<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec between two Windows Server, Checkpoint Maestro in between in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246385#M48014</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for the late reply, I was on vacation.&lt;/P&gt;&lt;P&gt;unfortunately, this is not a VPN tunnel on the checkpoint itself, but IPsec encrypted traffic between two servers with the checkpoint in between. There are no VPN tunnels running on the Checkpoint itself.&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 12:12:29 GMT</pubDate>
    <dc:creator>fourcly</dc:creator>
    <dc:date>2025-04-14T12:12:29Z</dc:date>
    <item>
      <title>IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/245648#M47861</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have the problem that an IPsec connection between two Windows servers is not working due to our Checkpoint Maestro Cluster. If we hang the server in front of the Checkpoint, the IPsec works without a problem, has anyone here had any experience with this?&lt;/P&gt;&lt;P&gt;In Wireshark I see many Identity Protection (Main Mode) packets in a row. There are also a lot of "Unknown packets" (243,244,246)&lt;/P&gt;&lt;P&gt;No NAT is active on our firewall and we have no other VPN tunnels running&lt;/P&gt;&lt;P&gt;Could this be a MTU/MSS problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 20:55:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/245648#M47861</guid>
      <dc:creator>fourcly</dc:creator>
      <dc:date>2025-04-03T20:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/245722#M47871</link>
      <description>&lt;P&gt;Hey Paul,&lt;/P&gt;
&lt;P&gt;If you do vpn tu and check option to list the tunnel by phase 1 or 2, option 3 and 4, what do you see?&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# vpn tu&lt;/P&gt;
&lt;P&gt;********** Select Option **********&lt;/P&gt;
&lt;P&gt;(1) List all IKE SAs&lt;BR /&gt;(2) * List all IPsec SAs&lt;BR /&gt;(3) List all IKE SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(4) * List all IPsec SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(5) Delete all IPsec SAs for a given peer (GW)&lt;BR /&gt;(6) Delete all IPsec SAs for a given User (Client)&lt;BR /&gt;(7) Delete all IPsec+IKE SAs for a given peer (GW)&lt;BR /&gt;(8) Delete all IPsec+IKE SAs for a given User (Client)&lt;BR /&gt;(9) Delete all IPsec SAs for ALL peers and users&lt;BR /&gt;(0) Delete all IPsec+IKE SAs for ALL peers and users&lt;/P&gt;
&lt;P&gt;* To list data for a specific CoreXL instance, append "-i &amp;lt;instance number&amp;gt;" to your selection.&lt;/P&gt;
&lt;P&gt;(Q) Quit&lt;/P&gt;
&lt;P&gt;*******************************************&lt;/P&gt;
&lt;P&gt;Also, what if you try below?&lt;/P&gt;
&lt;P&gt;vpn tu list peer_ike peer-ip and same command with peer_ipsec&lt;/P&gt;
&lt;P&gt;Alternatively, do basic debug:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;Check vpnd and iked files in $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 17:15:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/245722#M47871</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-04T17:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246385#M48014</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for the late reply, I was on vacation.&lt;/P&gt;&lt;P&gt;unfortunately, this is not a VPN tunnel on the checkpoint itself, but IPsec encrypted traffic between two servers with the checkpoint in between. There are no VPN tunnels running on the Checkpoint itself.&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246385#M48014</guid>
      <dc:creator>fourcly</dc:creator>
      <dc:date>2025-04-14T12:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246388#M48016</link>
      <description>&lt;P&gt;K, no worries. Hope you had nice vacation : - )&lt;/P&gt;
&lt;P&gt;Anyway, in that case, all you need to make sure is that CP is allowing the traffic to pass through, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246388#M48016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T12:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246389#M48017</link>
      <description>&lt;P&gt;Thank you, everything was fine!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a firewall rule that allows all traffic, everything is also allowed in the log. However, no connection is established when testing. If we put the server in front of the checkpoint so that it no longer takes over the routing, everything works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246389#M48017</guid>
      <dc:creator>fourcly</dc:creator>
      <dc:date>2025-04-14T12:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246390#M48018</link>
      <description>&lt;P&gt;Do you even see phase 1 form or nothing at all?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:24:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246390#M48018</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T12:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246405#M48024</link>
      <description>&lt;P&gt;Is the IPsec VPN blade enabled here?&lt;BR /&gt;I know this VPN is not terminating in the device, but I know IPsec code is handled as part of Implied Rules and something may be causing an issue.&lt;BR /&gt;I suspect TAC may be necessary to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246405#M48024</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-14T13:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec between two Windows Server, Checkpoint Maestro in between</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246444#M48028</link>
      <description>&lt;P&gt;You see any drops on the Maestro firewalls?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;fw ctl zdebug + drop | grep &amp;lt;IP&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What version? cpinfo -y all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What ports have you allowed? Think of: ESP, ike 500 upd-4500&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 19:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-between-two-Windows-Server-Checkpoint-Maestro-in-between/m-p/246444#M48028</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-14T19:10:29Z</dc:date>
    </item>
  </channel>
</rss>

