<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/230291#M44319</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107414"&gt;@checkpopipu&lt;/a&gt;&amp;nbsp; Did you find the solution on this?&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2024 14:17:12 GMT</pubDate>
    <dc:creator>SdanteMate</dc:creator>
    <dc:date>2024-10-21T14:17:12Z</dc:date>
    <item>
      <title>S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206728#M39039</link>
      <description>&lt;P&gt;Hey there!&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;TL;DR: IPSEC VPN problem - My Checkpoint device cant communicate with the Interoperable device (that is actually the AWS side of the tunnel) at all! the error is&amp;nbsp;"IKE failure: Initial exchange: Exchange failed: timeout reached"&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;The problem:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;I'm trying to connect my On-Premise and my AWS environment with a S2S VPN.&lt;/P&gt;&lt;P&gt;I have configured everything on AWS and then got a configuration tutorial document for my checkpoint.&lt;/P&gt;&lt;P&gt;I did everything, and got to the part when I have to test my connection, but it is not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;What I have already tried:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;In the logs I can see once in a minute a record with action "REJECT" and description&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;IKE failure: Initial exchange: Exchange failed: timeout reached". After that, there is another record with action "Encrypt", but then it stops. (Images of this are included at the end)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I tried to sniff all interfaces and understood that there is not even one packet that is sent to the Public IP that is defined in the interoperable device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also tried to ping this address and saw that I cannot talk to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to change the IP address of the interoperable device and it was preventing me to send anything to the new IP.&lt;/P&gt;&lt;P&gt;I have a rule that allows my firewall to communicate with that address in any type of communication so that's not the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a Lot!!!!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 17:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206728#M39039</guid>
      <dc:creator>checkpopipu</dc:creator>
      <dc:date>2024-02-21T17:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206937#M39099</link>
      <description>&lt;P&gt;I think you need to perform a vpn debug to get more info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 22:47:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206937#M39099</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-02-22T22:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206943#M39103</link>
      <description>&lt;P&gt;I would do simple vpn debug as well.&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic, wait 2-3 mins&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;Get ike and vpnd files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/206943#M39103</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T01:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/230291#M44319</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107414"&gt;@checkpopipu&lt;/a&gt;&amp;nbsp; Did you find the solution on this?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 14:17:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/230291#M44319</guid>
      <dc:creator>SdanteMate</dc:creator>
      <dc:date>2024-10-21T14:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233773#M45257</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9221"&gt;@SdanteMate&lt;/a&gt;&amp;nbsp; Have you been able to resolve the issue? Currently running into the same error. We have other tunnels to AWS that work just fine but can't get this one to work&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:01:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233773#M45257</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2024-11-26T08:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233789#M45261</link>
      <description>&lt;P&gt;In case anyone runs into the same issue and finds this post. The solution for us was to change the "Startup Action" Setting in AWS from Add to Start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Startup action&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The action to take when establishing the tunnel for a VPN connection. You can specify the following:&lt;/P&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;P&gt;Start: AWS initiates the IKE negotiation to bring the tunnel up. Only supported if your customer gateway is configured with an IP address.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Add: Your customer gateway device must initiate the IKE negotiation to bring the tunnel up.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 09:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233789#M45261</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2024-11-26T09:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233797#M45263</link>
      <description>&lt;P&gt;Thats really good to know, tx for sharing!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 11:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN/m-p/233797#M45263</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-26T11:47:25Z</dc:date>
    </item>
  </channel>
</rss>

