<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Configuration between Check Point and FortiGate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247652#M48397</link>
    <description>&lt;P&gt;Personally, I would never change those without checking with TAC first.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 14:35:59 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-29T14:35:59Z</dc:date>
    <item>
      <title>VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247585#M48388</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;A VPN has been configured between a Check Point R81 and Fortinet version 7.6 firewalls. After the initial VPN configuration, traffic is successfully traversing the two firewalls. If there is no traffic continually traversing the VPN for more than an hour, then the VPN appears to be broken and does not allow any traffic outbound from Check Point, unless the VPN reconfiguration is carried out on the Check Point firewall, however inbound traffic to the Check Point firewall is working fine.&lt;/P&gt;&lt;P&gt;Any suggestions to fix this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 04:24:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247585#M48388</guid>
      <dc:creator>arvindteemul1</dc:creator>
      <dc:date>2025-04-29T04:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247616#M48389</link>
      <description>&lt;P&gt;Enable permanent tunnel option with specific community and test.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Permanent tunnel.PNG" style="width: 461px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30341i97948B402D15ACF0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Permanent tunnel.PNG" alt="Permanent tunnel.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 10:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247616#M48389</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2025-04-29T10:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247617#M48390</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/79625"&gt;@arvindteemul1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Permanent Tunnels feature will send a UPD 18234 packet (tunnel testing) which is &lt;SPAN&gt;proprietary, so t&lt;/SPAN&gt;he FN gateway will not understand it. It may work just because of the traffic flow in the tunnel.&lt;/P&gt;
&lt;P&gt;What do the logs say?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?Highlight=Permanent" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?Highlight=Permanent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 11:18:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247617#M48390</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-04-29T11:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247618#M48391</link>
      <description>&lt;P&gt;Ah, fortiOS 7.6.x, lots of new features, but still feature release, so I would stick with 7.4, which is latest mature code : - )&lt;/P&gt;
&lt;P&gt;Anywho...make sure on Fortigate, setting auto keep alive is enabled and on CP exactly what the guys mentioned.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 12:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247618#M48391</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T12:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247623#M48392</link>
      <description>&lt;P&gt;Sounds like VPN timers are not the same on both sides. Would check p1 and p2 on both side and make sure they match.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you sure you run R81? and not R81.10 or R81.20? If so upgrade due EOL status&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 11:57:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247623#M48392</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-29T11:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247625#M48393</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 12:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247625#M48393</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-04-29T12:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247627#M48394</link>
      <description>&lt;P&gt;Always great sk to refer to, Don.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 12:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247627#M48394</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T12:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247641#M48395</link>
      <description>&lt;P&gt;On hour is default phase2 re-key timer (as &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;noted. &amp;nbsp;Be sure your implied rules enable VPN control connections and that you aren't trying to control IKE, IPsec, and (if applicable) NAT-T connections in your security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247641#M48395</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-29T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247650#M48396</link>
      <description>&lt;P&gt;thanks to all for your input...awaiting access to the firewall to check on the suggested items...will keep you posted!&lt;/P&gt;&lt;P&gt;On another note, while I'm cross referencing another firewall, I came across a typo in the Implied Policy section of R81.20, see attached:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 14:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247650#M48396</guid>
      <dc:creator>arvindteemul1</dc:creator>
      <dc:date>2025-04-29T14:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247652#M48397</link>
      <description>&lt;P&gt;Personally, I would never change those without checking with TAC first.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 14:35:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247652#M48397</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T14:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration between Check Point and FortiGate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247657#M48398</link>
      <description>&lt;P&gt;You have Remote Access control connections disabled. &amp;nbsp;This needs to be enabled for all of IPsec to function. &amp;nbsp;You also have Accept ICMP Requests enabled, which is not the default (and you almost certainly do not want this). &amp;nbsp;Someone has modified these implied rules in the past. &amp;nbsp;You should review the defaults again and re-align these.. &amp;nbsp;Here's a screenshot from sk179346.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/sc/SolutionsStatics/sk179346/implied%20rules202205261210461.png" target="_blank"&gt;https://sc1.checkpoint.com/sc/SolutionsStatics/sk179346/implied%20rules202205261210461.png&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 14:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Configuration-between-Check-Point-and-FortiGate/m-p/247657#M48398</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-29T14:56:37Z</dc:date>
    </item>
  </channel>
</rss>

