<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234241#M45373</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;When logs from a specific VPN community look like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 630px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28619i356C80BDC5918342/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;All logs are "key install" what i know is that key installation happens as configured on the advanced settings of the community:&lt;/P&gt;
&lt;P&gt;Phase 1: &lt;STRONG&gt;240 mins&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Phase2: &lt;STRONG&gt;3600 seconds&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;So why it is happening all the time?&lt;/P&gt;
&lt;P&gt;What does that mean, a customer is complaining that they are loosing connection !&lt;/P&gt;
&lt;P&gt;How to troubleshoot this problem?&lt;/P&gt;</description>
    <pubDate>Sun, 01 Dec 2024 15:06:10 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2024-12-01T15:06:10Z</dc:date>
    <item>
      <title>VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234241#M45373</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;When logs from a specific VPN community look like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 630px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28619i356C80BDC5918342/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;All logs are "key install" what i know is that key installation happens as configured on the advanced settings of the community:&lt;/P&gt;
&lt;P&gt;Phase 1: &lt;STRONG&gt;240 mins&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Phase2: &lt;STRONG&gt;3600 seconds&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;So why it is happening all the time?&lt;/P&gt;
&lt;P&gt;What does that mean, a customer is complaining that they are loosing connection !&lt;/P&gt;
&lt;P&gt;How to troubleshoot this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 15:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234241#M45373</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-01T15:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234246#M45374</link>
      <description>&lt;P&gt;Start with reading the data inside those logs, see if they are good events, or errors / failures.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 16:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234246#M45374</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-12-01T16:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234247#M45375</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Can we please see the whole log? Just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 17:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234247#M45375</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-01T17:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234270#M45382</link>
      <description>&lt;DIV id="tinyMceEditor_2c0b4fbb7118c9Moudar_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;All logs are same:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 993px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28628i2F781BF2AEFF3B1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 07:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234270#M45382</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T07:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234297#M45393</link>
      <description>&lt;P&gt;Thank you! So quick mode would be phase 2 issue...can they verify all the settings do indeed match?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 12:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234297#M45393</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T12:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234307#M45399</link>
      <description>&lt;P&gt;So in normal cases, how often should we see "&lt;STRONG&gt;key install&lt;/STRONG&gt;" log other than the 240 and 3600 defaults?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234307#M45399</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T13:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234308#M45400</link>
      <description>&lt;P&gt;I know defaults are 1 day for phase 1 and 1 hour for phase 2.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234308#M45400</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T13:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234313#M45402</link>
      <description>&lt;P&gt;Under normal circumstances, how often should we see "key install" logs apart from the 240 and 3600 defaults? I mean, how frequently do these logs typically appear?&lt;/P&gt;
&lt;P&gt;The tunnel is up so phase 2 is OK i think!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 772px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28632i3DDABA1329CC9FF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:28:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234313#M45402</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T13:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234323#M45410</link>
      <description>&lt;P&gt;Is there an outage during or before/ after the key install time stamp? From my point of view it looks like you are receiving key install. This could be an indication that the issue should be check on the other side of the tunnel. To proof this theory a vpn debug in ikeview would help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:01:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234323#M45410</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-02T14:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234326#M45411</link>
      <description>&lt;P&gt;Yes, customer is&amp;nbsp;experience an outage.&lt;/P&gt;
&lt;P&gt;I am trying to download the Ikeview but website is down!?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28633i77849C5BB8019D0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;any other link to get Ikeview?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234326#M45411</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T14:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234328#M45412</link>
      <description>&lt;P&gt;I just tried, worked for me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:09:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234328#M45412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T14:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234331#M45413</link>
      <description>&lt;P&gt;it works now!&lt;/P&gt;
&lt;P&gt;On my gateway i have iked0.elg, iked1.elg and iked2.elg&lt;/P&gt;
&lt;P&gt;there is no&amp;nbsp;&lt;EM&gt;ike.elg&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;ikev2.xmll&amp;nbsp; !&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28634i3588CC92194A0E13/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;which one should be used in &lt;STRONG&gt;ikeview&lt;/STRONG&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234331#M45413</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T14:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234332#M45414</link>
      <description>&lt;P&gt;Either of those should work.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234332#M45414</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T14:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234334#M45415</link>
      <description>&lt;P&gt;Have you enabled&amp;nbsp;&lt;SPAN&gt;vpn debug truncon for debug start? Reproduce issue and turn off&amp;nbsp;vpn debug truncoff&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;files rotate on their own no need to delete them. Copy them and load them in ikeview.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you see remote peer ip in ikeview you are on the right track&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234334#M45415</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-02T14:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234335#M45416</link>
      <description>&lt;P&gt;the command:&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;vpn debug truncon&lt;/STRONG&gt;, can it focus on specific community or it only debugs all S2S VPN?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:34:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234335#M45416</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T14:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234338#M45417</link>
      <description>&lt;P&gt;I dont believe it can be done for specific community.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:44:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234338#M45417</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T14:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234341#M45418</link>
      <description>&lt;P&gt;I can now see this kind of log:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 366px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28635iBFC27BE6DE122609/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and it is coming very often with different SPI&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234341#M45418</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T14:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234345#M45419</link>
      <description>&lt;P&gt;I would definitely examine phase 2 settings, because thats what those messages relate to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 15:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234345#M45419</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T15:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234347#M45420</link>
      <description>&lt;P&gt;Try under vpn comm to change to per gateway or per subnet change between them to see if there is improvement&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 15:29:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234347#M45420</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-02T15:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234350#M45421</link>
      <description>&lt;P&gt;I have now changed it to "per Gateway" and my gateway started to "key install" on the other side gateway, i will keep an eye on it and back tomorrow with some insights. We have many subnets behind every gateway so maybe this is a better choice.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 15:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-logs/m-p/234350#M45421</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-12-02T15:58:33Z</dc:date>
    </item>
  </channel>
</rss>

