<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R82 - IKE ID Peer VPN Peer? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/234446#M45441</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;There is an external HA cluster Whos MAIN IP is a private IP address.&lt;/P&gt;&lt;P&gt;They are experiencing an issue with a S2S VPN Peer rejecting the Peer ID as in IKEv2 the Active member will use the MAIN IP when establishing the VPN.&lt;/P&gt;&lt;P&gt;In R82 I see there is now the enhanced Link Selection feature.&lt;/P&gt;&lt;P&gt;Will this override the MAIN IP and allow us to bypass this limitation of IkeV2 on R81.X?&lt;/P&gt;&lt;P&gt;Is there any other planned features regarding IkeID I am not aware of in R82?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is this a question for our SE to answer?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Dec 2024 12:28:49 GMT</pubDate>
    <dc:creator>StackCap43382</dc:creator>
    <dc:date>2024-12-03T12:28:49Z</dc:date>
    <item>
      <title>R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/234446#M45441</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;There is an external HA cluster Whos MAIN IP is a private IP address.&lt;/P&gt;&lt;P&gt;They are experiencing an issue with a S2S VPN Peer rejecting the Peer ID as in IKEv2 the Active member will use the MAIN IP when establishing the VPN.&lt;/P&gt;&lt;P&gt;In R82 I see there is now the enhanced Link Selection feature.&lt;/P&gt;&lt;P&gt;Will this override the MAIN IP and allow us to bypass this limitation of IkeV2 on R81.X?&lt;/P&gt;&lt;P&gt;Is there any other planned features regarding IkeID I am not aware of in R82?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is this a question for our SE to answer?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 12:28:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/234446#M45441</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2024-12-03T12:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/234462#M45448</link>
      <description>&lt;P&gt;Thats my understanding as well, it would override main IP, but had not tested it in the lab yet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 14:04:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/234462#M45448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-03T14:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271200#M103423</link>
      <description>&lt;P&gt;I have a ticket for it - peer is asking us to confirm ike-id on enhanced link selection. As far as i can tell will need captures and debugs and offline checking in wireshark and ikeview - then i wonder if &lt;EM&gt;BestRoutingSenderIP&amp;nbsp;&lt;/EM&gt;from&amp;nbsp;sk108600 might be needed? You'd hope it wouldnt be so much of a faff anymore...if im lucky the otherside is a palo and i cant tell the Palo the remote id in the ike gateway peer identification field....i hope...ill let you know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 11:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271200#M103423</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2026-02-18T11:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271201#M103424</link>
      <description>&lt;P&gt;Are you using enhanced link selection in R82?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 12:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271201#M103424</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-18T12:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271205#M103425</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I must say i did not read enhaced link selection docummentation in R82, but below the options we found in the past for this limitation.&lt;/P&gt;
&lt;P&gt;If you will use only one external interface for VPN's with third party you could use one of the recommended options from&amp;nbsp;&lt;SPAN&gt;sk44978:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"In SmartConsole, open the Security Gateway object -&amp;gt; IPSec VPN &amp;gt; Link Selection.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Selecting the "Selected address from topology table:" or "Statically NATed IP:" option will affect the IPv4 address used as the IKE ID in Main Mode Packet 5."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;However if you use more than one external interface it is not a perfect solution. Another suggestion from Check Point is in&amp;nbsp;sk33822:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Configure the Security Gateway to work with ID configured to an&amp;nbsp;FQDN"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In this post we received another suggestion to use one VS per external interface so we can use options from&amp;nbsp;&lt;SPAN&gt;sk44978.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Main-Mode-ID/m-p/120566" target="_blank"&gt;IKE Main Mode ID - Check Point CheckMates&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 12:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271205#M103425</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2026-02-18T12:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: R82 - IKE ID Peer VPN Peer?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271207#M103426</link>
      <description>&lt;P&gt;I tried using it with one customer, but we could never make it work. Even had TAC case opened for it, no joy...so for sake of saving time and frustration, we just decided to use old school link selection method and all worked fine.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 12:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-IKE-ID-Peer-VPN-Peer/m-p/271207#M103426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-18T12:55:32Z</dc:date>
    </item>
  </channel>
</rss>

