<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN behavior question: Break-before-make / Make-before-break in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178770#M32740</link>
    <description>&lt;P&gt;This SK suggests we are using Break Before Make:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171756" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171756&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2023 20:07:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-21T20:07:31Z</dc:date>
    <item>
      <title>VPN behavior question: Break-before-make / Make-before-break</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178592#M32709</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;a customer asks how check point handles this behavior that you can configure with cisco or strongwan:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Break-before-make&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This is the &lt;STRONG&gt;default&lt;/STRONG&gt; behavior of the IKE daemon when reauthenticating an IKEv2 SA. It means that all IKE_SAs and CHILD SAs are torn down before recreating them. This will cause some interruptions during which no IPsec SAs are installed. If trap policies are used it could also trigger unnecessary acquires and hence duplicate IPsec SAs during that downtime. To prevent plaintext traffic from leaving the host appropriate firewall rules or drop policies may be used.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Make-before-break&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This method first creates duplicates of the IKE SAs and all CHILD SAs overlapping with the existing ones and then deletes the old ones. This avoids interruptions but requires that both peers can handle overlapping SAs (e.g. in regards to virtual IPs, duplicate policies or updown scripts). It is supported for IKEv2 since version 5.3.0 but is disabled by default and may be enabled by explicitly setting&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any information available on that?&lt;BR /&gt;&lt;BR /&gt;thanks&lt;/P&gt;&lt;P&gt;reinhard&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178592#M32709</guid>
      <dc:creator>ReinhardS</dc:creator>
      <dc:date>2023-04-20T08:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN behavior question: Break-before-make / Make-before-break</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178770#M32740</link>
      <description>&lt;P&gt;This SK suggests we are using Break Before Make:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171756" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171756&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178770#M32740</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T20:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN behavior question: Break-before-make / Make-before-break</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178780#M32744</link>
      <description>&lt;P&gt;Thats superb question...I had guy dealing with Cisco ask that once when we were with escalation guy from CP trying to fix CP-Cisco VPN and what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said was indeed the right assesment. Esc. guy gave that exact same sk.&lt;/P&gt;
&lt;P&gt;Have an awesome weekend!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SkodagramKaroqGIF.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20592iE5D485A62107EB91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SkodagramKaroqGIF.gif" alt="SkodagramKaroqGIF.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-behavior-question-Break-before-make-Make-before-break/m-p/178780#M32744</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-21T20:28:00Z</dc:date>
    </item>
  </channel>
</rss>

