<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN tunnel is narrowed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205471#M38772</link>
    <description>&lt;P&gt;Personally, I had done it probably 50 times at least, no issues. To be 100% sure, I would do it after hours. Does not affect much else aprt from the tunnel and from all I had seen, the most I would say it would ffect the speed is maybe 5%, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 13:58:07 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-08T13:58:07Z</dc:date>
    <item>
      <title>Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205464#M38766</link>
      <description>&lt;P&gt;I have a CP gateway that built two VPN tunnels to two branch offices as below:&lt;/P&gt;&lt;P&gt;Main Office: FW01 (CP 6000), VPN domain is 172.17.0.0/24&lt;/P&gt;&lt;P&gt;Office A: FW02 (SMB 1595), VPN domain is 192.168.1.0/24&lt;/P&gt;&lt;P&gt;Office B: FW03 (3rd party GW), VPN domain is 192.168.1.3/24&lt;/P&gt;&lt;P&gt;Two star VPN communities were created:&lt;/P&gt;&lt;P&gt;VPN_Community_A: contain FW01 and FW02&lt;/P&gt;&lt;P&gt;VPN_Community_B: contain FW01 and FW03&lt;/P&gt;&lt;P&gt;Each gateway is managed separately.&lt;/P&gt;&lt;P&gt;After setup, tunnels are up and VPN work. However, we found sometimes VPN between FW01 and FW02 is unstable, it may drop few packets in each day. No such issue found in VPN between FW01 and FW03. We had checked all the settings, all look fine.&lt;/P&gt;&lt;P&gt;The vpn tu tlist show there are ***Eclipsed*** and ***Narrow*** for VPN tunnels between FW01 and FW02. According to &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk166417&lt;/SPAN&gt;&lt;/SPAN&gt;, this usually caused by mismatch in the configuration of the VPN with the peer, particularly the "VPN Domain" section of both sides. We checked the VPN domain section several times, and ensure there are no overlapping or mismatch.&lt;/P&gt;&lt;P&gt;Since FW01's VPN domain is used in two VPN communities, is that cause the issue? I can't use same VPN domain in two different communities? Any hints will be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:50:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205464#M38766</guid>
      <dc:creator>Andy1977</dc:creator>
      <dc:date>2024-02-08T13:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205465#M38767</link>
      <description>&lt;P&gt;Thats not an issue mate, people use same vpn domain in 20 VPN communities, seen it before, no worries there. Just curious, are both tunnels set as permenent in the VP{M communities?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205465#M38767</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T13:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205467#M38768</link>
      <description>&lt;P&gt;On a side note, you can try turn off securexl to see if it fixes the issue OR just do vpn accel, as per below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk151114" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk151114&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205467#M38768</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T13:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205468#M38769</link>
      <description>&lt;P&gt;The VPN for FW01 and FW02 is permanent. VPN for FW01 and FW03 not permanent.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205468#M38769</guid>
      <dc:creator>Andy1977</dc:creator>
      <dc:date>2024-02-08T13:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205469#M38770</link>
      <description>&lt;P&gt;I think you mistyped, you said fw1 and fw2 twice, I guess you meant fw03 in one of those, but not sure which one.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205469#M38770</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T13:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205470#M38771</link>
      <description>&lt;P&gt;Yes, I also saw this post. May be I turn off VPN accel between FW01 and FW02. But I wonder what's the impact to turn off VPN accel? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205470#M38771</guid>
      <dc:creator>Andy1977</dc:creator>
      <dc:date>2024-02-08T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205471#M38772</link>
      <description>&lt;P&gt;Personally, I had done it probably 50 times at least, no issues. To be 100% sure, I would do it after hours. Does not affect much else aprt from the tunnel and from all I had seen, the most I would say it would ffect the speed is maybe 5%, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205471#M38772</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T13:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205472#M38773</link>
      <description>&lt;P&gt;Oh, yes. My typo, FW01 and FW02 is permanent VPN. FW01 and FW03 not permanent.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205472#M38773</guid>
      <dc:creator>Andy1977</dc:creator>
      <dc:date>2024-02-08T13:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205473#M38774</link>
      <description>&lt;P&gt;Here is my suggestion...&lt;/P&gt;
&lt;P&gt;1) Set tunnel with the issue same as one that works fine, install policy, observe&lt;/P&gt;
&lt;P&gt;IF no luck, then&lt;/P&gt;
&lt;P&gt;2) Turn off vpn accel, observe&lt;/P&gt;
&lt;P&gt;If still no luck, maybe run simple vpn debug (can be left for a long time) and have a quick look, if nothing obvious, maybe open TAC case&lt;/P&gt;
&lt;P&gt;debug:&lt;/P&gt;
&lt;P&gt;vpn debug trunc (rotates vpn debug files)&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic&lt;/P&gt;
&lt;P&gt;Leave debug for even 48 hours&lt;/P&gt;
&lt;P&gt;get vpnd.elg* and ike* files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;to turn off debug:&lt;/P&gt;
&lt;P&gt;fw ctl debug -x&lt;/P&gt;
&lt;P&gt;fw ctl debug 0&lt;/P&gt;
&lt;P&gt;All commands are in expert mode&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 14:03:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205473#M38774</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T14:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205477#M38775</link>
      <description>&lt;P&gt;I run vpn debug and use IKEView to look at the debug files. The 6 packets in Main Mode and 3 packets in Quick Mode are all fine. Tunnels are all up and running, but just occasionally lost some packets and then resumed shortly. I will see if turn off VPN accel help or not. Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 14:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205477#M38775</guid>
      <dc:creator>Andy1977</dc:creator>
      <dc:date>2024-02-08T14:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN tunnel is narrowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205478#M38776</link>
      <description>&lt;P&gt;sounds good!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 14:14:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-tunnel-is-narrowed/m-p/205478#M38776</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T14:14:05Z</dc:date>
    </item>
  </channel>
</rss>

