<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE Crashes and RA VPN issues on R81.20 Take 98 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242766#M47183</link>
    <description>&lt;P&gt;Just a thought, guys.&lt;/P&gt;
&lt;P&gt;I'm sure I mentioned about stability before and suggested to Checkpoint that it does not matter how secure a product is 'marketed' for, if the service suffers stability issues, the overall Checkpoint experience will be tarnished.&lt;/P&gt;
&lt;P&gt;I would personally like to see a supported mature and feature train release.&amp;nbsp;&lt;BR /&gt;Example:&lt;BR /&gt;R82 - Feature release&lt;BR /&gt;R81.20 - Recommended Release&lt;BR /&gt;R81.10 - mature release (Support for 3 years, once version is deemed mature)&lt;BR /&gt;&lt;BR /&gt;The positives of this:&lt;BR /&gt;Clients investment is protected while maintaining stability for the features they are using.&lt;BR /&gt;Certification investment could potentially be longer if you are certified against recommended, which last until mature train is expired.&lt;/P&gt;</description>
    <pubDate>Sun, 02 Mar 2025 10:04:12 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2025-03-02T10:04:12Z</dc:date>
    <item>
      <title>IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242309#M47056</link>
      <description>&lt;P&gt;We recently installed Take 98 on R81.20 and started having wide-spread problems with Remote Access VPN connecting. We also received a report from TAC Pro Support that an IKE crash was reported on our gateways, but unfortunately no additional details of the crash were provided. We did not see any signs that site-to-site VPN was affected, just RA VPN. After troubleshooting for a couple days, TAC informed us of a known bug and provided a patch that has fixed the issue. If you run into this issue after upgrading to T98, don't hesitate to reach out to TAC and ask about a patch for IKE crash.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:38:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242309#M47056</guid>
      <dc:creator>Alex_Lewis</dc:creator>
      <dc:date>2025-02-25T20:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242311#M47058</link>
      <description>&lt;P&gt;Interesting...I had not had that problem myself. Just curious, what was the actual fix?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 19:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242311#M47058</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-25T19:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242316#M47061</link>
      <description>&lt;P&gt;I wonder if Check Point knows what Important Notes are for?&lt;/P&gt;
&lt;P&gt;Let me help; &lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Important-Notes.htm?tocpath=_____2" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Important-Notes.htm?tocpath=_____2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Some VPN issue was also reported in some of the latest threads as well, without anything in the important notes.&lt;/P&gt;
&lt;P&gt;The extreme load on MLMs also was not present for a long time, I'm unsure yet if it has been added, as dates are not present when a new entry is added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And yeah - don't upgrade to newest jumbos but let others take the hit &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt; You continuously for each jumbo advertise that this is now faster and more stable. Reporting it is now in your lab and stable, updating for 1hour 24hour and 48hours progress to stress how stable it is.&lt;/P&gt;
&lt;P&gt;I invite you to not post these updates. I see them at best as ignorance, and at worst as false advertising in a let's be honest a non existing lab or a lab consisting of a VM with zero usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Henrik&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242316#M47061</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2025-02-25T20:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242317#M47062</link>
      <description>&lt;P&gt;I guess the IKE crashing is not an issue for everyone. I had asked TAC about installing on other gateways when we upgrade them. There answer was "Unless we see the same IKED crashes or frequent significant RA VPN/S2S VPN tunnel disconnections, we don't recommend to install this portfix on all the gateways on T98."&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242317#M47062</guid>
      <dc:creator>Alex_Lewis</dc:creator>
      <dc:date>2025-02-25T20:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242318#M47063</link>
      <description>&lt;P&gt;I suppose everyone's experience is different. I can only speak for myself &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:06:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242318#M47063</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-25T20:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242368#M47070</link>
      <description>&lt;P&gt;Running into exactly the same problem across our estate.&amp;nbsp; Think I've got 4 separate PRO cases open:-)&amp;nbsp; TAC has not mentioned a fix - I will link them to this post.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7612"&gt;@Alex_Lewis&lt;/a&gt;&amp;nbsp;do you mind privately sharing the SR number where TAC provided you with the patch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 09:24:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242368#M47070</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-02-26T09:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242397#M47072</link>
      <description>&lt;P&gt;There is a hot fix identifier mentioned in this thread over an earlier take FYI&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Product-Announcements/R81-20-Jumbo-Hotfix-Accumulator-take-96-has-been-released-today/ba-p/237606" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Product-Announcements/R81-20-Jumbo-Hotfix-Accumulator-take-96-has-been-released-today/ba-p/237606&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 12:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242397#M47072</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-02-26T12:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242399#M47073</link>
      <description>&lt;P&gt;I think then we can assume it is not important enough to put it on this list. I see recently stuff has been added so then we also assume Check Point is still aware of this page. If an issue is only affecting a small amount of customers it would make sense not to put it on this page. It could be that the Jumbo is good for 99% of the customer and some it can cause an issue. If they put everything on this page it will make unreadable and difficult to understand.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the lab testing, I don't think it is needed to call someone ignorant. It is clearly stated it is in a LAB setup so everyone is aware of this. I think we all know the definition of a lab and that could not fully reflect a realtime setup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 12:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242399#M47073</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-26T12:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242408#M47075</link>
      <description>&lt;P&gt;You are right, and it came out harshly - I am sorry for that.&lt;/P&gt;
&lt;P&gt;I was trying (in a bad mood) to argue that the value of these tests show very little&amp;nbsp; in regards if of showing the issues that continuously keep popping up when we read down the forum posts.&lt;/P&gt;
&lt;P&gt;My grympy mood was more pointed to, that we as customers need to have downtime, even though it is well known inside Check Point. "It only affects a subset of users, so we will not state it clearly as a risk in the upgrade information" is I think, a strange decision.&lt;/P&gt;
&lt;P&gt;Let the customer evaluate the known issues. So does he hold a large RA environment, he could take a knowledgeable decision instead of feeling the pain and maybe skip upgrading.&lt;/P&gt;
&lt;P&gt;What our own management would say, is that transparency is key.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242408#M47075</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2025-02-26T13:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242409#M47076</link>
      <description>&lt;P&gt;Dont worry man, life is too short to get offended, thats been always my motto, haha. I dont get offended to anything, or in human way lol.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, I totally get what you are saying and I agree 100%. Its fair to say customers should be the ones to evaluate those things, because, lets be fair, production environment is hard to compare even to fully simulated lab, for the lack of better terms.&lt;/P&gt;
&lt;P&gt;Cheers brother.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242409#M47076</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-26T13:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242610#M47122</link>
      <description>&lt;P&gt;Which model?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 21:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242610#M47122</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-02-27T21:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242613#M47124</link>
      <description>&lt;P&gt;I was going to install jumbo 98 for the customer next week, but considering things said in this post, I think will stick with take 92 for now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 00:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242613#M47124</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T00:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242763#M47182</link>
      <description>&lt;P&gt;Just FYI to all,&lt;/P&gt;
&lt;P&gt;TAC has provided updated guidance which does not involve installing a patch.&amp;nbsp; Boils down to:&lt;BR /&gt;-&amp;nbsp;disabling the "Perform an organized shutdown of tunnels upon gateway restart" option&lt;BR /&gt;- Creating a backup of and then removing the '&lt;SPAN&gt;$FWDIR/database/cookiedb.NDB' and '$FWDIR/database/deldb.NDB' files.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We're currently still in freeze and the issue is not business impacting so we will implement in the coming week. As always best to check in with TAC before performing this in your own environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;Ruan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 08:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242763#M47182</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-03-02T08:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Crashes and RA VPN issues on R81.20 Take 98</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242766#M47183</link>
      <description>&lt;P&gt;Just a thought, guys.&lt;/P&gt;
&lt;P&gt;I'm sure I mentioned about stability before and suggested to Checkpoint that it does not matter how secure a product is 'marketed' for, if the service suffers stability issues, the overall Checkpoint experience will be tarnished.&lt;/P&gt;
&lt;P&gt;I would personally like to see a supported mature and feature train release.&amp;nbsp;&lt;BR /&gt;Example:&lt;BR /&gt;R82 - Feature release&lt;BR /&gt;R81.20 - Recommended Release&lt;BR /&gt;R81.10 - mature release (Support for 3 years, once version is deemed mature)&lt;BR /&gt;&lt;BR /&gt;The positives of this:&lt;BR /&gt;Clients investment is protected while maintaining stability for the features they are using.&lt;BR /&gt;Certification investment could potentially be longer if you are certified against recommended, which last until mature train is expired.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 10:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-Crashes-and-RA-VPN-issues-on-R81-20-Take-98/m-p/242766#M47183</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-03-02T10:04:12Z</dc:date>
    </item>
  </channel>
</rss>

