<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Something to keep in mind when VPN tunnel is down in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242252#M47049</link>
    <description>&lt;P&gt;Sources:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank" rel="noopener"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk101219" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk101219: VPN features in R80.x and R81.x versions&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk144094" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk144094: VPN tunnels with 3rd party peers fail because of mismatched IDs&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2025 09:56:43 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2025-02-25T09:56:43Z</dc:date>
    <item>
      <title>Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242065#M47024</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I know these settings in Guidbedit might not always be relevent, specially in newer versions, but I did come across few scenarios lately, in R81.20 as a matter of fact, where we had to go to guidbedit and set below values to false to get VPN tunnel to work:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_enable_supernet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;I sometimes also check this on the gateway, though this was only problem few times, so probably not a requirement, but also something to consider:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;gateway object -&amp;gt; other -&amp;gt; connection persistence -&amp;gt; I always check keep all connections&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2025 14:48:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242065#M47024</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-23T14:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242091#M47028</link>
      <description>&lt;P&gt;Yes! And this can become a daunting issue when trying to set up a tunnel with 3rd party peers. And if you're unlucky enough, even some TAC engineers forget to think about it and a simple solution as this turns into a repeated debugging and messaging back and forth.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or if you pay attention during your studies for CCTE, hopefully it won't become that big of an issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 06:56:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242091#M47028</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-02-24T06:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242129#M47037</link>
      <description>&lt;P&gt;Well, its good those sort of things dont happen too often these days, but just something to keep in mind, as I mentioned. Thats why we share ideas on here, to help others out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 12:18:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242129#M47037</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-24T12:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242157#M47041</link>
      <description>&lt;P&gt;Do you think these still come into play when using granular encryption domains?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 15:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242157#M47041</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-02-24T15:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242158#M47042</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can only speak from my own experience and here it is &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ever since R80 came out, I had never seen this issue with Azure, AWS or Fortinet, ONLY with Palo Alto and Cisco. Cant say if thats case with others, but thats what I had observed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 16:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242158#M47042</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-24T16:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242227#M47047</link>
      <description>&lt;P&gt;One thing I also found from time to time, depending on 3rd party vendor, is that say even if ONLY subnets are involved, you still may need to select "per gateway" in tunnel management tab of the VPN community.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 02:36:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242227#M47047</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-25T02:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242252#M47049</link>
      <description>&lt;P&gt;Sources:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank" rel="noopener"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk101219" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk101219: VPN features in R80.x and R81.x versions&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk144094" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk144094: VPN tunnels with 3rd party peers fail because of mismatched IDs&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 09:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242252#M47049</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-02-25T09:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242282#M47053</link>
      <description>&lt;P&gt;All great references&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 14:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242282#M47053</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-25T14:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Something to keep in mind when VPN tunnel is down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242283#M47054</link>
      <description>&lt;P&gt;Btw, that last sk, never seen it before, but ran the command in R82 and it worked.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 14:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Something-to-keep-in-mind-when-VPN-tunnel-is-down/m-p/242283#M47054</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-25T14:56:33Z</dc:date>
    </item>
  </channel>
</rss>

