<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231633#M44671</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This morning, the site-to-site VPN started working again. I didn’t change anything in the configuration, and the investigation conducted (thank you for your useful information) confirms that the issue was not attributable to Check Point or Cisco Meraki but likely 'in the middle' (that is, within the Internet connectivity).&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Nov 2024 13:05:06 GMT</pubDate>
    <dc:creator>cyberluke365</dc:creator>
    <dc:date>2024-11-04T13:05:06Z</dc:date>
    <item>
      <title>Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231238#M44546</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a site-to-site VPN between Check Point R81.20&amp;nbsp;&lt;SPAN&gt;Take 53 and Cisco Meraki.&amp;nbsp;It is a policy-based VPN (IKEv1).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let's consider this rudimental schema:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="S2S Check Point and Cisco Meraki.drawio.png" style="width: 687px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28266i3E6DB455A966F3A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="S2S Check Point and Cisco Meraki.drawio.png" alt="S2S Check Point and Cisco Meraki.drawio.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1. If I ping the PC (192.168.1.1) from Cisco Meraki (ETH1 192.168.2.254), (by using tcpdump on Check Point) I can see the traffic reaching the Check Point; the PC responds, but I don’t see these replies on Cisco Meraki.&lt;/P&gt;&lt;P&gt;2. If I ping Cisco Meraki (ETH1 192.168.2.254) from the PC (192.168.1.1), I see in the Smart Log that the traffic is encrypted, but, again, it doesn’t reach Cisco Meraki.&lt;/P&gt;&lt;P&gt;Any thought ?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:56:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231238#M44546</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-10-30T09:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231294#M44569</link>
      <description>&lt;P&gt;What does &lt;A href="https://support.checkpoint.com/results/sk/sk30583" target="_self"&gt;fw monitor&lt;/A&gt; say?&lt;BR /&gt;Note that fw monitor will show the traffic as it is encrypted/decrypted (though the source/destination IP will change to the tunnel endpoints).&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 21:11:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231294#M44569</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-30T21:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231310#M44580</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I made two tests while running&amp;nbsp;fw monitor -F "192.168.1.1,0,192.168.2.254,0,0" -F "192.168.2.254,0,192.168.1.1,0,0".&lt;/P&gt;&lt;P&gt;1. PING 192.168.2.254 (from PC1 - 192.168.1.1)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[vs_0][ppak_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62652
ICMP: type=8 code=0 echo request id=1 seq=814
[vs_0][fw_3] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62652
ICMP: type=8 code=0 echo request id=1 seq=814
[vs_0][fw_3] bond1:I[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62652
ICMP: type=8 code=0 echo request id=1 seq=814
[vs_0][fw_3] bond1.9:o[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62652
ICMP: type=8 code=0 echo request id=1 seq=814&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ICMP packets never reach Cisco Meraki.&lt;/P&gt;&lt;P&gt;2. PING PC1 - 192.168.1.1 (from 192.168.2.254)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[vs_0][ppak_0] bond1.9:iD[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][ppak_0] bond1.9:i[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][fw_0] bond1.9:i[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][fw_0] bond1.9:I[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][fw_0] bond1:o[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][fw_0] bond1:O[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10670 seq=0
[vs_0][ppak_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0
[vs_0][fw_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0
[vs_0][fw_0] bond1:I[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0
[vs_0][fw_0] bond1.9:o[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0
[vs_0][fw_0] bond1.9:O[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0
[vs_0][fw_0] bond1.9:Oe[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62732
ICMP: type=0 code=0 echo reply id=10670 seq=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ICMP packets reach PC1, but replies never come back Cisco Meraki.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 23:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231310#M44580</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-10-30T23:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231372#M44593</link>
      <description>&lt;P&gt;So, just for the context, in fw monitor, though Im sure you may know this, but in case you did not...D means decrypted and E means encrypted, but if you say packet never comes back, did you do basic zdebug on CP to see if anything possibly gets dropped?&lt;/P&gt;
&lt;P&gt;What do logs show on Meraki end?&lt;/P&gt;
&lt;P&gt;On a side note, is this domain or route based? How are enc domains configured? I ask, because IF you have combination of hosts/subnet, then you can set tunnel mgmt tab inside vpn community in smart console as "per gateway". Happy to do remote and assist, if you are allowed to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 14:20:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231372#M44593</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-31T14:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231470#M44611</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;SPAN&gt;thank you for your useful information. Well, I'll provide more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; Let's start with fw monitor. This is the complete trace for 1 ICMP packet - PING from PC to Cisco Meraki&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[vs_0][ppak_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][fw_1] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][fw_1] bond1:I[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][fw_1] bond1.9:o[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][fw_1] bond1.9:O[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][fw_0] bond1.9:Oe[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872
[vs_0][ppak_0] bond1.9:Oe[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=60 id=62769
ICMP: type=8 code=0 echo request id=1 seq=872&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; This is the complete trace for 1 ICMP packet -&amp;nbsp;PING from Cisco Meraki to Check Point&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.A.&lt;/STRONG&gt; It arrives to Check Point:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[vs_0][ppak_0] bond1.9:iD[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0
[vs_0][ppak_0] bond1.9:i[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0
[vs_0][fw_0] bond1.9:i[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0
[vs_0][fw_0] bond1.9:I[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0
[vs_0][fw_0] bond1:o[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0
[vs_0][fw_0] bond1:O[44]: 192.168.2.254 -&amp;gt; 192.168.1.1 (ICMP) len=84 id=0
ICMP: type=8 code=0 echo request id=10926 seq=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.B.&lt;/STRONG&gt; PC replies:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[vs_0][ppak_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][fw_0] bond1:i[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][fw_0] bond1:I[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][fw_0] bond1.9:o[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][fw_0] bond1.9:O[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][fw_0] bond1.9:Oe[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0
[vs_0][ppak_0] bond1.9:Oe[44]: 192.168.1.1 -&amp;gt; 192.168.2.254 (ICMP) len=84 id=62773
ICMP: type=0 code=0 echo reply id=10926 seq=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked at the tables reported in "&lt;EM&gt;fw monitor&lt;/EM&gt;" section of &lt;A title="fw monitor" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_CLI_ReferenceGuide/Content/Topics-CLIG/FWG/fw-monitor.htm?Highlight=fw%20monitor" target="_self"&gt;R81.20 CLI Reference Guide&lt;/A&gt; in order to understand the meaning of "&lt;EM&gt;i, I, O,...&lt;/EM&gt;" (as per your suggestion).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3. Questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3.1.&lt;/STRONG&gt; I'm not sure what does "&lt;EM&gt;Oe&lt;/EM&gt;" mean; something like &lt;STRONG&gt;Post-Outbound+&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;Pre-Outbound VPN&amp;nbsp;&lt;/STRONG&gt;?&lt;BR /&gt;&lt;STRONG&gt;3.2.&lt;/STRONG&gt; By the traces (I'm focusing on traffic initiated by PC - point 1 - or reply traffic from PC - point 2) I see the "&lt;EM&gt;E&lt;/EM&gt;" is missing; so the packet isn't encrypted...is it correct ? If it is correct, so why in SmartLog I'm seeing these packets as "Encrypted" (those initiated by PC - point 1):&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Encrypted packets.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28299i574EF9E13A4380E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Encrypted packets.png" alt="Encrypted packets.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Now I provide more info about this site-to-site VPN:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;This VPN was setup long time ago (it's not brand new); this issue started just few days ago&lt;/LI&gt;&lt;LI&gt;We have other VPNs configured at the same manner (Check Point- Cisco Meraki) with no issue&lt;/LI&gt;&lt;LI&gt;No changes were made on Cisco Meraki or Check Point&lt;/LI&gt;&lt;LI&gt;On Cisco Meraki I see WAN packets exchanged by Cisco Meraki and Check Point (related to site-to-site VPN); (tunnel) packets leaving Cisco Meraki (point 2 above); but no (tunnel) packets from Check Point.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;These are site-to-site details:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Encryption Method:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;IKEv1 (policy-based)&lt;/P&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;IKE - Phase 1&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Encryption Algorithm: AES-128&lt;/DIV&gt;&lt;DIV class=""&gt;Data Integrity: SHA1&lt;/DIV&gt;&lt;DIV class=""&gt;Diffie-Hellman group: 2 (1024 bit)&lt;/DIV&gt;&lt;DIV class=""&gt;Renegotiation: 480 minutes&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;IPSec - Phase 2&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Encryption Algorithm: AES-128&lt;/DIV&gt;&lt;DIV class=""&gt;Data Integrity: SHA1&lt;/DIV&gt;&lt;DIV class=""&gt;PFS: Off&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Renegotiation: 28800 seconds&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Check Point&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;VPN Domain: 5 IP class&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Cisco Meraki&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;VPN Domain: 1 IP class&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;I have learned that colleagues at Site B have experienced Internet connectivity slowdown issues which led them to open a support ticket with the local ISP. I am concerned that the ISP may have made changes (to their infrastructure) that would explain the described behavior.&lt;/P&gt;&lt;P class=""&gt;However, I would like to be certain that the problem does not lie with Check Point.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 Nov 2024 11:13:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231470#M44611</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-11-01T11:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231479#M44613</link>
      <description>&lt;P&gt;All valid questions&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/29052"&gt;@cyberluke365&lt;/a&gt;&amp;nbsp;. So Oe flafg means Post Outbound, encrypted, so it means leaving CP encrypted. What happens to it after, I have no idea.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 11:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231479#M44613</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-01T11:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231483#M44616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes, Oe means&amp;nbsp;&lt;SPAN&gt;Outbound before encrypt, check this link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41563" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41563&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It seems to me that firewall is encrypting the packets. You could check if some new NAT rule is being applied to this traffic, that should be reflected on logs. If there is no NAT, i would do a ping from 192.168.1.1 to 192.168.2.254 with size 500 bytes, and check that traffic on external interface, you should filter tcpdump with the peer ip address, esp or nat-t, and greater than 500. The size of the packet is just a way to identify them after encryption, so you could use any size. If traffic does not leave the firewall, check drops with fw ctl zdebug drop. If they leave the firwall, check the meraki device. If you say it was working before it should be ok, but i would double check which encryption domain are being negotiated in phase 2 (vpn tu tlist). Also, as always... should open a case with TAC. hth.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 13:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231483#M44616</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-11-01T13:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231484#M44617</link>
      <description>&lt;P&gt;Also, forgot to ask again, did you make sure what I mentioned in my previous post? If you use combination of hosts/subnets. you should set tunnel mgmt tab in vpn community in smart console as "per gateway" and install policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 13:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231484#M44617</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-01T13:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231499#M44623</link>
      <description>&lt;P&gt;When you initiate the ping, do you see the outgoing IPsec traffic leaving your local gateway?&lt;BR /&gt;If you do, and given it appears on your end the traffic is being properly encrypted (as evidenced by the Oe packet in fw monitor), the problem is unlikely to be on your end.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 15:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231499#M44623</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-01T15:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231532#M44639</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thank you for sharing the link.&lt;/P&gt;&lt;P&gt;Could you please explain your statement "it seems to me that firewall is encrypting the packets" ? This part of the table at the link you provided:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Parameters.png" style="width: 926px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28305i176C2C8C84F077A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Parameters.png" alt="Parameters.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The latest packet from&amp;nbsp;&lt;STRONG&gt;fw monitor &lt;/STRONG&gt;(PING) reports "&lt;EM&gt;Oe&lt;/EM&gt;". Comparing it with table above, if I'm not mistaken, this indicates &lt;STRONG&gt;Pre-Outbound VPN&lt;/STRONG&gt;,&amp;nbsp;&lt;EM&gt;Outbound before encrypt. &lt;/EM&gt;So it isn't encrypted yet, as the "&lt;EM&gt;OE&lt;/EM&gt;" state is missing. It seems to me that packet is stuck between the &lt;STRONG&gt;Pre-Outbound VPN&lt;/STRONG&gt; and &lt;STRONG&gt;Post-Outbound VPN&lt;/STRONG&gt;, correct ? However from SmartLog I see the ICMP packets as encrypted (screenshot I post before). So maybe there is something wrong in the logic I wrote here.&lt;/P&gt;&lt;P&gt;I confirm there is no NAT. The &lt;STRONG&gt;ping -l 500 192.168.2.254&lt;/STRONG&gt; returns &lt;EM&gt;Request timeout&lt;/EM&gt;. While doing it, I run the tcpdump of external interface and this is the capture results filtered by the public IP of &lt;EM&gt;Site B&lt;/EM&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tcpdump.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28307i1C11B0ABFF7E9BB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="tcpdump.png" alt="tcpdump.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Legend&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;*.66 - Public IP of Site B&lt;/LI&gt;&lt;LI&gt;*.30 - Public IP of Site A&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I also opened a case with TAC; I'm waiting for their first contact.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 12:16:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231532#M44639</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-11-02T12:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231533#M44640</link>
      <description>&lt;P&gt;What it means essentially is that traffic is going through the tunnel, hence the Oe flag in fw monitor.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 12:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231533#M44640</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-02T12:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231534#M44641</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;,&lt;BR /&gt;VPN Domain (on both sites) are subnets, no hosts. &lt;STRONG&gt;VPN Tunnel Sharing&lt;/STRONG&gt; is set to &lt;EM&gt;One VPN tunnel per subnet pair.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 12:19:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231534#M44641</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-11-02T12:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231535#M44642</link>
      <description>&lt;P&gt;K, no issues on that front then.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 12:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231535#M44642</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-02T12:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231625#M44669</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes, it is correct that Oe is before encryption, but if gateway is tagging this packet for encryption it is a good sign, it is normal not to see OE because the IP's change, they are encapsulated and you can only see the public IP's instead (that is why the tcpdump trick helps us to check if the packet is leaving). On the other hand, on the capture you provided, how long are ESP packets? if they are 548 bits or something like that, that is your ping being encrypted and sent to the remote peer, that would mean the firewall is doing its job.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 12:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231625#M44669</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-11-04T12:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231633#M44671</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This morning, the site-to-site VPN started working again. I didn’t change anything in the configuration, and the investigation conducted (thank you for your useful information) confirms that the issue was not attributable to Check Point or Cisco Meraki but likely 'in the middle' (that is, within the Internet connectivity).&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 13:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231633#M44671</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2024-11-04T13:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231634#M44672</link>
      <description>&lt;P&gt;Thats great to know!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 13:10:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231634#M44672</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-04T13:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231667#M44678</link>
      <description>&lt;P&gt;When the packet hits OE, it will be fully encrypted (source of local gateway, destination of remote gateway).&lt;BR /&gt;fw monitor will only show it if the&amp;nbsp;filter includes those IP addresses (otherwise, it won't show it).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 18:25:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/231667#M44678</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-04T18:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250287#M48900</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;If you have an S2S VPN that is in UP, both Phase 1 and Phase 2, but your traffic is not being 'Encrypted/Decrypted' and you don't see it going through the VPN TUNNEL you have built either, this may be some configuration error in the Phase 2 part of the VPN?&lt;BR /&gt;I use policy based VPN, in R81.20 with JHF 98&lt;BR /&gt;Can I use some diagnostic command to find out why my traffic is not going through the VPN tunnel?&lt;BR /&gt;It's weird, because the VPN is up but there is no traffic through the tunnel.&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2025 14:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250287#M48900</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-05-31T14:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250288#M48901</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;You can always do fw monitor. Fwiw, try vpn accel off as well as a test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2025 15:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250288#M48901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-31T15:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Site to Site VPN, Tunnel is UP, but traffic doesn't arrive to destination</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250365#M48948</link>
      <description>&lt;P&gt;You could probably get that information through debugging the VPN module:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_PerformanceTuning_AdminGuide/Content/Topics-PTG/Kernel-Debug/Module-VPN.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_PerformanceTuning_AdminGuide/Content/Topics-PTG/Kernel-Debug/Module-VPN.htm&lt;/A&gt;&lt;BR /&gt;Having said that have you confirmed there are routes for the relevant networks that point to the VPN tunnel?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:52:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Site-to-Site-VPN-Tunnel-is-UP-but-traffic-doesn-t/m-p/250365#M48948</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-02T13:52:34Z</dc:date>
    </item>
  </channel>
</rss>

