<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220228#M42131</link>
    <description>&lt;P&gt;&lt;SPAN&gt;what LSM Gateways do you use and what Version are they running on? : 1100 &amp;amp; 1430 Appliance and which are running on&amp;nbsp;R77.20.87 (990173004).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there a Log Entry from an LSM GW? :No&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 13:00:34 GMT</pubDate>
    <dc:creator>Anandsekar</dc:creator>
    <dc:date>2024-07-10T13:00:34Z</dc:date>
    <item>
      <title>Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220006#M42090</link>
      <description>&lt;P&gt;Ipsec tunnel down phase 2 after upgrading to r81.20 take 41 and ipsec tunnel is unstable&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220006#M42090</guid>
      <dc:creator>Anandsekar</dc:creator>
      <dc:date>2024-07-08T19:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220022#M42095</link>
      <description>&lt;P&gt;More info?&lt;/P&gt;
&lt;P&gt;- what verion you came from&lt;/P&gt;
&lt;P&gt;- what you see in logs&lt;/P&gt;
&lt;P&gt;- cp to cp or cp to vendor&lt;/P&gt;
&lt;P&gt;- both sides unstable&lt;/P&gt;
&lt;P&gt;- global encryption domain or per community&lt;/P&gt;
&lt;P&gt;etc&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 21:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220022#M42095</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-08T21:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220096#M42110</link>
      <description>&lt;P&gt;&lt;SPAN&gt;- what verion you came from -- R81.10 JHF Take 79 to R81.20 Take 41&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- what you see in logs -&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkmate.PNG" style="width: 800px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26664i35B47555C24136FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Checkmate.PNG" alt="Checkmate.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- cp to cp or cp to vendor -- Checkpoint to checkpoint LSM security gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- both sides unstable - yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- global encryption domain or per community - on all tunnel in the community&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 12:34:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220096#M42110</guid>
      <dc:creator>Anandsekar</dc:creator>
      <dc:date>2024-07-09T12:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220132#M42117</link>
      <description>&lt;P&gt;- what verion you came from : - R81.10 Take 79 to R81.20 Take 41&lt;/P&gt;&lt;P&gt;- what you see in logs : -&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkmate.PNG" style="width: 800px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26674i993A128D3282A5C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Checkmate.PNG" alt="Checkmate.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- cp to cp or cp to vendor : CP to CP those are LSM security&amp;nbsp; gateways management by smart provisioning&lt;/P&gt;&lt;P&gt;- both sides unstable : yes&lt;/P&gt;&lt;P&gt;- global encryption domain or per community : -&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkmate2.PNG" style="width: 473px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26675i9C9E822A269FB222/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkmate2.PNG" alt="checkmate2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 17:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220132#M42117</guid>
      <dc:creator>Anandsekar</dc:creator>
      <dc:date>2024-07-09T17:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220151#M42121</link>
      <description>&lt;P&gt;Hmmm unclear error. Maybe VPN debug could give more info.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180488" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180488&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In the mean time maybe you can check the basics. This will be as I assume certificate based tunnel.&lt;/P&gt;
&lt;P&gt;So maybe check if the CRL check is working:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108632" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108632&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32648" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32648&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also check if the VPN certificates are still valid:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk178304" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk178304&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This is not a Gaia embedded gateway right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 20:20:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220151#M42121</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-09T20:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220200#M42129</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;what LSM Gateways do you use and what Version are they running on?&lt;BR /&gt;&lt;BR /&gt;Is there a Log Entry from an LSM GW?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 10:02:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220200#M42129</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-07-10T10:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220228#M42131</link>
      <description>&lt;P&gt;&lt;SPAN&gt;what LSM Gateways do you use and what Version are they running on? : 1100 &amp;amp; 1430 Appliance and which are running on&amp;nbsp;R77.20.87 (990173004).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there a Log Entry from an LSM GW? :No&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 13:00:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220228#M42131</guid>
      <dc:creator>Anandsekar</dc:creator>
      <dc:date>2024-07-10T13:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec tunnel down phase 2 after upgrading to r81.20 take 41</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220243#M42138</link>
      <description>&lt;P&gt;Ike failure usually means phase 1 is down, not phase 2. Can you run vpn tu and check what it shows when you filter for that specific tunnel?&lt;/P&gt;
&lt;P&gt;Or try below options.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn tu list ike&lt;BR /&gt;vpn tu list ipsec&lt;BR /&gt;vpn tu list peer_ike ip-addr&lt;BR /&gt;vpn tu list peer_ipsec ip-addr&lt;BR /&gt;vpn tu list tunnels&lt;BR /&gt;vpn tu tlist&lt;BR /&gt;vpn tu mstats&lt;BR /&gt;vpn tu del ipsec all&lt;BR /&gt;vpn tu del ipsec ip-addr&lt;BR /&gt;vpn tu del ipsec ip-addr username&lt;BR /&gt;vpn tu del ipsec ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu del all&lt;BR /&gt;vpn tu del ip-addr&lt;BR /&gt;vpn tu del ip-addr username&lt;BR /&gt;vpn tu del ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu conn&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 13:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ipsec-tunnel-down-phase-2-after-upgrading-to-r81-20-take-41/m-p/220243#M42138</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-10T13:47:43Z</dc:date>
    </item>
  </channel>
</rss>

