<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn access broken after setting up a cluster in high avaliablity in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199227#M37320</link>
    <description>&lt;P&gt;Thanks for the reply Andy, I spoke to my boss he doesn't want me sharing logs in an open forum unless we can make sure none of the public IP information is visible.&lt;/P&gt;&lt;P&gt;I will try to make sure I keep this thread updated once we have found the solution and the steps taken to resolve.&lt;/P&gt;&lt;P&gt;Checkpoint support are normally pretty quick, the client has pro support plus if I am not mistaken. I raised this issue on Friday, the 24th, and still no proper feedback from them. I hope its not other issues in the world causing challenges.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 05:46:44 GMT</pubDate>
    <dc:creator>rmasprey</dc:creator>
    <dc:date>2023-11-29T05:46:44Z</dc:date>
    <item>
      <title>vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199120#M37303</link>
      <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;&lt;P&gt;We have a client who had a single 3100 series device and vpn worked with L2TP and the windows client no problem, for other reasons we where not able to use the checkpoint client vpn. This solutions has worked perfectly and been in place for a number of years.&lt;/P&gt;&lt;P&gt;We upgraded the client to two 3600 series devices, and setup the cluster in high availability mode, so far everything else is working except the vpn. The VPN worked once when I tested it and now nothing happens.&lt;/P&gt;&lt;P&gt;The internet is on eth1, fw1 x.x.x.98, fw2 x.x.x.99, cluster ip x.x.x.100. which is the ip we always connected to. We sent checkpoint the debug files last night.&lt;/P&gt;&lt;P&gt;I have noticed in testing, when connecting I don't get the normal prompt to enter a user name and password.&lt;/P&gt;&lt;P&gt;Has anybody else had issues with L2TP vpn connectivity in a high availability cluster ? My colleague has had no issues at other sites with a similar setup but those sites are using the checkpoint vpn software to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 06:01:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199120#M37303</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-11-28T06:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199163#M37309</link>
      <description>&lt;P&gt;Were there other changes such as version involved at the same time, does it work when a specific cluster member is active?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 14:56:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199163#M37309</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-28T14:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199175#M37310</link>
      <description>&lt;P&gt;Thank you for the reply &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I have tried with disconnecting one of the devices, then the other, no luck. I have tried using the IP on each physical firewall, and also no luck.&lt;/P&gt;&lt;P&gt;Same versions on the old and new devices. R81.20 and the same blades are active.&lt;/P&gt;&lt;P&gt;Still waiting on checkpoint support for an update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 15:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199175#M37310</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-11-28T15:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199181#M37312</link>
      <description>&lt;P&gt;What version of code was it working on and what version is it failing on?&lt;BR /&gt;Other than testing the L2TP client, what debug/information did you gather from the gateway?&lt;BR /&gt;The following SK might help in terms of debug:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk17957" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk17957&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 15:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199181#M37312</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-28T15:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199185#M37315</link>
      <description>&lt;P data-unlink="true"&gt;Thank's for the SK &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; , we followed &lt;A href="https://support.checkpoint.com/results/sk/sk180488" target="_self"&gt;sk180488&lt;/A&gt;&amp;nbsp; which checkpoint directed us to. Will try the debug you have suggested and see if that gives us some insight.&lt;/P&gt;&lt;P data-unlink="true"&gt;We looked through the logs we generated for checkpoint but have not spotted a reason why its failing yet.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 15:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199185#M37315</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-11-28T15:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199189#M37316</link>
      <description>&lt;P&gt;Can you share logs here so we can have a look?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 17:08:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199189#M37316</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-28T17:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199227#M37320</link>
      <description>&lt;P&gt;Thanks for the reply Andy, I spoke to my boss he doesn't want me sharing logs in an open forum unless we can make sure none of the public IP information is visible.&lt;/P&gt;&lt;P&gt;I will try to make sure I keep this thread updated once we have found the solution and the steps taken to resolve.&lt;/P&gt;&lt;P&gt;Checkpoint support are normally pretty quick, the client has pro support plus if I am not mistaken. I raised this issue on Friday, the 24th, and still no proper feedback from them. I hope its not other issues in the world causing challenges.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 05:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199227#M37320</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-11-29T05:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199391#M37374</link>
      <description>&lt;P&gt;The issue you're describing, where the client could only connect once, sounds very similar to what happens when you have your Link Selection settings set to "Main IP" when the main IP of your cluster is not the IP address your VPN will terminate on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have not already, please collect a tcpdump packet capture on your gateway, filtered only for the public IP address of your L2TP client and share that alongside the debugs for TAC to review.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 21:01:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199391#M37374</guid>
      <dc:creator>D_Schoenberger</dc:creator>
      <dc:date>2023-11-30T21:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199392#M37375</link>
      <description>&lt;P&gt;Thats totally fair, understood. If you can share whatever possible, would help us.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 21:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199392#M37375</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T21:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199540#M37418</link>
      <description>&lt;P&gt;In case like this the client connects in Visitor mode and it disconnects after 60mins in my experience&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 23:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199540#M37418</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-12-01T23:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199865#M37480</link>
      <description>&lt;P&gt;Thank you for your reply. We are still trying to get this resolved with the assistance of checkpoint support. We had a remote session this morning with a T3 engineer who collected some more logs wile I was attempting to connect.&lt;/P&gt;&lt;P&gt;I had a look on the ipsec VPN on the cluster and link selection is set "Selected address from topology table" and the public facing ip is chosen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 14:18:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199865#M37480</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-12-06T14:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199873#M37483</link>
      <description>&lt;P&gt;One thing I would do personally is when you examine the logs collected, search for public IP of the client, as well as whatever external IP is they are connecting to and see what you can find.&lt;/P&gt;
&lt;P&gt;Not saying that will give you clear resolution, but at least it may "steer" in the right direction.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 14:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/199873#M37483</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-06T14:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/200039#M37511</link>
      <description>&lt;P&gt;Thank you to everybody who has commented. Checkpoint Support came back to us last night, it looks like we have a mismatch in encryption.&lt;/P&gt;&lt;P&gt;We re added the clients 3100 to our management server after updating all the ip's to new ones as a possible alternative. Last week checkpoint support removed the device in case it was causing a conflict.&lt;/P&gt;&lt;P&gt;When testing we got the vpn connection but the connection to the lan was not working. After 15 minutes I then started to get a response to a ping to a local device.&lt;/P&gt;&lt;P&gt;Last night I did some changes on the GW, under IPSec VPN, Traditional Mode. The bellow screen shots are from our 3100 device:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 408px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23589i1539E82BE812590A/image-dimensions/408x162?v=v2" width="408" height="162" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 278px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23590i3DE52B0F3B884A97/image-dimensions/278x242?v=v2" width="278" height="242" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Advanced Tab&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 421px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23591iF8EA11FF028A6DFC/image-dimensions/421x313?v=v2" width="421" height="313" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I click okay it gives me an error "check one data integrity method", so I have clicked cancel, and if I open it again I get the same.&lt;/P&gt;&lt;P&gt;In my testing last night I cleared the traditional mode on cluster settings as they had all been ticked, then tried to set it to what windows l2pn connection wanted then matched it to what the 3100 showed as we could establish the connection to that device.&lt;/P&gt;&lt;P&gt;The cluster shows the following under Traditional mode IKE Properties:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 488px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23592i7B260242F003D1D1/image-dimensions/488x429?v=v2" width="488" height="429" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Under Advanced settings, I have only selected group 2, previously 19 and 20 where also ticked.&lt;/P&gt;&lt;P&gt;The 3600 member's had new IP Addresses assigned to their network ports and we changed the main ip address on the 3100 and unplugged it from the network when we added the virtual Ip addresses on the cluster to match the 3100 ip addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 494px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23593i5C4A4D5E0CCB1237/image-dimensions/494x236?v=v2" width="494" height="236" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The cluster virtual IP column is what we had on the 3100 device.&lt;/P&gt;&lt;P&gt;In my testing the vpn to the 3100 on a different public ip is working today as it always use to. The vpn to the cluster and the normal public ip does nothing. It almost looks like the policy for the Gateway settings are not applying properly. The 3100 was our main firewall, which was replaced with 2 3600 in high availability mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 06:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/200039#M37511</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-12-08T06:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: vpn access broken after setting up a cluster in high avaliablity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/200393#M37603</link>
      <description>&lt;P&gt;Checkpoint T3 support is still investigating the issue. In the Debug the negotiation is failing on phase2, and the other error that is seen is :&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TransMatchFailure: prop# 1 propID ISAKMP trans# 1 transID 1 reason &amp;lt;Wrong value for: Authentication Method&amp;gt;&lt;BR /&gt;TransMatchFailure: prop# 1 propID ISAKMP trans# 2 transID 1 reason &amp;lt;Wrong value for: Hash Algorithm&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We getting vpn connectivity on the old 3100 no issues, but for some reason the 3600 in cluster mode is giving the above errors.&lt;/P&gt;&lt;P&gt;Checkpoint Support checked through out settings, and we have them set the same as the 3100.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 06:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpn-access-broken-after-setting-up-a-cluster-in-high-avaliablity/m-p/200393#M37603</guid>
      <dc:creator>rmasprey</dc:creator>
      <dc:date>2023-12-13T06:04:26Z</dc:date>
    </item>
  </channel>
</rss>

