<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to connect to remote server through site to site vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222988#M42755</link>
    <description>&lt;P&gt;Thank you for your response. I did run the capture on destination firewall. I can see the SYN packet coming from the remote site. However, I do not see that packet being sent to the actual server. In the logs, I do not see a drop either. That is what is puzzling. I checked connection from the firewall to backend server using telnet &amp;lt;IP&amp;gt; &amp;lt;port&amp;gt; and that works fine.&lt;BR /&gt;In the interest of time, I am checking if I can get the route-based VPN (DMVPN) working. Will post here once I test.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2024 00:15:33 GMT</pubDate>
    <dc:creator>gouri-menon</dc:creator>
    <dc:date>2024-08-08T00:15:33Z</dc:date>
    <item>
      <title>Unable to connect to remote server through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222792#M42711</link>
      <description>&lt;P&gt;Hi team. I am trying to setup a site-to-site VPN across 2 tenants in Azure. The product I am using in both location is "CloudGuard Network Security Firewall &amp;amp; Threat Prevention" from Azure marketplace. I did setup the VPN in mesh topology with local &amp;amp; remote "interoperable" device along with the shared key. I am doing this to simulate not having access to the remote checkpoint. I then setup the policy rule &amp;amp; NAT rule to flow over the VPN community.&lt;/P&gt;&lt;P&gt;I then tried connecting from a windows server on side to a NGINX server on the other side of the tunnel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; -&amp;nbsp; 172.16.102.213 (WIN) ==&amp;gt; GW01 ==&amp;gt; VPN Tunnel ==&amp;gt; GW02 ==&amp;gt; 10.0.0.100 (NGINX)&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;In the logs (using smartview) I can see the session which uses VPN blade + encrypt on the source gateway &amp;amp; VPN blade + decrypt on the destination gateway along with the service (http or https). I have even tried the other way for port 3389 &amp;amp; here too I can see it go through the tunnel &amp;amp; arrive at the remote site. In both cases however, the packet is not flowing from the gateway to the destination machine.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;# vpn tu&lt;/DIV&gt;&lt;DIV class=""&gt;Option-1&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;Peer xxx.xxx.xxx.xxx , gw-01 SAs:&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;0aa90a313c5066a6,69958fa937977e7d&amp;gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Option-2&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;SAs of all instances:&lt;/P&gt;&lt;P&gt;Peer xxx.xxx.xxx.xxx , gw-01 SAs:&lt;/P&gt;&lt;P&gt;IKE SA &amp;lt;0aa90a313c5066a6,69958fa937977e7d&amp;gt;&lt;BR /&gt;(No IPSec SAs)&lt;/P&gt;&lt;P&gt;Similarly, it shows the tunnel up on the other gateway.&amp;nbsp;Am I missing a step or doing something wrong ? Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Aug 2024 01:15:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222792#M42711</guid>
      <dc:creator>gouri-menon</dc:creator>
      <dc:date>2024-08-06T01:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote server through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222975#M42748</link>
      <description>&lt;P&gt;If you think the problem is not the vpn tunnel I would do ip r get IP and use that interface output to tcpdump to see what happens to the traffic. Could be routing or acl on system itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 19:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222975#M42748</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-07T19:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote server through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222988#M42755</link>
      <description>&lt;P&gt;Thank you for your response. I did run the capture on destination firewall. I can see the SYN packet coming from the remote site. However, I do not see that packet being sent to the actual server. In the logs, I do not see a drop either. That is what is puzzling. I checked connection from the firewall to backend server using telnet &amp;lt;IP&amp;gt; &amp;lt;port&amp;gt; and that works fine.&lt;BR /&gt;In the interest of time, I am checking if I can get the route-based VPN (DMVPN) working. Will post here once I test.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 00:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-connect-to-remote-server-through-site-to-site-vpn/m-p/222988#M42755</guid>
      <dc:creator>gouri-menon</dc:creator>
      <dc:date>2024-08-08T00:15:33Z</dc:date>
    </item>
  </channel>
</rss>

