<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN tunnel in Phase-1 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198297#M37092</link>
    <description>&lt;P&gt;Is this configured as permanent tunnel?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 17 Nov 2023 19:06:37 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-11-17T19:06:37Z</dc:date>
    <item>
      <title>VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198295#M37091</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After upgrading the central firewall to R81.10, the tunnel stays in phase-1. There is status information below.&lt;BR /&gt;In some places, it is written that I need to create traffic. Does anyone have any information?&lt;/P&gt;&lt;P&gt;Central FW: version R81.10 Hotfix: 110. Cluster&lt;/P&gt;&lt;P&gt;Branch FW: 1530 appliance, version:&amp;nbsp;R80.20.30&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN tunnel monitor log:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Tunnel centralfw&amp;lt;=&amp;gt; sideA
State Up - Phase1
Community sideAVPNSite
Type Regular

From sideA
To centralfw
State Up - Phase1
Peer IP X.X.X.14
Next Hop IP N/A
Interface N/A
Source IP N/A
Link Priority Primary
Prob State N/A
Peer Type Regular
UDP Encapsulation None
MEP participants&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your replying.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 18:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198295#M37091</guid>
      <dc:creator>ikafka</dc:creator>
      <dc:date>2023-11-17T18:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198297#M37092</link>
      <description>&lt;P&gt;Is this configured as permanent tunnel?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 19:06:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198297#M37092</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-17T19:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198302#M37095</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My problem has solved. I checked all VPN comunity configuration. I see sideA WAN IP address is wrong. when change it true IP address tunnel is connected and status&amp;nbsp; up.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 19:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198302#M37095</guid>
      <dc:creator>ikafka</dc:creator>
      <dc:date>2023-11-17T19:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198307#M37098</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 19:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198307#M37098</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-17T19:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198330#M37113</link>
      <description>&lt;P&gt;Kind of strange, after upgrade it is not working.&lt;/P&gt;&lt;P&gt;But after your checking, found out to be wrong configuration?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2023 01:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198330#M37113</guid>
      <dc:creator>just13pro</dc:creator>
      <dc:date>2023-11-18T01:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel in Phase-1</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198339#M37119</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76362"&gt;@just13pro&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, that is strange. I wrote that it was solved briefly due to workload. I will now give a detailed explanation.&lt;/P&gt;&lt;P&gt;2 months ago, we made an ip change in the region where we used the 1530 series device. After this change, 1530 was reconnected to the central management according to the new WAN IP address (with SIC.)&lt;/P&gt;&lt;P&gt;After so much time passed, we realized that there was no ping from the center to the sideA.&amp;nbsp; that not only ping but also IP phone etc. nothing works.&lt;/P&gt;&lt;P&gt;When I checked, I saw that it was so, but ping is coming from sideA. When I looked at the logs, I saw these logs.&lt;/P&gt;&lt;P&gt;@;65686661;[cpu_0];[fw4_1];fw_log_drop_ex: Packet proto=1 10.99.5.20:2048 -&amp;gt; 172.16.0.10:16972 dropped by fw_ipsec_encrypt_on_tunnel_instance Reason: No error - tunnel is not yet established;&lt;/P&gt;&lt;P&gt;When I monitored the tunnel, I saw the above output (tunnel monitoring output). I realized that the tunnel was one-way UP. Then it occurred to me to check the community settings. (I think this was the first thing I should have done. sometimes this happens unfortunately. ) There was no problem with the community settings. When I looked at the 1530 firewall object, I realized that the WAN IP address was different. After changing the WAN IP address to the current one, the tunnel was up.&lt;/P&gt;&lt;P&gt;I don't understand how the tunnel worked for so long and ping, IP phone continued to work. As a result, the process worked like this. as a result, it is a fact that there is a STRANGE situation. or if there is an explanation, if anybody writes and enlightens this situation, I will learn something.&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2023 09:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-in-Phase-1/m-p/198339#M37119</guid>
      <dc:creator>ikafka</dc:creator>
      <dc:date>2023-11-19T09:49:17Z</dc:date>
    </item>
  </channel>
</rss>

