<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20 IPSEC Tunnel with Zscaler in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194605#M36237</link>
    <description>&lt;P&gt;I m trying to find the scenario which is relevant to me but one thing i dont understand is why i am not able to ping the zscaler endpoint once i put my cluster in the vpn community.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 04:51:10 GMT</pubDate>
    <dc:creator>LostBoY</dc:creator>
    <dc:date>2023-10-10T04:51:10Z</dc:date>
    <item>
      <title>R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194575#M36226</link>
      <description>&lt;P&gt;I setup an IPSEC Tunnel in Fortinet FWs with Zscaler and it works fine. Now i am trying to do the same in a similar environment with CP 81.20 Cluster.IPSEC tunnel is not working and one problem i noticed is that once i enable the VPN Community i no longer can ping Zscaler endpoints with which the tunnel needs to be stablished. They ping perfectly fine from the GW when i remove the CP CLuster from VPN Community.&lt;/P&gt;&lt;P&gt;Is this expected behaviour in Checkpoint ? Shouldnt the endpoints be reachable even if they are part of the community ? is there any other step i need to do in order to reach the Zscaler endpoints.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 20:15:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194575#M36226</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-10-09T20:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194580#M36227</link>
      <description>&lt;P&gt;You may want to do captures or zdebung to see why it fails, but sounds like it could be one of the scenarios from below sk.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 21:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194580#M36227</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T21:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194583#M36228</link>
      <description>&lt;P&gt;I presume you set this up per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk174848" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk174848&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 22:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194583#M36228</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-09T22:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194602#M36236</link>
      <description>&lt;P&gt;Yes..i followed this precisely&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 02:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194602#M36236</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-10-10T02:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194605#M36237</link>
      <description>&lt;P&gt;I m trying to find the scenario which is relevant to me but one thing i dont understand is why i am not able to ping the zscaler endpoint once i put my cluster in the vpn community.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 04:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194605#M36237</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-10-10T04:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194639#M36241</link>
      <description>&lt;P&gt;Thankfully i figured out the problem..as it turned out NAT-T is enabled by default on VPN domain.&lt;/P&gt;&lt;P&gt;As my Cluster isnt behind any NAT device it was unable to negotiate ike phase 2 with NAT-T on.. as soon as i turned it off Tunnel was established successfully.&lt;/P&gt;&lt;P&gt;Thanks to everyone who replied to this topic.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 09:29:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194639#M36241</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-10-10T09:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 IPSEC Tunnel with Zscaler</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194641#M36243</link>
      <description>&lt;P&gt;Good job ✔&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:10:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-IPSEC-Tunnel-with-Zscaler/m-p/194641#M36243</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T10:10:42Z</dc:date>
    </item>
  </channel>
</rss>

