<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167357#M30262</link>
    <description>&lt;P&gt;That worked. Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2023 22:25:32 GMT</pubDate>
    <dc:creator>dphonovation</dc:creator>
    <dc:date>2023-01-10T22:25:32Z</dc:date>
    <item>
      <title>Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167291#M30251</link>
      <description>&lt;P&gt;I have a weird outtage today where somehow the licensing on my cluster got all out of whack. I've fixed it and cluster is now all green.&lt;/P&gt;&lt;P&gt;However what I now notice is that ICMP to a Remote Office is broken as soon as I have a community setup on the CP side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint Public IP: x.x.x.x&lt;/P&gt;&lt;P&gt;Checkpoint VPN Encryption Domain: 10.10.171.0/24&lt;/P&gt;&lt;P&gt;Remote peer Public IP: z.z.z.z&lt;/P&gt;&lt;P&gt;Remote Peer Encryption Domain: 192.168.1.0/24 and 192.168.11.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as I configure this community (star or mesh), z.z.z.z can no longer ping x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint logs report "Clear text packet should be encrypted".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went as far as blowing out all the VPN communities, disabling IPSEC VPN. Pushing policy. Then reenabling and readding the community. I'm rather confused, as I know for a fact before this used to be fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On top of this, Checkpoint Mobile stopped working entirely.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 14:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167291#M30251</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2023-01-10T14:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167309#M30254</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk108600 - scenario 3?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Did this work on a previous version or the same?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 15:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167309#M30254</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-10T15:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167310#M30255</link>
      <description>&lt;P&gt;The same gateways and versions didn't change and that is whats confusing.&lt;/P&gt;&lt;P&gt;I've certainly never modified the file in that sk for scenario 3 before.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 15:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167310#M30255</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2023-01-10T15:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167336#M30259</link>
      <description>&lt;P&gt;"Clear text packet should be encrypted" means a packet was received that was not encrypted that, by policy, should be.&lt;BR /&gt;That points to a configuration error.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600" target="_self"&gt;sk108600&lt;/A&gt; Scenario 3 is the main issue here (the fact the gateway IPs are always included in the encryption domain).&lt;BR /&gt;The fact you're getting this error in the remote to local direction implies the remote VPN peer is managed by a third party and is most likely a third party device.&lt;BR /&gt;To resolve this, you will need to have the remote end change the configuration to include their peer IP as part of their encryption domain OR apply the fix described in sk108600.&lt;BR /&gt;If both ends of the VPN are gateways managed by the same management and you're experiencing this, it might be worth a TAC case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Check Point Mobile issue is something completely different, most likely.&lt;BR /&gt;Please start a new thread related to this issue with appropriate details about this issue (error messages, exact version/JHF used, etc).&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:06:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167336#M30259</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-10T19:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167337#M30260</link>
      <description>&lt;P&gt;Thanks. I will try adding the peer IP.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167337#M30260</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2023-01-10T19:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Creating VPN community w/ private IPs in Enc Domain breaks ICMP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167357#M30262</link>
      <description>&lt;P&gt;That worked. Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 22:25:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Creating-VPN-community-w-private-IPs-in-Enc-Domain-breaks-ICMP/m-p/167357#M30262</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2023-01-10T22:25:32Z</dc:date>
    </item>
  </channel>
</rss>

