<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VTI tunnel not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/184870#M34044</link>
    <description>&lt;P&gt;I have two firewall. one is 6200 and other 1500 SMB appliance. I have created a VTI tunnel but the tunnel is not working.&lt;/P&gt;&lt;P&gt;I have created simple group for vpn domain. But on SMB it can't fetch topology properly as you can see in image I have attached.&lt;/P&gt;&lt;P&gt;why it can't fetch the VPN reomte peer ip address?&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jun 2023 04:40:04 GMT</pubDate>
    <dc:creator>PankajTiwari1</dc:creator>
    <dc:date>2023-06-27T04:40:04Z</dc:date>
    <item>
      <title>VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/184870#M34044</link>
      <description>&lt;P&gt;I have two firewall. one is 6200 and other 1500 SMB appliance. I have created a VTI tunnel but the tunnel is not working.&lt;/P&gt;&lt;P&gt;I have created simple group for vpn domain. But on SMB it can't fetch topology properly as you can see in image I have attached.&lt;/P&gt;&lt;P&gt;why it can't fetch the VPN reomte peer ip address?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 04:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/184870#M34044</guid>
      <dc:creator>PankajTiwari1</dc:creator>
      <dc:date>2023-06-27T04:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/184990#M34045</link>
      <description>&lt;P&gt;What is the 6200 running (Version/JHF)?&lt;BR /&gt;What firmware is the 1500 running?&lt;BR /&gt;Are both of these gateways managed by the same management? (If so, what version/JHF is managing it)&lt;BR /&gt;You created a VTI tunnel: following what instructions, exactly?&lt;BR /&gt;"I have created simple group for VPN domain" ok, but where was this configured?&lt;BR /&gt;"Tunnel is not working"&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How did you attempt to test it?&lt;/LI&gt;
&lt;LI&gt;How did you determine it "failed"?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please provide precise troubleshooting steps taken with errors provided.&lt;/P&gt;
&lt;P&gt;It's not clear to me if Fetch Topology should fetch the "remote IP" for the VTI peer.&lt;BR /&gt;You should enter that manually if it is not being fetched.&lt;BR /&gt;If you want to "fix" Fetch Topology, I recommend a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 20:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/184990#M34045</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-27T20:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185009#M34046</link>
      <description>&lt;P&gt;the 6200 series running version is R81.10 JHF 95 and 1500 series version is R81.10.05.&lt;/P&gt;&lt;P&gt;Both gateways are managed by separate management server. Both have running version is R81.20 JHF 10.&lt;/P&gt;&lt;P&gt;And 6200 series appliance are in cluster.&lt;/P&gt;&lt;P&gt;VTI interface topology.........&lt;/P&gt;&lt;P&gt;I created VTI 18. For cluster I assigned IP address....&amp;nbsp; &amp;nbsp;VIP- 169.254.180.15, GW1- 169.254.180.11, GW2- 169.254.180.9&lt;/P&gt;&lt;P&gt;For SMB 1500 series VTI IP is 169.254.180.10&lt;/P&gt;&lt;P&gt;For testing purposes I run the command VPN TU TLIST and it shows NO outbound SA error.&lt;/P&gt;&lt;P&gt;I can't enter manually maybe it fetch automatically from the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 04:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185009#M34046</guid>
      <dc:creator>PankajTiwari1</dc:creator>
      <dc:date>2023-06-28T04:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185113#M34047</link>
      <description>&lt;P&gt;I don't think that a TAC case is warranted for first time implementations. --- Account Managers, and Sales Engineers on your team should be able to assist, or connect you with PS for assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A few points I noticed:&lt;/P&gt;
&lt;P&gt;- Your interfaces are set to DHCP Ranges? They should be routable.&lt;/P&gt;
&lt;P&gt;- If the SMB Device doesn't have a static IP, ensure you have some kind of DynDNS so that we can reach it reliably, otherwise tunnel will only be reliably initiated from SMB side.&lt;/P&gt;
&lt;P&gt;- If you've followed all the steps outlined in the Admin Guide, make sure you have routes set up.. VTI's are not community based, and will require the traffic to be actually routed out that interface.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VPN-Tunnel-Interfaces.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VPN-Tunnel-Interfaces.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/IPv4-Static-Routes.htm?tocpath=Network%20Management%7CIPv4%20Static%20Routes%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/IPv4-Static-Routes.htm?tocpath=Network%20Management%7CIPv4%20Static%20Routes%7C_____0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 23:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185113#M34047</guid>
      <dc:creator>SSlater</dc:creator>
      <dc:date>2023-06-28T23:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185257#M34064</link>
      <description>&lt;P&gt;Thanks for your support. the issue is resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 05:38:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185257#M34064</guid>
      <dc:creator>PankajTiwari1</dc:creator>
      <dc:date>2023-06-30T05:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185359#M34087</link>
      <description>&lt;P&gt;How did you resolve the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 20:31:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185359#M34087</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-30T20:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185413#M34104</link>
      <description>&lt;P&gt;I'm still not getting VPN&amp;nbsp; peer IP address on topology page but tunnel is working.&lt;/P&gt;&lt;P&gt;On the VPN domain page I have All IP addresses behind Gateway to I have selected user defined. In which I have selected empty Group and then I published and install the policy and its working.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 05:32:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185413#M34104</guid>
      <dc:creator>PankajTiwari1</dc:creator>
      <dc:date>2023-07-03T05:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185501#M34113</link>
      <description>&lt;P&gt;An empty encryption domain is normal for route-based VPNs.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 19:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/185501#M34113</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-03T19:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: VTI tunnel not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/186112#M34254</link>
      <description>&lt;P&gt;I know that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I have empty group in VPN communities on both sides but empty group is not defined on VPN domain. When I defined empty group in vpn domain and install the policy and it worked.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 09:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VTI-tunnel-not-working/m-p/186112#M34254</guid>
      <dc:creator>PankajTiwari1</dc:creator>
      <dc:date>2023-07-11T09:31:31Z</dc:date>
    </item>
  </channel>
</rss>

