<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT-T through VPN tunnel in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216543#M41264</link>
    <description>&lt;P&gt;The broken tunnel is VMWARE HCX on both ends. This was working fine for weeks. We rebooted the checkpoint gateways and it stopped working. I beleieve the HCX tunnel was reset, but that is managed by a different team. We just built a new HCX mesh over the same checkpoint tunnel as the broken one, and it seems to be working. The strange thing is the checkpoint is definitely dropping traffic for the broken mesh, and passing traffic for the working mesh. Maybe something in the packet is messed up.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 14:16:12 GMT</pubDate>
    <dc:creator>Scott_Paisley</dc:creator>
    <dc:date>2024-06-05T14:16:12Z</dc:date>
    <item>
      <title>NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216515#M41257</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We have a site-to-site checkpoint VPN&lt;/P&gt;
&lt;P&gt;We are using VMWARE HCX to migrate some workloads through that tunnel. HCX uses NAT-T to build a VPN tunnel using whatever transport is available, which in this case happens to be a checkpoint VPN tunnel, so we are tunneling NAT-T through a checkpoint VPN tunnel.&lt;/P&gt;
&lt;P&gt;This has been working for months.&lt;/P&gt;
&lt;P&gt;On Friday it broke after we installed the CVE patch and rebooted all the gateways.&lt;/P&gt;
&lt;P&gt;Here is the log message "Failure preparing tunnel creation, internal error"&lt;/P&gt;
&lt;P&gt;We opened a ticket with TAC on Friday and spoke to an engineer who said they had seen this once before, but it was fixed by an unrelated hotfix.&lt;/P&gt;
&lt;P&gt;On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"&lt;/P&gt;
&lt;P&gt;I don't believe this to be true.&lt;/P&gt;
&lt;P&gt;Is anybody else running HCX over a checkpoint VPN (or any other NAT-T traffic)?&lt;/P&gt;
&lt;P&gt;Anybody else seen this error and know the fix?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 13:05:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216515#M41257</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-06-05T13:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216517#M41258</link>
      <description>&lt;P&gt;&lt;SPAN&gt;On a call today with a different engineer, they said "NAT-T through a Checkpoint VPN tunnel is not supported"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I agree with you, Im 100% positive that is NOT true.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is it failing on phase 1 or 2?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 13:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216517#M41258</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T13:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216519#M41259</link>
      <description>&lt;P&gt;the checkpoint is dropping the packets so it never gets as far as phase 1&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 13:19:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216519#M41259</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-06-05T13:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216522#M41260</link>
      <description>&lt;P&gt;Maybe this?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk170141" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk170141&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 13:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216522#M41260</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216525#M41261</link>
      <description>&lt;P&gt;we have looked at that, but in this case default route is the route that should be used&lt;/P&gt;
&lt;P&gt;we have just tried a different tunnel to a different site and it seems to be working so I guess it is supported after all&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 13:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216525#M41261</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-06-05T13:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216540#M41263</link>
      <description>&lt;P&gt;100% supported, it always has been. Btw, just wondering...does it make any difference if tunnel is reset from both ends? Whats the other side?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216540#M41263</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T14:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216543#M41264</link>
      <description>&lt;P&gt;The broken tunnel is VMWARE HCX on both ends. This was working fine for weeks. We rebooted the checkpoint gateways and it stopped working. I beleieve the HCX tunnel was reset, but that is managed by a different team. We just built a new HCX mesh over the same checkpoint tunnel as the broken one, and it seems to be working. The strange thing is the checkpoint is definitely dropping traffic for the broken mesh, and passing traffic for the working mesh. Maybe something in the packet is messed up.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216543#M41264</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-06-05T14:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216548#M41265</link>
      <description>&lt;P&gt;Can you do basic VPN debug and attach iked and vpnd files?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;look for iked and vpnd files in $FWDIR/log dir&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216548#M41265</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T14:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216551#M41266</link>
      <description>&lt;P&gt;the checkpoint tunnels are up and always have been. we don't have any diagnostics from HCX. Anyway, it now seems it does work, apart from the original mesh.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:31:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216551#M41266</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-06-05T14:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: NAT-T through VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216554#M41267</link>
      <description>&lt;P&gt;I would say if it can be reset from that side, it may help.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-T-through-VPN-tunnel/m-p/216554#M41267</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T14:34:47Z</dc:date>
    </item>
  </channel>
</rss>

