<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site Tunnel multi-SAs crash in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230577#M44362</link>
    <description>&lt;P&gt;Looking at the debug, it is failing on "Create Child SA". This appears to be a larger tunnel with 16 IKE SA's from your screenshot.&lt;/P&gt;
&lt;P&gt;What does your encryption domain look like, are these all subnets? How often are you re-keying Phase2? What version are you running on?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2024 12:37:21 GMT</pubDate>
    <dc:creator>CaseyB</dc:creator>
    <dc:date>2024-10-23T12:37:21Z</dc:date>
    <item>
      <title>Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230574#M44360</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am facing a problem with PFsence site to site VPN. The config. matched on both sides. same everything and the encyption domains.&amp;nbsp;&lt;BR /&gt;Although the problem, the S2S VPN will work but after a while it stops. The only way to make work again is by resting the VPN then it works again.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I tried to debug the issue found some weird things.&amp;nbsp; Like many SAs peer connection and it keeps adding till the connection stops.&amp;nbsp;&lt;BR /&gt;After reset start all again. also the IPSEC phase 2 many inbounds and outbounds .&amp;nbsp; Any ideas what to check or where to start ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-10-23 14_25_20-lagadpsec01.png" style="width: 496px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28178i2C7ED4F7DC994A00/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-10-23 14_25_20-lagadpsec01.png" alt="2024-10-23 14_25_20-lagadpsec01.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-10-23 14_26sec01.png" style="width: 535px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28179i8DC8B67B3AE9765C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-10-23 14_26sec01.png" alt="2024-10-23 14_26sec01.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-10-psec01.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28180iA70FA9780A4B654F/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-10-psec01.png" alt="2024-10-psec01.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:28:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230574#M44360</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-23T12:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230577#M44362</link>
      <description>&lt;P&gt;Looking at the debug, it is failing on "Create Child SA". This appears to be a larger tunnel with 16 IKE SA's from your screenshot.&lt;/P&gt;
&lt;P&gt;What does your encryption domain look like, are these all subnets? How often are you re-keying Phase2? What version are you running on?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230577#M44362</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-10-23T12:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230637#M44383</link>
      <description>&lt;P&gt;Under the VPN community you have SA per host, per subnet or per gateway?&lt;/P&gt;
&lt;P&gt;What version you running? share cpinfo -y all output from relevant vpn gateway&lt;/P&gt;
&lt;P&gt;How often tunnel breaks? Does this match either the p1 or p2 timer?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 21:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230637#M44383</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-10-23T21:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230650#M44384</link>
      <description>&lt;P&gt;No ipsec sa clearly tells us its phase 2 issue. How do you have tunnel management seclected? per host, subnet or gateway? If you arew only using subnets, then subnet should be selected, but if its combo of both hosts/subnets, then select per gateway.&lt;/P&gt;
&lt;P&gt;Also, do vpn domains match properly on both ends?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 01:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230650#M44384</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-24T01:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230661#M44386</link>
      <description>&lt;P&gt;The encryption domain has multi subnet, Client VPN net and some pcs.&lt;BR /&gt;Renegotiate phase 2 : 3600 Sec.&amp;nbsp;&lt;BR /&gt;FW :&amp;nbsp;R81.10 - Build 062 Take&amp;nbsp;139&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 498px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28196i0B907D6BD1F5BC90/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 597px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28197iE39C672F5B63485F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 06:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230661#M44386</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-24T06:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230663#M44387</link>
      <description>&lt;P&gt;It is per Subnet,&amp;nbsp;&lt;BR /&gt;Ver :&amp;nbsp;&lt;SPAN&gt;FW :&amp;nbsp;R81.10 - Build 062 Take&amp;nbsp;139.&amp;nbsp;&lt;BR /&gt;I had to restart it every day cuz it works for a couple of hours then it does not work till i reset the VPN&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 512px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28198i24DB93FE094F9C1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 06:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230663#M44387</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-24T06:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230665#M44389</link>
      <description>&lt;P&gt;it's actually per Subnet. It not the first time i add hosts and subnets to ED with VPN Sharing per subnet. It always worked fine. I dont know also if this is an issue on the other side the Pfsense. Although it is worth to try .&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 07:08:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230665#M44389</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-24T07:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230708#M44413</link>
      <description>&lt;P&gt;You don't need those hosts in the encryption domain, the&amp;nbsp;10.148.8.0/22 encompasses them, I would remove them.&lt;/P&gt;
&lt;P&gt;Your screenshot shows 16 SA's, based on the encryption domain you provided, I would only expect 8 after removing the hosts and 12 before, that makes it seem like the tunnels are not building properly.&lt;/P&gt;
&lt;P&gt;I would do a "vpn tu tlist -p &amp;lt;IP of PFsense&amp;gt;" from the GW CLI to validate all of the subnets are building properly, because that seems like the culprit.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 12:42:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230708#M44413</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-10-24T12:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230710#M44414</link>
      <description>&lt;P&gt;actually it does not matter what we do it will keep adding SA's till i have to reset the VPN to make it work again. I see by other VPNs only one SA's although the ED has many networks. I dont know how relevant&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 715px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28200i86827174E16CB1EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt; is that..&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 12:55:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230710#M44414</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-24T12:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230711#M44415</link>
      <description>&lt;P&gt;To me, it looks like the subnets are not defined properly on the PFsense side.&lt;/P&gt;
&lt;P&gt;Looking back at the debug you posted, the failed "Created Child SA" is an inbound request, as in the PFsense is sending a subnet the Check Point does not like. You should be able to see those in the "TSi" and "TSr" fields.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 13:10:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230711#M44415</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-10-24T13:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230713#M44417</link>
      <description>&lt;P&gt;Well, if it worked before, maybe you just got lucky, but technically, if its combo of hosts/subnets, it should be set per gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 13:12:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/230713#M44417</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-24T13:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/231016#M44493</link>
      <description>&lt;P&gt;Now it looks different :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 927px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28230i725EC17643139CAD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 15:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/231016#M44493</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-10-28T15:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site Tunnel multi-SAs crash</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/231042#M44502</link>
      <description>&lt;P&gt;Check what Casey typed before, you have to check further into the debugs:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Looking back at the debug you posted, the failed "Created Child SA" is an inbound request, as in the PFsense is sending a subnet the Check Point does not like. You should be able to see those in the "TSi" and "TSr" fields."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also regarding software, search here for '"VPN' and check if any bugs match. You should check everything above take 139.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 21:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-Tunnel-multi-SAs-crash/m-p/231042#M44502</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-10-28T21:22:59Z</dc:date>
    </item>
  </channel>
</rss>

