<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: could someone advice me how to determine the value for &amp;quot;ipsec.replay_counter_window_size&amp;qu in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/228918#M44095</link>
    <description>&lt;P&gt;Response from TAC:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartConsole to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.).&lt;/P&gt;&lt;P&gt;Verify by running the "&lt;EM&gt;cpstat mg&lt;/EM&gt;" command on Security Management Server / in the context of&amp;nbsp;&lt;EM&gt;each&lt;/EM&gt;&amp;nbsp;Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk13009" target="_blank" rel="noopener"&gt;GuiDBedit Tool&lt;/A&gt;&amp;nbsp;to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper left pane, go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;-&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Network Objects&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;-&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;network_objects&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper right pane, select the relevant Security Gateway / Cluster object.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Press CTRL+F (or go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Search&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;menu -&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Find&lt;/STRONG&gt;&lt;/EM&gt;) - paste&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;ipsec.replay_counter_window_size&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Find Next&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the lower pane, right-click on the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;ipsec.replay_counter_window_size&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- select&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Edit...&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- delete the default value of 64 - enter the relevant value - click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Save the changes: go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;File&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;menu - click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Save All&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close the GuiDBedit Tool.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartConsole to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Install the policy onto the relevant Security Gateway / Cluster object.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Keep in mind that the default value is 64, and there is no desired value - you will need to lower or higher it until it reaches the correct value where this issue does not re-appear.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2024 07:57:09 GMT</pubDate>
    <dc:creator>isazonov</dc:creator>
    <dc:date>2024-10-04T07:57:09Z</dc:date>
    <item>
      <title>could someone advice me how to determine the value for "ipsec.replay_counter_window_size"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122345#M17513</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;could someone direct me how I can adjust the setting to avoid VPN Tunnel termination due to "possible replay attack".&lt;BR /&gt;&lt;BR /&gt;I do have the issue described in sk94984. The issue exists only for one Tunnel. The issue is gone when I disable the replay check. Now I wanted to turn it back on and adjust the window size. In the SK they only say to adjust it to the relevant value.&lt;/P&gt;&lt;P&gt;In the logs I do have the message:&lt;/P&gt;&lt;P&gt;Warning: possible replay attack. Sequence Number 1490945 (Expected 1491179)&lt;/P&gt;&lt;P&gt;Currently I used 1200 as window size but the tunnel is still being terminated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I determine / calculate the value? Seem that it isn’t just 1491179-1490945&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;R80.40 T94&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122345#M17513</guid>
      <dc:creator>Florian_Schneid</dc:creator>
      <dc:date>2021-06-28T10:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: could someone advice me how to determine the value for "ipsec.replay_counter_window_size&amp;qu</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122355#M17514</link>
      <description>&lt;P&gt;Better use the information found in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk94984&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk94984: VPN traffic is dropped with "Encryption failure: Warning: possible replay attack" log&lt;/A&gt;&amp;nbsp;and involve TAC if this does not help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 12:51:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122355#M17514</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-06-28T12:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: could someone advice me how to determine the value for "ipsec.replay_counter_window_size&amp;qu</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122357#M17515</link>
      <description>&lt;P&gt;Hi Günter,&lt;BR /&gt;&lt;BR /&gt;as mentioned above I followed the SK94984. But i didn't want to have the reply check disabled in general. So i decided to do the route descibed in the additional part of the SK and adjust the window size. I did adjust it to 1200 the log shows it triggered even it was only 234 as from the logs.&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Florian&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 12:59:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122357#M17515</guid>
      <dc:creator>Florian_Schneid</dc:creator>
      <dc:date>2021-06-28T12:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: could someone advice me how to determine the value for "ipsec.replay_counter_window_size&amp;qu</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122364#M17516</link>
      <description>&lt;P&gt;So i would suggest to involve TAC !&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 13:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122364#M17516</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-06-28T13:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: could someone advice me how to determine the value for "ipsec.replay_counter_window_size&amp;qu</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/228918#M44095</link>
      <description>&lt;P&gt;Response from TAC:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartConsole to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.).&lt;/P&gt;&lt;P&gt;Verify by running the "&lt;EM&gt;cpstat mg&lt;/EM&gt;" command on Security Management Server / in the context of&amp;nbsp;&lt;EM&gt;each&lt;/EM&gt;&amp;nbsp;Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk13009" target="_blank" rel="noopener"&gt;GuiDBedit Tool&lt;/A&gt;&amp;nbsp;to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper left pane, go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;-&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Network Objects&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;-&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;network_objects&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper right pane, select the relevant Security Gateway / Cluster object.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Press CTRL+F (or go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Search&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;menu -&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Find&lt;/STRONG&gt;&lt;/EM&gt;) - paste&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;ipsec.replay_counter_window_size&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Find Next&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the lower pane, right-click on the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;ipsec.replay_counter_window_size&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- select&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Edit...&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;- delete the default value of 64 - enter the relevant value - click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Save the changes: go to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;File&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;menu - click on&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Save All&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close the GuiDBedit Tool.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartConsole to the Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Install the policy onto the relevant Security Gateway / Cluster object.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Keep in mind that the default value is 64, and there is no desired value - you will need to lower or higher it until it reaches the correct value where this issue does not re-appear.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 07:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/228918#M44095</guid>
      <dc:creator>isazonov</dc:creator>
      <dc:date>2024-10-04T07:57:09Z</dc:date>
    </item>
  </channel>
</rss>

