<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN issue between Cisco ASA and Checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159441#M27908</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When you say "&lt;SPAN&gt;Each time we create a supernet as the domain&lt;/SPAN&gt;" do you mean adding that supernet to your local encryption domain (checkpoint)? or in the remote encryption domain (ASA)?&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;and the user tries to connect to 172.30.1.1&lt;/SPAN&gt;" where is the user? behind checkpoint or behind ASA?&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;on the ASA we see a tunnel for 172.16.0.0 and 172.30.0.0&lt;/SPAN&gt;" does ASA receive these ID's from checkpoint? or ASA send those ID's to checkpoint?&lt;/P&gt;
&lt;P&gt;Easy answer would be&amp;nbsp;&lt;SPAN&gt;sk108600 scenario 1, edit the user.def file to send your local encryption domain to the ASA peer as you need. If that is not the case more details are needed to understand your enviroment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2022 12:27:05 GMT</pubDate>
    <dc:creator>RS_Daniel</dc:creator>
    <dc:date>2022-10-13T12:27:05Z</dc:date>
    <item>
      <title>VPN issue between Cisco ASA and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159423#M27902</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;We have an issue creating a vpn between Checkpoint&amp;nbsp; and Cisco ASA.&lt;/P&gt;&lt;P&gt;Each time we create a supernet as the domain, 172.16.0.0/12, and the user tries to connect to 172.30.1.1 for example, on the ASA we see a tunnel for 172.16.0.0 and 172.30.0.0 and the traffic never makes it.&lt;/P&gt;&lt;P&gt;The setting on Checkpoint vpn community is set to vpn per subnet pair.&lt;/P&gt;&lt;P&gt;I have checked gui dbedit and the setting ike_enable_supernet is enabled under global properties and also ike_use_largest possible subnets is also set to true.&lt;/P&gt;&lt;P&gt;What do we need to do to get the gateway to use the supernet? how do I check the setting is true on the gateway?&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 08:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159423#M27902</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-13T08:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco ASA and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159441#M27908</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When you say "&lt;SPAN&gt;Each time we create a supernet as the domain&lt;/SPAN&gt;" do you mean adding that supernet to your local encryption domain (checkpoint)? or in the remote encryption domain (ASA)?&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;and the user tries to connect to 172.30.1.1&lt;/SPAN&gt;" where is the user? behind checkpoint or behind ASA?&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;on the ASA we see a tunnel for 172.16.0.0 and 172.30.0.0&lt;/SPAN&gt;" does ASA receive these ID's from checkpoint? or ASA send those ID's to checkpoint?&lt;/P&gt;
&lt;P&gt;Easy answer would be&amp;nbsp;&lt;SPAN&gt;sk108600 scenario 1, edit the user.def file to send your local encryption domain to the ASA peer as you need. If that is not the case more details are needed to understand your enviroment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 12:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159441#M27908</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-10-13T12:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco ASA and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159448#M27910</link>
      <description>&lt;P&gt;Which the version do you have on your Gateway ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 14:15:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159448#M27910</guid>
      <dc:creator>Abi</dc:creator>
      <dc:date>2022-10-13T14:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco ASA and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159529#M27942</link>
      <description>&lt;P&gt;Better open a SR# with CP TAC !&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 10:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159529#M27942</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-14T10:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco ASA and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159534#M27945</link>
      <description>&lt;P&gt;R81.10&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 11:52:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-issue-between-Cisco-ASA-and-Checkpoint/m-p/159534#M27945</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T11:52:42Z</dc:date>
    </item>
  </channel>
</rss>

