<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route-based VPN with Azure - BGP problem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158466#M27623</link>
    <description>&lt;P&gt;As a side note,&amp;nbsp;in my opinion Checkmates is in some sense an alternative to TAC. It is I believe funded by Checkpoint, there are representatives from the company too, and it is just another channel for Checkpoint to help out customers. If you think I am non-paying customer you are very wrong. If I can resolve a problem with the help of community this is saved money/time for TAC so everyone is happy.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 15:07:38 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2022-09-29T15:07:38Z</dc:date>
    <item>
      <title>Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158398#M27608</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Gateway R80.40&lt;/P&gt;
&lt;P&gt;I am setting up route based (VTI) site to site VPN tunnel between on-premise and Azure. VPN tunnel is up, however bgp traffic from Azure does not seem to pass VPN blade correctly. The opposite direction works fine&lt;/P&gt;
&lt;DIV id="tinyMceEditorabihsot___0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 975px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17964iEB4739901C82B594/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VPN tunnel as per instructions, empty group in topology.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I am not too sure about VPN column in the policy. I might "borrowed" directional match configuration from aws, but I can't find any document to confirm what should I put in VPN column for Azure.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;Internal_clear &amp;gt; AWS VPN community&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;AWS VPN community &amp;gt; AWS VPN community&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;AWS VPN community &amp;gt; Internal_clear&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 29 Sep 2022 07:13:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158398#M27608</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-09-29T07:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158429#M27615</link>
      <description>&lt;P&gt;Ask CP TAC how to resolve that !&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 10:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158429#M27615</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-29T10:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158434#M27618</link>
      <description>&lt;P&gt;Thanks for your time!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the purpose of this forum then if all questions should be directed to TAC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 11:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158434#M27618</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-09-29T11:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158445#M27620</link>
      <description>&lt;P&gt;To discuss issues and versions as well as answering questions is the purpose of this forum - but you seem not to have an academical question but a big issue in production that should be resolved quickly, therefore i have suggested &amp;nbsp;to contact TAC instead of waiting for a miracle from CheckMates (as you give no details of the VTI config that would be important here...)...&lt;/P&gt;
&lt;P&gt;CheckMates is not an alternative for TAC but a low-level discussion group also containing technical suggestions.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 13:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158445#M27620</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-29T13:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158461#M27622</link>
      <description>&lt;P&gt;Not sure where you get the idea of "big issue in production"?&lt;/P&gt;
&lt;P&gt;I started my post with "I am setting up ...", which would indicate a completely new configuration. I was not able to find complete instruction in Checkpoint documentation which led to interpretation of some settings and I ran out of options to test, hence this post. I could also go to TAC, but I thought this is also the right place to discuss.&lt;/P&gt;
&lt;P&gt;What exactly you would like to know about VTI config? My understanding is that VPN tunnel is up, VTI config is fine too, because I can receive and send traffic based on the log, however one direction is not processed by correct firewall rule and therefore dropped.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:57:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158461#M27622</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-09-29T14:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158466#M27623</link>
      <description>&lt;P&gt;As a side note,&amp;nbsp;in my opinion Checkmates is in some sense an alternative to TAC. It is I believe funded by Checkpoint, there are representatives from the company too, and it is just another channel for Checkpoint to help out customers. If you think I am non-paying customer you are very wrong. If I can resolve a problem with the help of community this is saved money/time for TAC so everyone is happy.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:07:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158466#M27623</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-09-29T15:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158469#M27626</link>
      <description>&lt;P&gt;Just to clarify, CheckMates is owned and run by Check Point. We are quite happy to hear you want to ask the community before going to the official support channels. I agree it helps everyone if we all share the issue resolution here.&lt;BR /&gt;&lt;BR /&gt;That said, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23615"&gt;@abihsot__&lt;/a&gt;&amp;nbsp; If you have to open a ticket with TAC for this, do not forget to share the actual resolution with us.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;both academic questions and huge production issue questions are welcome in the community. We are all friends and colleagues here, please do not forget that.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:44:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158469#M27626</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-29T15:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158526#M27637</link>
      <description>&lt;P&gt;I had this issue in AWS exactly the same.&lt;/P&gt;&lt;P&gt;In AWS the "encryption domain" was setup with a specific subnet ( lets say: 10.10.10.0/24 ) instead of 0.0.0.0/0 , so the BGP peers (169.254.1.1) traffic is not correctly encrypted from the AWS site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This looks like the same issue on your config , because traffic to azure gets encrypted correctly&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 11:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158526#M27637</guid>
      <dc:creator>nickdegroot</dc:creator>
      <dc:date>2022-09-30T11:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158529#M27638</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23615"&gt;@abihsot__&lt;/a&gt;&amp;nbsp;...do you see any drops on the CP firewall if filtering for BGP? For example -&amp;gt; fw ctl zdebug + drop | grep ":179"...if you run that command, it should give you something if its dropped.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:46:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158529#M27638</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-30T12:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN with Azure - BGP problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158554#M27642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The Gaia Admin Guide contains a section on setting up VTIs for route based VPNs and states (paraphrased):&lt;/P&gt;&lt;P&gt;Directional&amp;nbsp;matching is necessary for Route Based VPN when a VPN community is included in the VPN&lt;BR /&gt;column in the rule. This is because without bi-directional matching, the rule only applies to&lt;BR /&gt;connections between a community and an encryption domain (Domain Based Routing).&lt;/P&gt;&lt;P&gt;The directional rule must contain these directional matching conditions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Community &amp;gt; Community&lt;/LI&gt;&lt;LI&gt;Community &amp;gt; &lt;STRONG&gt;Internal_Clear&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Internal_Clear&lt;/STRONG&gt; &amp;gt; Community&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Internal_Clear &lt;/STRONG&gt;refers to all traffic from IP addresses to and from the&amp;nbsp;specified VPN community.&lt;/LI&gt;&lt;LI&gt;It is not necessary to define bidirectional matching rules if the VPN&amp;nbsp;column contains the value Any.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, to answer your question, the VPN column needs to have the three matching conditions specified above replacing "Community" with the name of your community.&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 00:47:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-with-Azure-BGP-problem/m-p/158554#M27642</guid>
      <dc:creator>Colin_Campbell1</dc:creator>
      <dc:date>2022-10-01T00:47:54Z</dc:date>
    </item>
  </channel>
</rss>

