<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permanent tunnel question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/207543#M39261</link>
    <description>&lt;P&gt;Did you manage to get a answer to this?&lt;/P&gt;&lt;P&gt;I am also wondering how the permanent tunnels are supposed to work (check point to check point). I have seen that the satellite gateways encrypts the tunnel_test and on the central it gets decrypted. But when Central initiates a tunnel tests it does not encrypt it, in the other end at the satellite it gets dropped because it expects the packet to be encrypted. "Clear text packet should be encrypted"&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 10:24:46 GMT</pubDate>
    <dc:creator>frankthetank_69</dc:creator>
    <dc:date>2024-03-01T10:24:46Z</dc:date>
    <item>
      <title>Permanent tunnel question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137927#M20898</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I had a question and I hope someone can give an answer. Just wondering, when someone sets up vpn site to site with say 1 central gateway and bunch of satellite gateways and its set as permanent tunnel, should tunnel management have 1 subnet per pair or gateway? Also, should tunnel_keepalive_method be set to tunneltest on all sides, or dpd on central gw and tunnel test on others?&lt;/P&gt;
&lt;P&gt;Reason I ask is because we have customer who has intermittent vpn disconnect issues and sadly, TAC cant find any sk's or documents advising on how permanent tunnels between cp devices should be configured.&lt;/P&gt;
&lt;P&gt;They have tunnel_keepalive_method set in guidbedit to dpd for central cluster and as tunneltest for all satellite ones and all satellite gw's are 1100 managed by another management server and all configured as externally managed gateways in dashboard for vpn purpose, so 1 central gateway in community and about 20 satellite ones, same vpn star community.&lt;/P&gt;
&lt;P&gt;This all worked fine for so many months and all of a sudden yesterday, things started ocurring without any changes,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any insight would be appreciated!&lt;/P&gt;
&lt;P&gt;Thanks as always!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 02:11:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137927#M20898</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-10T02:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent tunnel question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137942#M20900</link>
      <description>&lt;P&gt;Long shot, but does this perhaps correlate with policy pushes?&amp;nbsp; I ran into the issue described in&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk142355" target="_self"&gt;sk142355&lt;/A&gt; a couple of times already.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 11:14:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137942#M20900</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-01-08T11:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent tunnel question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137949#M20902</link>
      <description>&lt;P&gt;Thank you for the reply, but not related. Customer has that enabled and VPN tunnels issue happens randomly, never after policy push.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 14:01:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/137949#M20902</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-08T14:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent tunnel question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/207543#M39261</link>
      <description>&lt;P&gt;Did you manage to get a answer to this?&lt;/P&gt;&lt;P&gt;I am also wondering how the permanent tunnels are supposed to work (check point to check point). I have seen that the satellite gateways encrypts the tunnel_test and on the central it gets decrypted. But when Central initiates a tunnel tests it does not encrypt it, in the other end at the satellite it gets dropped because it expects the packet to be encrypted. "Clear text packet should be encrypted"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:24:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/207543#M39261</guid>
      <dc:creator>frankthetank_69</dc:creator>
      <dc:date>2024-03-01T10:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent tunnel question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/207573#M39267</link>
      <description>&lt;P&gt;Actually yes. It turns out you set it as "one tunnel per gateway pair" and permanent tunnel in tunnel mgmt tab, which would present 0.0.0.0/0 as enc domain. This was back in R80.30 I believe, but ever since they went to R81 and above, never had the issue.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 18:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permanent-tunnel-question/m-p/207573#M39267</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-01T18:27:35Z</dc:date>
    </item>
  </channel>
</rss>

