<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX and routebased VPN (Azure) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/181902#M33292</link>
    <description>&lt;P&gt;The first problem was solved by changing the alias of the vpnt interfaces. The alias of the interface needs to be exactly the same as the name of the interopable device object where this interface will be used for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second problem is solved by using NAT with the correct vpnt interfaces.&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 12:04:04 GMT</pubDate>
    <dc:creator>Wesley_van_der_</dc:creator>
    <dc:date>2023-05-24T12:04:04Z</dc:date>
    <item>
      <title>VSX and routebased VPN (Azure)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180636#M33017</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A nice new feature in VSX R81 is that we can create vpnt interfaces on a virtual firewall, using vsx_provisioning_tool on the SMS/MDS. We have a VSX setup with SMS, running both on R81.10 with JHF take 87.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to setup a new S2S VPN (routebased) with Azure. I managed to do that using&amp;nbsp;sk176249.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the tunnel is up (phase 1 and 2) and BGP traffic from azure arives at our firewall. We will use BGP over the tunnel and now I am facing 2 different issues causing the BGP peer in active state instead of&amp;nbsp;established.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) BGP traffic from azure arives at our firewall, but is dropped with the reason "According to the policy the packet should not have been decrypted"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Normally with a policy based VPN, the VPN domains is the first thing I look at. But now we do use routed based and I have configured empty VPN domains as mentoined in the sk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a route for the BGP peer in Azure (connected to vpnt interface).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) BGP traffic initiated from our firewall, uses a funny ip as its source ip.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This traffic was first dropped ofcourse on our firewall since the rule I created uses the expected source ip. I tried to accept the traffic and use source NAT for this specifc traffic. Now the traffic is accepted, but not encrypted and routed over the tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any tips to troubleshoot any further are welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 14:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180636#M33017</guid>
      <dc:creator>Wesley_van_der_</dc:creator>
      <dc:date>2023-05-11T14:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and routebased VPN (Azure)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180666#M33025</link>
      <description>&lt;P&gt;Are you using a configuration similar to:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk176249" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk176249&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 19:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180666#M33025</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-11T19:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and routebased VPN (Azure)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180862#M33066</link>
      <description>&lt;P&gt;Yes. I used the sk to configure the VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 06:39:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180862#M33066</guid>
      <dc:creator>Wesley_van_der_</dc:creator>
      <dc:date>2023-05-15T06:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and routebased VPN (Azure)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180991#M33109</link>
      <description>&lt;P&gt;Recommend a TAC case here to investigate: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 21:34:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/180991#M33109</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-15T21:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and routebased VPN (Azure)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/181902#M33292</link>
      <description>&lt;P&gt;The first problem was solved by changing the alias of the vpnt interfaces. The alias of the interface needs to be exactly the same as the name of the interopable device object where this interface will be used for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second problem is solved by using NAT with the correct vpnt interfaces.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 12:04:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-routebased-VPN-Azure/m-p/181902#M33292</guid>
      <dc:creator>Wesley_van_der_</dc:creator>
      <dc:date>2023-05-24T12:04:04Z</dc:date>
    </item>
  </channel>
</rss>

