<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212355#M40306</link>
    <description>&lt;P&gt;Interesting. I configured masses of VPN tunnels at FortiGate devices and never heard that wording &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2024 05:01:21 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2024-04-26T05:01:21Z</dc:date>
    <item>
      <title>Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212254#M40274</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Good morning everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am setting up IPsec over the Public Internet with many partners around the world.&amp;nbsp;One of my partners uses a Cisco ASA, and there was a problem with that.&amp;nbsp;CheckPoint send traffic selector 0.0.0.0.&amp;nbsp;Cisco rejects the request and IPsec does not up. Has anyone encountered such a problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use CheckPoint 1800 on cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 08:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212254#M40274</guid>
      <dc:creator>stelsyas</dc:creator>
      <dc:date>2024-04-25T08:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212285#M40281</link>
      <description>&lt;P&gt;Sounds like both ends disagree on what the encryption domain is and/or you've configured your end to establish a single tunnel for all traffic (0.0.0.0) and the other end isn't configured to accept this.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:11:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212285#M40281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-25T14:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212291#M40284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;PhoneBoy!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need configure connection between local network 185.xx.xx.xx/29 (my CP) and 91.xx.xx.xx/30 (Cisco).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added network 185.xx.xx.xx/29 to VPN-&amp;gt;Site to Site -&amp;gt; Advanced -&amp;gt; Local ecryption domain is defined manualy...&amp;nbsp;&lt;/P&gt;&lt;P&gt;But CheckPoint on Phase 2 sending traffic selector 0.0.0.0/0. Another firewall (PfSense, Strongswan, Huawei)&amp;nbsp;normal to accept it.&amp;nbsp;The problem is only with Cisco ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212291#M40284</guid>
      <dc:creator>stelsyas</dc:creator>
      <dc:date>2024-04-25T14:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212294#M40286</link>
      <description>&lt;P&gt;Can you show how you configured your VPN domain on CP side? The issue is, CP only sends 0.0.0.0/0 if the VPN domain is empty.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:27:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212294#M40286</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-25T14:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212297#M40288</link>
      <description>&lt;P&gt;In case you configured the domain to select it's proxy id per pair of gateways, it surely sends 0.0.0.0/0 what is expected behavior.&lt;BR /&gt;On the ASA side there should be something like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crypto map outside_map 10 match address VPN-Traffic
crypto map outside_map 10 set peer &amp;lt;Peer_IP_Address&amp;gt;

! Define the ACL for interesting traffic
access-list VPN-Traffic extended permit ip any4 any4&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how i configured that long time ago&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212297#M40288</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-25T14:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212300#M40289</link>
      <description>&lt;P&gt;And i thought, it's defined in the tunnel management.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp-tunnel-management.png" style="width: 421px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25398i93AB84501A3F0FE8/image-dimensions/421x316?v=v2" width="421" height="316" role="button" title="cp-tunnel-management.png" alt="cp-tunnel-management.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212300#M40289</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-25T14:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212303#M40290</link>
      <description>&lt;P&gt;Config on screens:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25400iB8DC742F87D4F8DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25399i58AB489DEFD0FC5A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:40:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212303#M40290</guid>
      <dc:creator>stelsyas</dc:creator>
      <dc:date>2024-04-25T14:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212304#M40291</link>
      <description>&lt;P&gt;IPSec is up if configure the following on the Cisco:&lt;BR /&gt;&amp;gt;&amp;gt;access-list VPN-Traffic extended permit ip any4 any4&lt;/P&gt;&lt;P&gt;But in this case, all traffic will be sent via IPSec.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212304#M40291</guid>
      <dc:creator>stelsyas</dc:creator>
      <dc:date>2024-04-25T14:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212311#M40292</link>
      <description>&lt;P&gt;Just configure it as permanent tunnel using VTIs and set option&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16383"&gt;@Vincent_Bacher&lt;/a&gt;&amp;nbsp;advised in the community. I had done this many times and works without any issues. If you need help, just ping me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212311#M40292</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-25T15:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212344#M40302</link>
      <description>&lt;P&gt;Just to clarify the "one tunnel per gateway pair" is sometimes called "double quad zeroes" or a "universal tunnel" by some vendors if it helps locate their proper documentation for this setup.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 21:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212344#M40302</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-25T21:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212345#M40303</link>
      <description>&lt;P&gt;Super valid point...I know Fortinet calls it that all the time, not sure about Cisco, but its probably the same thing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 21:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212345#M40303</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-25T21:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212355#M40306</link>
      <description>&lt;P&gt;Interesting. I configured masses of VPN tunnels at FortiGate devices and never heard that wording &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 05:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212355#M40306</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-26T05:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic selector 0.0.0.0/0 in IPSec with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212372#M40310</link>
      <description>&lt;P&gt;Now you have &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 11:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-selector-0-0-0-0-0-in-IPSec-with-CISCO-ASA/m-p/212372#M40310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-26T11:26:08Z</dc:date>
    </item>
  </channel>
</rss>

