<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Methods to Reset Site-to-Site IPSec VPN tunnel in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237096#M46014</link>
    <description>&lt;P&gt;But what Im saying is if you delete cp object and add it back, you dont need to know psk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You only need to know it if you delete interoperable object and put it back in the community.&lt;/P&gt;
&lt;P&gt;Hope thats clear now?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sun, 29 Dec 2024 01:10:23 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-29T01:10:23Z</dc:date>
    <item>
      <title>Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237069#M45990</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Appliance: 9100 - Standalone - R81.20&lt;/P&gt;&lt;P&gt;I am having VPN tunnel DOWN and have to reboot the device to resolve the VPN tunnel to UP. So, I just want to ask if there is a way to reset VPN tunnel instead of using SmartView Monitor, vpn tu?&lt;BR /&gt;Cause my GW don't have SmartEvent/Monitoring Licenses so I can't reset VPN tunnel in SmartView Monitor; and when using vpn tu to delete IPSec SAs/IKE, it didn't&amp;nbsp;recover.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best Regards.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 18:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237069#M45990</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-12-28T18:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237070#M45991</link>
      <description>&lt;P&gt;Consider using Permanent Tunnels to improve the reliability of the tunnels:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;As companies have become more dependent on VPNs for communication to other sites, uninterrupted connectivity has become more crucial than ever before. Therefore it is essential to make sure that the VPN tunnels are kept up and running. Permanent Tunnels are constantly kept active and as a result, make it easier to recognize malfunctions and connectivity problems.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_adminscap variable"&gt;Administrators&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;can monitor the two sides of a VPN tunnel and identify problems without delay."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 19:05:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237070#M45991</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-28T19:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237073#M45994</link>
      <description>&lt;P&gt;Best way I know of to truly reset vpn tunnel is remove cp gw from vpn community, push policy, add it back, push policy again.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 20:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237073#M45994</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-28T20:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237079#M45998</link>
      <description>&lt;P&gt;.. just make sure you still know the correct PSK, because you will have to enter it again ..&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 23:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237079#M45998</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-28T23:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237080#M45999</link>
      <description>&lt;P&gt;I dont believe thats needed if you remove cp object, ONLY interoperable one.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237080#M45999</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T00:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237082#M46001</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp; when using vpn tu to delete IPSec SAs/IKE, it didn't recover.&lt;/P&gt;&lt;P&gt;Then there is a problem with the VPN configuration. To troubleshoot further , additional information is needed.&lt;/P&gt;&lt;P&gt;E.g. which Phase is failing?&lt;/P&gt;&lt;P&gt;what does "vpn tu list peer_ipsec &amp;lt;peer_IP&amp;gt;" show?&lt;/P&gt;&lt;P&gt;What do you see in tcpdump on the external interface of the firewall? tcpdump -nnni &amp;lt;ext_iface&amp;gt; host &amp;lt;peer_IP&amp;gt;&lt;/P&gt;&lt;P&gt;What do you see in the FW logs for the &amp;lt;peer_IP&amp;gt;?&lt;/P&gt;&lt;P&gt;What does "the other side" see in their logs?&lt;/P&gt;&lt;P&gt;Next step is to allow IKE debugging. Keep in mind, in R81.20 iked is multithreaded, so the IKE debug info can go into any of the /etc/fw/log/iked?.* file, and there is no corresponding ikeview utility anymore to conveniently "decipher" these files.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 01:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237082#M46001</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T01:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237083#M46002</link>
      <description>&lt;P&gt;&amp;gt; &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm" target="_blank" rel="noopener noreferrer"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_&lt;STRONG&gt;R82&lt;/STRONG&gt;_SitetoSiteVPN_AdminGuide/Content/T...&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; Standalone - &lt;STRONG&gt;R81.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Consider using Permanent Tunnels to improve the reliability of the tunnels:&lt;/P&gt;&lt;P&gt;Allowing DPD will not help if the tunnel does not establish correctly to begin with (provided there is some traffic between the enc domains).&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 02:36:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237083#M46002</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T02:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237086#M46005</link>
      <description>&lt;P&gt;Try this in the lab &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; And how do you know, that "the other side" is a CheckPoint?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237086#M46005</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T00:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237088#M46007</link>
      <description>&lt;P&gt;I tried it at least 50 times lol&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237088#M46007</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T00:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237090#M46009</link>
      <description>&lt;P&gt;#metoo&amp;nbsp; and every time the PSK disappeared. In any case, I would first make sure the correct PSK is known.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:26:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237090#M46009</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T00:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237092#M46010</link>
      <description>&lt;P&gt;Im positive you would have deleted interoperable object, as there is nowhere you can put PSK on CP object in the community.&lt;/P&gt;
&lt;P&gt;But, I agree, always good idea to know PSK.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237092#M46010</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T00:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237093#M46011</link>
      <description>&lt;P&gt;You mean if both CP FWs are managed by the same Mgmt station, right? And if it's a 3d party company?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:53:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237093#M46011</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T00:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237094#M46012</link>
      <description>&lt;P&gt;I mean one CP and other one 3rd party. In such case, other object has to be presented as interoperable object.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 00:57:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237094#M46012</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T00:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237095#M46013</link>
      <description>&lt;P&gt;Exactly! That's why you need to know the PSK &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From the the original post it's not clear what "the other side" is and who controls it. So, in this case, the PSK *must* be mentioned.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 01:04:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237095#M46013</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T01:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237096#M46014</link>
      <description>&lt;P&gt;But what Im saying is if you delete cp object and add it back, you dont need to know psk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You only need to know it if you delete interoperable object and put it back in the community.&lt;/P&gt;
&lt;P&gt;Hope thats clear now?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 01:10:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237096#M46014</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T01:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237097#M46015</link>
      <description>&lt;P&gt;In this case yes, indeed. I interpreted it a bit wider and "looser" - the object is a CP device managed by a 3d party. So, a misunderstanding on my part &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 01:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237097#M46015</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-29T01:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237098#M46016</link>
      <description>&lt;P&gt;Glad we are in agreement &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Dec 2024 01:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237098#M46016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-29T01:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Methods to Reset Site-to-Site IPSec VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237224#M46044</link>
      <description>&lt;P&gt;There are no more ways then this, so indeed reboot or vpn tu.&lt;/P&gt;
&lt;P&gt;Policy push can force rekey, it is not a reset but sometimes it can trigger stuff.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 18:45:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Methods-to-Reset-Site-to-Site-IPSec-VPN-tunnel/m-p/237224#M46044</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-30T18:45:07Z</dc:date>
    </item>
  </channel>
</rss>

