<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN with 3rd party DAIP Gateway(Strongswan IPSec in Ubuntu) with RSA Auth in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/202621#M38125</link>
    <description>&lt;P&gt;Can you help me with your configuration settings? I'm trying but with no success.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jan 2024 17:10:00 GMT</pubDate>
    <dc:creator>Kalloww00</dc:creator>
    <dc:date>2024-01-09T17:10:00Z</dc:date>
    <item>
      <title>Site to Site VPN with 3rd party DAIP Gateway(Strongswan IPSec in Ubuntu) with RSA Auth</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197935#M37005</link>
      <description>&lt;P&gt;I have tested the site to site vpn between checkpoint and DAIP gateway(Strongswan ipsec in Ubuntu) with RSA auth in lab and able to bring the tunnel up.&lt;/P&gt;&lt;P&gt;During the testing I encountered below issue on Strongswan ipsec side,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Checkpoint is sending MM packet 6, but Strongswan ipsec is dropping with error “no trusted RSA public key found for &amp;lt;ip address&amp;gt;”.&lt;/LI&gt;&lt;LI&gt;The Strongswan ipsec is expecting the peer identity(peer IP in my case) to be present on checkpoint certificate's Subject Alternate Name.&lt;/LI&gt;&lt;LI&gt;The checkpoint default certificate will have CN as hostname and SAN as management IP.&lt;/LI&gt;&lt;LI&gt;I resolved it by creating new certificate with SAN contains identity IP.&lt;/LI&gt;&lt;LI&gt;In checkpoint only one internal_ca signed certificate can be created for IPsec, So to create new certificate I used 3rd party CA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My query is about adding new 3rd party signed certificate on gateway ipsec properties, can it cause any issue to existing vpn? As per my understanding it should not cause negative impact. Please clarify whether my understanding is correct or wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 16:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197935#M37005</guid>
      <dc:creator>Pavan_Kumar</dc:creator>
      <dc:date>2023-11-14T16:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with 3rd party DAIP Gateway(Strongswan IPSec in Ubuntu) with RSA Auth</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197957#M37009</link>
      <description>&lt;P&gt;It shouldn't, no.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 00:40:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197957#M37009</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-15T00:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with 3rd party DAIP Gateway(Strongswan IPSec in Ubuntu) with RSA Auth</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197964#M37011</link>
      <description>&lt;P&gt;Thanks for clearing my doubt..&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 05:38:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/197964#M37011</guid>
      <dc:creator>Pavan_Kumar</dc:creator>
      <dc:date>2023-11-15T05:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with 3rd party DAIP Gateway(Strongswan IPSec in Ubuntu) with RSA Auth</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/202621#M38125</link>
      <description>&lt;P&gt;Can you help me with your configuration settings? I'm trying but with no success.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 17:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-with-3rd-party-DAIP-Gateway-Strongswan-IPSec-in/m-p/202621#M38125</guid>
      <dc:creator>Kalloww00</dc:creator>
      <dc:date>2024-01-09T17:10:00Z</dc:date>
    </item>
  </channel>
</rss>

