<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189883#M35005</link>
    <description>&lt;P&gt;&lt;SPAN&gt;What version/JHF are the gateways and management?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;What is the exact nature of the traffic?&lt;BR /&gt;&lt;/SPAN&gt;What are the exact Access Policy rules being used to permit traffic in these cases?&lt;BR /&gt;The “fix” for this is to ensure rules that match on the first packet are used (ie must be a simple TCP/UDP service).&lt;BR /&gt;This is basically what sk113479 says.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2023 13:26:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-08-18T13:26:40Z</dc:date>
    <item>
      <title>IPSec VPN Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189864#M35001</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We recently faced with an issue on all our IPSec VPN's. We have around 10 Site to Site IPSec VPN's with different third parties. All tunnels are up on both phases. But on some tunnles, our ED's can't reach the Remote ED with an error of&amp;nbsp;"Connection terminated before detection: Insufficient data passed. To learn more see sk113479."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But before we all able to reach the remote ED's from our local ED's. Now, The remote ED can able to reach to our Local ED. Below you can find the screenshot.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What could cause this? Any suggestion will be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 11:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189864#M35001</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-18T11:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189866#M35002</link>
      <description>&lt;P&gt;In laymans terms, all that sk is literally telling you is that 3 way handshake is not happening, so you would definitely need to run captures to figure out why. In my experience, its usually not CP issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:22:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189866#M35002</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-18T12:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189879#M35003</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What kidn of captures should I ran&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189879#M35003</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-18T12:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189880#M35004</link>
      <description>&lt;P&gt;You will see few commands at the bottom of the file I attached.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:55:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189880#M35004</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-18T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189883#M35005</link>
      <description>&lt;P&gt;&lt;SPAN&gt;What version/JHF are the gateways and management?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;What is the exact nature of the traffic?&lt;BR /&gt;&lt;/SPAN&gt;What are the exact Access Policy rules being used to permit traffic in these cases?&lt;BR /&gt;The “fix” for this is to ensure rules that match on the first packet are used (ie must be a simple TCP/UDP service).&lt;BR /&gt;This is basically what sk113479 says.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 13:26:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189883#M35005</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-18T13:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189943#M35021</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;May be If the below description helps.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;JHF Take 197 is installed on both Gaeywats and the management server&lt;/P&gt;&lt;P&gt;One scenario may be helping in this case is we have a IPSec tunnel with a third party with 3 Local ED's and 6 Remote ED's of different subnets on the same peer. Previosuly, on the tunnel managment option of VPN Community, One VPN Tunnel per subnet pair is selected. And at a time 1 ED is working and all other ED's are down on phase 2. Then I have selected One VPN tunnel per gateway pair, and now all the ED's are UP on phase 2.&lt;/P&gt;&lt;P&gt;All 6 Remote ED's are reaching our Local ED's But Our local ED's ca't reach the Remote ED's. The partner said the traffic is not reaching their destination. When I checked from checkpoint Log it shows Connection terminated.&lt;/P&gt;&lt;P&gt;Does selecting VPN tunnel per gateway pair have an impact?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 15:42:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189943#M35021</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-20T15:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189944#M35022</link>
      <description>&lt;P&gt;I believe you would select that option per gateway if you use mix of hosts and subnets. I also see customers use it when having Azure or AWS tunnel thats permanent route based.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 15:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189944#M35022</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-20T15:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189945#M35023</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What about this one? All 6 Remote ED's are reaching our Local ED's But Our local ED's can't reach the Remote ED's. The partner said the traffic is not reaching their destination. When I checked from checkpoint Log it shows Connection terminated.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;How can I fix the connection terminated. Insufficient Data Passed error&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 18:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189945#M35023</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-20T18:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189946#M35024</link>
      <description>&lt;P&gt;Understood. What does it show from fw monitor? At what point does the connection terminate?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 19:26:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189946#M35024</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-20T19:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189952#M35027</link>
      <description>&lt;P&gt;Below is the output from fwmonitor&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 05:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189952#M35027</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-21T05:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189967#M35028</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84011"&gt;@gemechisd&lt;/a&gt;&amp;nbsp;, will review it later. Can you please indicate affected IP addresses? ie your end, their end?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 11:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189967#M35028</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T11:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189974#M35033</link>
      <description>&lt;P&gt;Local ED: 10.100.140.35 &amp;amp; 10.1.175.111&lt;BR /&gt;&lt;BR /&gt;Remote ED: 102.318.58.83 &amp;amp; 10.0.103.8&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 12:01:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189974#M35033</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-21T12:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189976#M35035</link>
      <description>&lt;P&gt;Ok, so I see from your screencap that i and I are happening on eth1-02 and o on eth1...is that expected? You probably wont see big O since connection would be encrypted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 12:06:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189976#M35035</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T12:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189987#M35041</link>
      <description>&lt;P&gt;By the way, did you ever end up opening TAC case for this?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 13:26:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189987#M35041</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T13:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189989#M35043</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;eth1 &amp;amp; eth1-02.&lt;BR /&gt;&lt;BR /&gt;eth1 is when I try to ping the Remote Host.&lt;BR /&gt;&lt;BR /&gt;eth1-02 is when I try to telnet the Remote Host.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 13:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189989#M35043</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-21T13:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189990#M35044</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I haven't opened a TAC Case.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 13:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189990#M35044</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-08-21T13:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189991#M35045</link>
      <description>&lt;P&gt;I think it might be a good idea at this point, as its possible this will require further debugging.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 13:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/189991#M35045</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T13:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/190002#M35048</link>
      <description>&lt;P&gt;The VPN configuration is only relevant insofar as the actual Access Policy rules used to allow the relevant traffic, which you did not provide here.&lt;BR /&gt;Please provide screenshots (sensitive details redacted).&lt;BR /&gt;The services used in the rules should NOT be redacted.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 15:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/190002#M35048</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-21T15:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Connection terminated</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/191510#M35336</link>
      <description>&lt;P&gt;Any APPC/URLF rule matched for that traffic?&lt;/P&gt;
&lt;P&gt;If so, try to put a rule for the affected traffic with Action accept on top inside the layer (or in-line layer) for APPC/URLF rulebase&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 20:33:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-VPN-Connection-terminated/m-p/191510#M35336</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-09-04T20:33:02Z</dc:date>
    </item>
  </channel>
</rss>

