<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S2S VPN history. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195949#M36544</link>
    <description>&lt;P&gt;Hello, Mates.&lt;/P&gt;
&lt;P&gt;Is there any way to see the "summary" of the status of a VPN?&lt;/P&gt;
&lt;P&gt;My intention is to know if a S2S VPN that we have against a third party is down or rebooted maybe 12 hours ago.&lt;/P&gt;
&lt;P&gt;I am looking for options in the SmartView Monitor, but I can't find an appropriate option.&lt;/P&gt;
&lt;P&gt;Any ideas that can help me please?&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Oct 2023 17:57:25 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-10-23T17:57:25Z</dc:date>
    <item>
      <title>S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195949#M36544</link>
      <description>&lt;P&gt;Hello, Mates.&lt;/P&gt;
&lt;P&gt;Is there any way to see the "summary" of the status of a VPN?&lt;/P&gt;
&lt;P&gt;My intention is to know if a S2S VPN that we have against a third party is down or rebooted maybe 12 hours ago.&lt;/P&gt;
&lt;P&gt;I am looking for options in the SmartView Monitor, but I can't find an appropriate option.&lt;/P&gt;
&lt;P&gt;Any ideas that can help me please?&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 17:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195949#M36544</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-23T17:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195952#M36545</link>
      <description>&lt;P&gt;The only thing we log is when the tunnel "comes up" (key install).&lt;BR /&gt;The tunnel never really goes "down" unless the remote end stops responding (which should be logged).&lt;/P&gt;
&lt;P&gt;In R82, I believe we plan to have some enhanced VPN monitoring features.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 18:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195952#M36545</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-23T18:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195953#M36546</link>
      <description>&lt;P&gt;Uhm,&lt;/P&gt;
&lt;P&gt;I have a S2S VPN, which 12 hours ago, lost connection between both sides of the VPN.&lt;/P&gt;
&lt;P&gt;So, we want to "see" if in that time range, the VPN was logged as "down" in Check Point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have made some filters in the SmartConsole, "calling" only the VPN community under discussion, and filtering the "action" field with a "Key Install".&lt;/P&gt;
&lt;P&gt;And this is the result I get.&lt;/P&gt;
&lt;P&gt;Exactly what does the "Key Install" mean?&lt;/P&gt;
&lt;P&gt;Is it the moment when Check Point "detects" that a VPN is being set up?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22924i302DB5AC1012F478/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN2.png" alt="VPN2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22923i34CC5B332970E3FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN1.png" alt="VPN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Is there any option that you think can help me?&lt;BR /&gt;&lt;BR /&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 21:29:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/195953#M36546</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-23T21:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196032#M36568</link>
      <description>&lt;P&gt;A VPN connection requires symmetric encryption keys to be generated every so often with the various IPsec timers determining how often this is done.&lt;BR /&gt;Likewise, the remote end might request termination and issue a "delete IKE SA request."&lt;BR /&gt;These are logged as "Key Install" events as they affect the encryption keys used.&lt;/P&gt;
&lt;P&gt;If the remote VPN peer cannot be reached, you may see "peer not responding" messages in the logs.&lt;BR /&gt;However, this will only occur if there is active traffic on the VPN.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 13:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196032#M36568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-24T13:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196046#M36570</link>
      <description>&lt;P&gt;Old Legacy SV Monitor has Tunnels on GW &amp;gt; VPN History &amp;gt; Last Day &amp;gt; Active Tunnels Average that should show it.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196046#M36570</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-24T15:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196050#M36572</link>
      <description>&lt;P&gt;A monitoring tool could help.&lt;BR /&gt;&lt;BR /&gt;For example pinging a host across the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other option is with SNMP :&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk63663" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk63663&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196050#M36572</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-10-24T15:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196055#M36575</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This action ""delete IKE SA request.", does not necessarily mean that the VPN TUNEL, is "down" right?&lt;/P&gt;
&lt;P&gt;I mean, the remote peer may send a message like "delete IKE SA request.", but for us, it may be something "transparent", and we could still see the tunnel "active", at that moment?&lt;/P&gt;
&lt;P&gt;Or is this action necessarily going to lower the tunnel?&lt;/P&gt;
&lt;P&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 17:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196055#M36575</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-24T17:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN history.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196186#M36599</link>
      <description>&lt;P&gt;Correct, an IKE SA being deleted does not necessarily mean the tunnel is down.&lt;BR /&gt;In IKEv2, it's actually done as part of the rekeying process that should happen every few hours (so called Break Before Make).&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 17:24:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-history/m-p/196186#M36599</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-25T17:24:59Z</dc:date>
    </item>
  </channel>
</rss>

