92</dc:creator>
      <dc:date>2022-07-28T14:30:24Z</dc:date>
    </item>
  </channel>
</rss>

