<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CP to Azure S2S vpn issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/235535#M45656</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just to update on this, customer and I had been working with EXCELLENT Tier3 engineer in dallas TAC (I worked with him many times before, he is great) and he gave us some things to check, which we had verified, but still no luck. Strangely enough, when he had customer run vpn tu tlist -p peer_ip command, it shows message "narrowed" in one of the table entries.&lt;/P&gt;
&lt;P&gt;We confirmed enc domains, enc. settings, did debugs, did tunnel resets, but same issue.&lt;/P&gt;
&lt;P&gt;Will do another remote with TAC and hopefully have more clarity. I feel we are close to solving this.&lt;/P&gt;
&lt;P&gt;Thanks for all the help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 16:13:07 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-12T16:13:07Z</dc:date>
    <item>
      <title>CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231209#M44536</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I hope someone might be able to shed some light into this situation, as I find it very peculiar. So, customer has domain based vpn between cp and azure and tunnel works fine, BUT, here is the issue. So, azure subnet is 10.18.0.0/16 and there is one host in that subnet that no matter what we do, logs show its going through the tunnel, though random one shows it being dropped or going out clear (randomly), but the page to access it never does come up, like it should.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the other hosts/services work fine.&lt;/P&gt;
&lt;P&gt;Now, customer did have Azure case, they did bunch of checks and determined its not the problem on their end. I, together with the customer, did bunch of captures, checked the logs, we even added that host IP into enc domain, reset the tunnel, set tunnel management per gateway as a test, no dice.&lt;/P&gt;
&lt;P&gt;I dont sadly have the actual log at the moment (can get it from the client), but captures when we run them show traffic comes to internal interface and thats it, nothing else, which is super odd, because say host 10.18.0.80 or .85 are fine, but .81 never works. Now, I know logically it would indicate issue with the host, but MS support verified 100% that is not the case.&lt;/P&gt;
&lt;P&gt;I had client do basic vpn debugs on cp side, will review them myself, but just wondering if anyone may have any insight/suggestions we could try. I cant possible think of anything else myself that we had not tested.&lt;/P&gt;
&lt;P&gt;Thanks as always.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 00:46:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231209#M44536</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-30T00:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231221#M44542</link>
      <description>&lt;P&gt;Did you contact CP TAC yet ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 08:53:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231221#M44542</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-10-30T08:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231243#M44549</link>
      <description>&lt;P&gt;Not yet, as I want to review vpn debugs myself first.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 10:19:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231243#M44549</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-30T10:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231272#M44557</link>
      <description>&lt;P&gt;Just to update on this...customer will try change the IP of the problematic host to see if that helps, but if not, they will send me the vpn debugs and will review. Honestly, Im not sure this even really qualifies for TAC case, though logs clearly show when issue is there that traffic does NOT go through VPN tunnel and Azure support is adamant its not problem on their end.&lt;/P&gt;
&lt;P&gt;Anywho, lets see what gives &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 17:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231272#M44557</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-30T17:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231305#M44576</link>
      <description>&lt;P&gt;Do you have "disable NAT in VPN community" set?&amp;nbsp; Almost sounds like you have a NAT of some kind just for that .81 address which would allow the traffic to enter the tunnel but then get dropped on the other end.&amp;nbsp; If the destination IP is getting NATted that could be why the traffic seems to disappear in your capture after the inbound.&lt;/P&gt;
&lt;P&gt;I assume there is no Windows Firewall on .81?&amp;nbsp;&amp;nbsp;If the traffic can be verified to be entering the tunnel properly on your side, you may need a packet capture on the .81 host to confirm the traffic is actually getting there.&amp;nbsp; Had many a troubleshooting session where the traffic is going into the tunnel properly and the other end insists it is decrypting and reaching the endpoint on their side...but it isn't due to a VPN config/policy or routing issue.&amp;nbsp; Until you do that packet capture they will just blame you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 22:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231305#M44576</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-10-30T22:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231311#M44581</link>
      <description>&lt;P&gt;Yep, we do have nat disabled. I even had them create manual no nat rule for that IP, no luck. Funny enough, when we do captures, randomly it shows going through the tunnel, but even then page never comes up.&lt;/P&gt;
&lt;P&gt;Let me see if their dedicated Azure expert can change the ip of that host and see what happens.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 23:10:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231311#M44581</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-30T23:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231442#M44605</link>
      <description>&lt;P&gt;Btw, just confirmed, no windows firewall. Let me review the logs and see what we can find.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 18:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231442#M44605</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-31T18:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231444#M44606</link>
      <description>&lt;P&gt;Just spoke with customer. They decided to install jumbo 89 on their mgmt and cluster, so will let me know this weekend if that changes anything. I secretly hope it fixes the issue, but lets see.&lt;/P&gt;
&lt;P&gt;If not, they will open TAC case next week and will provide an update.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 19:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231444#M44606</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-31T19:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231584#M44659</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this kind of issues needs cooperation from both sides.&lt;/P&gt;
&lt;P&gt;from your (CP) side, you can only run:&lt;BR /&gt;vpn tu conn &amp;amp; fw monitor on the connection 5 tupple, and tcpdump on the ESP/NAT-T packets, but someone needs to run traffic capture on Azure side to see if the traffic reached the other sides, and if so, what it happening with it? does it reach the host? (if you manage this host, you can install wireshark over there and see for yourself), does the host respond or not?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 19:24:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231584#M44659</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-11-03T19:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231593#M44662</link>
      <description>&lt;P&gt;I totally agree. Let me follow up with customer to see if jumbo 89 made any difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 20:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/231593#M44662</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-03T20:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232787#M44992</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just to give quick update on this, spoke with customer, they tried changing the IP on Azure host side, no luck. They wull install jumbo 89 this Saturday on the cluster and test. I would personally be shocked if that fixes anything, but lets hope for the best &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Anyway, if no change, they will open TAC case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 19:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232787#M44992</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-14T19:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232802#M44996</link>
      <description>&lt;P&gt;"but captures when we run them show traffic comes to internal interface and thats it, nothing else, which is super odd, because say host 10.18.0.80 or .85 are fine, but .81 never works."&lt;/P&gt;
&lt;P&gt;if this capture is tcpdump it makes sense because you see the data incoming on LAN interface unecrypted. Then it would be send out on WAN interface and you will see ESP traffic between the 2 public IP's.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For better understanding we need vpn debug while traffic is send towards the problem host. I assume you see on your side on the check point drops and unencrypted packets? Or you always see encrypted data in the logs towards the host? If you do not seen encrypted log entries it could be an indication it is an issue on your side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using global encryption domain for tunnel? or you set it up on the community itself (would recommend this)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 21:12:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232802#M44996</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-14T21:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232803#M44997</link>
      <description>&lt;P&gt;Its actually set per community, not global. As far as packets, you see encrypted ones most of the time and then unencrypted say 5-10% of the time (randomly) and shows dropped because of ssl inspection, which I find very peculiar.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, let me see if jumbo install makes any difference, but if not, then we may need to do some basic vpn debugs next time they can dedicate some time to this.&lt;/P&gt;
&lt;P&gt;Thanks Lesley.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 21:17:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232803#M44997</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-14T21:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232934#M45049</link>
      <description>&lt;P&gt;Just to give an update...client installed jumbo 90, but same issue, which Im really not surprised about. Anywho, they will open TAC case next week to check this further.&lt;/P&gt;
&lt;P&gt;I will update when we have more info.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 17:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/232934#M45049</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-16T17:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233156#M45088</link>
      <description>&lt;P&gt;Any debugs on the way? Ike viewer would help here a lot&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 18:42:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233156#M45088</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-19T18:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233159#M45089</link>
      <description>&lt;P&gt;Not yet sadly. These guys are super busy, so may take awhile :- (&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 18:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233159#M45089</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-19T18:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233181#M45092</link>
      <description>&lt;P&gt;I worked with a customer today on a new Azure VPN setup. &amp;nbsp;Had some issues, too, band the customer had the Windows firewall policy on the Azure VM not allowing some traffic in and out. &amp;nbsp;They did have some NSGs in place, too, which had to be adjusted.&lt;/P&gt;
&lt;P&gt;Another item was missing a subnet on the Azure side VPN “local network gateway”. &amp;nbsp;This may not be your issue tho.&lt;/P&gt;
&lt;P&gt;I also had their vpn community tunnel management set to “one tunnel per subnet pair” rather than universal tunnels. I wasn’t sure how they had their Azure side configured.&lt;/P&gt;
&lt;P&gt;I hope some of this helps. Good luck with it!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 23:15:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233181#M45092</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-11-19T23:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233185#M45095</link>
      <description>&lt;P&gt;Hey Duane, tx for responding man, always nice to hear from you! Yea, we tested all those things you mentioned, tried different tunnel mgmt options, no dice. We know setup is right, as its ONLY this one host with the issue, but based on all Azure support did, they told the customer to look elsewhere.&lt;/P&gt;
&lt;P&gt;I know they will probably open TAC case, but you know how it goes, lots of IT issues and only few guys to deal with them, so they need to work on more pressing problems, specially before holidays.&lt;/P&gt;
&lt;P&gt;I know their IT boss will text me, as he always does, to ask for my help on this, though I feel he does it lately to get a good travel destination advice from me &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Anywho, I will certainly update once I have more info.&lt;/P&gt;
&lt;P&gt;Thanks as always again!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 00:14:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/233185#M45095</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-20T00:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/234096#M45351</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just to update on this quick, customer told me they opened TAC case, but since its Txgiving in USA today, they will probably revisit this next week and let me know the outcome.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 17:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/234096#M45351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-28T17:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: CP to Azure S2S vpn issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/235109#M45580</link>
      <description>&lt;P&gt;Just to provide quick update on this. Customer has the TAC case opened and I believe it went to senior engineer, so once I have more details and when it gets fixed, will let you guys know how.&lt;/P&gt;
&lt;P&gt;Anyd&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 22:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-to-Azure-S2S-vpn-issue/m-p/235109#M45580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-09T22:53:16Z</dc:date>
    </item>
  </channel>
</rss>

