<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with VPN &amp;amp; PPPoE: R81.20 - Build 039 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231544#M44649</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I replaced my Check Point SMB 1550 with a Quantum 3600 and I cannot get the tunnel to Harmony SASE working again.&lt;/P&gt;&lt;P&gt;As far as I can debug it, the packet get encrypted but never leave the firewall.&lt;/P&gt;&lt;P&gt;The VPN is up:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;IKE:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Peer 209.35.231.46 , vpn-harmony-sase.ffm SAs:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;  IKEv2 SA 2cae2ad64b836a8f,93a026f7f36c90f7&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;IPsec:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Peer 209.35.231.46 , vpn-harmony-sase.ffm SAs:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;  IKEv2 SA 2cae2ad64b836a8f,93a026f7f36c90f7&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;    INBOUND:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;      1. 0x2a45d4a5  (i: 2)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;    OUTBOUND:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;FONT face="andale mono,times"&gt;      1. 0xc5850354  (i: 2)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see the packets coming in through "fw monitor"&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=48460&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=139&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=48945&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=140&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=49316&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=141&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;But the packets don't make it to the network: "fw ctl zdebug drop shows" me&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;@;6607.255;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=1 10.2.3.2:14 -&amp;gt; 10.0.1.10:0 dropped by vpn_before_offload Reason: failed to get OS route;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;@;6608.256;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=1 10.2.3.2:14 -&amp;gt; 10.0.1.10:0 dropped by vpn_before_offload Reason: failed to get OS route;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;This really weird, because the firewall itself can ping the system:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[Expert@fortress-new:0]# ping 10.0.1.10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;PING 10.0.1.10 (10.0.1.10) 56(84) bytes of data.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;64 bytes from 10.0.1.10: icmp_seq=1 ttl=64 time=1.02 ms&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;The destination network is a bridging interface (br0).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yours, Martin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Nov 2024 17:36:49 GMT</pubDate>
    <dc:creator>Masek</dc:creator>
    <dc:date>2024-11-02T17:36:49Z</dc:date>
    <item>
      <title>Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231544#M44649</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I replaced my Check Point SMB 1550 with a Quantum 3600 and I cannot get the tunnel to Harmony SASE working again.&lt;/P&gt;&lt;P&gt;As far as I can debug it, the packet get encrypted but never leave the firewall.&lt;/P&gt;&lt;P&gt;The VPN is up:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;IKE:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Peer 209.35.231.46 , vpn-harmony-sase.ffm SAs:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;  IKEv2 SA 2cae2ad64b836a8f,93a026f7f36c90f7&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;IPsec:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Peer 209.35.231.46 , vpn-harmony-sase.ffm SAs:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;  IKEv2 SA 2cae2ad64b836a8f,93a026f7f36c90f7&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;    INBOUND:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;      1. 0x2a45d4a5  (i: 2)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;    OUTBOUND:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;FONT face="andale mono,times"&gt;      1. 0xc5850354  (i: 2)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see the packets coming in through "fw monitor"&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=48460&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=139&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=48945&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=140&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[vs_0][fw_1] pppoe7:i[44]: 10.2.3.2 -&amp;gt; 10.0.1.10 (ICMP) len=84 id=49316&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;ICMP: type=8 code=0 echo request id=14 seq=141&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;But the packets don't make it to the network: "fw ctl zdebug drop shows" me&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;@;6607.255;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=1 10.2.3.2:14 -&amp;gt; 10.0.1.10:0 dropped by vpn_before_offload Reason: failed to get OS route;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;@;6608.256;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=1 10.2.3.2:14 -&amp;gt; 10.0.1.10:0 dropped by vpn_before_offload Reason: failed to get OS route;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;This really weird, because the firewall itself can ping the system:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;[Expert@fortress-new:0]# ping 10.0.1.10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;PING 10.0.1.10 (10.0.1.10) 56(84) bytes of data.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;64 bytes from 10.0.1.10: icmp_seq=1 ttl=64 time=1.02 ms&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;The destination network is a bridging interface (br0).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yours, Martin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 17:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231544#M44649</guid>
      <dc:creator>Masek</dc:creator>
      <dc:date>2024-11-02T17:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231558#M44654</link>
      <description>&lt;P&gt;Which JHF (Jumbo) is installed on this system and co&lt;SPAN&gt;uld you please share a simple diagram of the topology?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 10:54:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231558#M44654</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-11-03T10:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231559#M44655</link>
      <description>&lt;P&gt;Installed the latest recommended JHF (89?)&lt;BR /&gt;Had to roll back and disconnect the system&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 10:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231559#M44655</guid>
      <dc:creator>Masek</dc:creator>
      <dc:date>2024-11-03T10:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231568#M44658</link>
      <description>&lt;P&gt;It was Take 89. I am rebuilding the system and try it without a bridging interface&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 17:28:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/231568#M44658</guid>
      <dc:creator>Masek</dc:creator>
      <dc:date>2024-11-03T17:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237685#M46159</link>
      <description>&lt;P&gt;&amp;nbsp;Is there one update about this test&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30412"&gt;@Masek&lt;/a&gt;&amp;nbsp;, i had the same problem in my LAB enverioment.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 13:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237685#M46159</guid>
      <dc:creator>carlos_luz</dc:creator>
      <dc:date>2025-01-06T13:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237731#M46170</link>
      <description>&lt;P&gt;Use migrate_server for backup/restore at the moment...&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 18:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237731#M46170</guid>
      <dc:creator>Masek</dc:creator>
      <dc:date>2025-01-06T18:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237732#M46171</link>
      <description>&lt;P&gt;&amp;nbsp;I had the same problem and after changed the Bridge to Physhical interface the problem stop...&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;But i had this in one LAB enverioment, but i think there is necessary open one Case.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 18:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/237732#M46171</guid>
      <dc:creator>carlos_luz</dc:creator>
      <dc:date>2025-01-06T18:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN &amp; PPPoE: R81.20 - Build 039</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/242261#M47052</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Did you find a solution to the problem?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Nigel&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 11:31:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-VPN-amp-PPPoE-R81-20-Build-039/m-p/242261#M47052</guid>
      <dc:creator>Nigel_Todd</dc:creator>
      <dc:date>2025-02-25T11:31:05Z</dc:date>
    </item>
  </channel>
</rss>

