<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPsec VPN Initiator in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173194#M31479</link>
    <description>&lt;P&gt;I have Hub and Spoke Site to Site topology (both managed by same central management).&lt;/P&gt;&lt;P&gt;I am trying to understand, why always only the spoke initiated of tunnel creation?&lt;/P&gt;&lt;P&gt;I never saw that Hub was the initiator.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 13:46:52 GMT</pubDate>
    <dc:creator>leonid1890</dc:creator>
    <dc:date>2023-03-01T13:46:52Z</dc:date>
    <item>
      <title>IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173194#M31479</link>
      <description>&lt;P&gt;I have Hub and Spoke Site to Site topology (both managed by same central management).&lt;/P&gt;&lt;P&gt;I am trying to understand, why always only the spoke initiated of tunnel creation?&lt;/P&gt;&lt;P&gt;I never saw that Hub was the initiator.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 13:46:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173194#M31479</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-03-01T13:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173210#M31481</link>
      <description>&lt;P&gt;VPN tunnels are usually open when one of the parties starts sending traffic to the other VPN domain. If you want them to be always up, set up permanent tunnels in the community properties.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I can only assume, in your case, it is only satellite sites initiate connections to the main site and not the other way around.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:31:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173210#M31481</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-01T14:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173211#M31482</link>
      <description>&lt;P&gt;A VPN tunnel is only initiated when traffic needs to be sent down the tunnel.&lt;BR /&gt;A hub site would only initiate a connection to a spoke when it or a different spoke site have traffic for that particular site.&lt;BR /&gt;If a spoke site has a dynamic IP, the spoke must initiate the tunnel to ensure the hub knows what IP to send traffic to.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173211#M31482</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-01T14:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173214#M31485</link>
      <description>&lt;P&gt;As the guys said, make sure permanent tunnel option inside vpn community is enabled. Now, here is something to keep in mind. Enabling that is NOT enough on its own. You have to do below changes in guidbedit as well per below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Tunnel-Management.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Tunnel-Management.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this section (you need DPD value specially if its 3rd party device on the other side)&lt;/P&gt;
&lt;H4&gt;Permanent Tunnel Mode Based on Dead Peer Detection&lt;/H4&gt;
&lt;P&gt;DPD can monitor remote peers with the permanent tunnel feature. All related behavior and configurations of permanent tunnels are supported.&lt;/P&gt;
&lt;P&gt;To configure DPD for a permanent tunnel, the permanent tunnel must be in the VPN community. After you configure the permanent tunnel, configure Permanent Tunnel mode Based on DPD. There are different possibilities for permanent tunnel mode:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;tunnel_test&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(default) - The permanent tunnel is monitored by a tunnel test (as in earlier versions). It works only between&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_cp variable"&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;. Keepalive packets are always sent.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;dpd&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The active DPD mode. A peer receives DPD requests at regular intervals (10 seconds). DPD requests are only sent when there is no traffic from the peer.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;passive&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The passive DPD mode. Peers do not send DPD requests to this peer. Tunnels with passive peers are monitored only if there is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_ipsec variable"&gt;IPsec&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;traffic and incoming DPD requests.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Note&lt;/SPAN&gt;: To use this mode for only some&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;, enable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;forceSendDPDPayload&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;registry key on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_cp variable"&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;remote peers.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="Procedure_Heading"&gt;To enable DPD monitoring:&lt;/P&gt;
&lt;P&gt;On each VPN&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the VPN community, configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;tunnel_keepalive_method&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;property, in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_guidbedit variable"&gt;Database Tool (GuiDBEdit Tool)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk13009" target="_blank" rel="noopener"&gt;sk13009&lt;/A&gt;) or dbedit (see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI3301" target="_blank" rel="noopener"&gt;skI3301&lt;/A&gt;). This includes 3rd Party&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;. (You cannot configure different monitor mechanisms for the same&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;).&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_guidbedit variable"&gt;Database Tool (GuiDBEdit Tool)&lt;/SPAN&gt;, go to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Objects&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;network_objects&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&amp;lt;&lt;EM&gt;Name of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;object&lt;/EM&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;VPN&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;For the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Value&lt;/SPAN&gt;, select a permanent tunnel mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Save all the changes.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Install the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_access variable"&gt;Access Control&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="Procedure_Heading"&gt;Optional Configuration:&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:52:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173214#M31485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T14:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173299#M31500</link>
      <description>&lt;P&gt;You right, only satellite sites initiate connections to the main site and not the other way around.&lt;BR /&gt;And that what I am trying to understand, why it is not in the opposite?&lt;/P&gt;&lt;P&gt;For example: if I reboot one of satellites, after it came up it will try to initiate the tunnel (and not the HUB).&lt;BR /&gt;After the reboot there is no traffic that need to go throug the tunnel.&lt;/P&gt;&lt;P&gt;So on which decision they determine who will start the tunnel initiation?&lt;/P&gt;&lt;P&gt;Note: I don't want the tunnel to be always up,&lt;BR /&gt;I am asking this question in order to understand how it is working.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 06:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173299#M31500</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-03-02T06:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173300#M31501</link>
      <description>&lt;P&gt;Let's assume I added new settlite to my current topology,&lt;BR /&gt;and there is no traffic which need to be sent down the tunnel&lt;BR /&gt;but there is still tunnel created and initiated by settlite.&lt;/P&gt;&lt;P&gt;Maybe there is something is missing from my understanding.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 06:55:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173300#M31501</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-03-02T06:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173344#M31503</link>
      <description>&lt;P&gt;So without permanent tunnel enabled, the way it works really depends which side initiates the traffic, so regardless where traffic comes from, it would "kick start" the tunnel. I dont believe there is specific mechanism to force hub over spoke to be preferred, as far as I know.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 11:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173344#M31503</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T11:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173375#M31513</link>
      <description>&lt;P&gt;Starting in R81 if an interoperable device type is part of a VPN Community and Permanent Tunnels is set, the&amp;nbsp;tunnel_keep_alive_method variable will be automatically set to "DPD" instead of "TUNNEL_TEST".&amp;nbsp; This applies after upgrades as well.&amp;nbsp; This is mentioned in scenario 5 of&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173375#M31513</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-02T14:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173376#M31514</link>
      <description>&lt;P&gt;Thanks for pointing that out, never really paid attention to it, good to know!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:30:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173376#M31514</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN Initiator</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173419#M31531</link>
      <description>&lt;P&gt;As we stated previously, the tunnel only comes up when one end needs to send traffic to the other.&lt;BR /&gt;If the traffic largely comes from the satellite, it is normal for the satellite to initiate the VPN tunnel.&lt;BR /&gt;The hub will only do if it has traffic for the satellite and the tunnel isn't already up.&lt;BR /&gt;This is all expected behavior.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-Initiator/m-p/173419#M31531</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-02T20:27:23Z</dc:date>
    </item>
  </channel>
</rss>

