<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with site Certificate Based VPNs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250165#M48857</link>
    <description>&lt;P&gt;Curious... what do you mean by "after a while"? &amp;nbsp;What time interval (be as precise as you can) is this?&lt;/P&gt;
&lt;P&gt;I'll hazard a guess, however: if it's 1 hour, then this is an IPsec phase 2 re-key issue. &amp;nbsp;Make sure you have the VPN control connections enabled in your Global Properties, or be certain to have IPsec NAT-Traversal (UDP 4500) allowed in your ruleset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2025 15:20:24 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2025-05-29T15:20:24Z</dc:date>
    <item>
      <title>Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250077#M48848</link>
      <description>&lt;P&gt;We currently utilize &lt;SPAN class=""&gt;certificate&lt;/SPAN&gt; &lt;SPAN class=""&gt;based&lt;/SPAN&gt; &lt;SPAN class=""&gt;VPNs&lt;/SPAN&gt; between our main cluster and Fortinet and Starlink appliances.&lt;BR /&gt;These devices are installed on moving devices.&lt;/P&gt;&lt;P&gt;We see that the VPNs are established but after a while they go down and we were in logs the different types of errors:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Main mode local machine configured not to responde to unknow IP address and or not included in the remoteaccess community"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"VPN failed to resolve gateway IP address"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;We analyzed the SK related to these issues but we understand that they do not apply to this case.&lt;/P&gt;&lt;P&gt;We were also surprised to see inconsistencies in the IPs we had in the established tunnels when we consulted them through the VPN tu tlist command.&lt;/P&gt;&lt;P&gt;Does anyone have any suggestion of what we could analyze?&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 18:52:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250077#M48848</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2025-05-28T18:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250083#M48849</link>
      <description>&lt;P&gt;What is the sk?&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 19:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250083#M48849</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-28T19:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250086#M48850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SK are&amp;nbsp;sk132332,&amp;nbsp;sk119301 and&amp;nbsp;&lt;SPAN&gt;sk117713&amp;nbsp;but none of them apply to our case&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 19:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250086#M48850</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2025-05-28T19:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250094#M48851</link>
      <description>&lt;P&gt;I assume these "moving devices" are Dynamic IP.&lt;BR /&gt;Are the necessary interoperable objects defined as such?&lt;/P&gt;
&lt;P&gt;One issue with DAIP VPN endpoints is that we don't know what IP address they're coming from.&lt;BR /&gt;In the case of a Check Point-managed gateway, most likely there is a persistent connection with management that we can use to determine the remote IP to use.&lt;BR /&gt;In the case of interoperable objects, we don't have such a mechanism and can only use traffic initiated from the remote VPN to learn about the IP in use.&lt;/P&gt;
&lt;P&gt;I assume the errors occur when the IP association "times out" due to inactivity.&lt;BR /&gt;The fix for this is likely to have something periodically generate traffic through the VPN tunnel to keep it (and the IP association) active.&lt;BR /&gt;We have a mechanism called&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181994" target="_self"&gt;network probe&lt;/A&gt;&amp;nbsp;to do this periodically starting in R82.&lt;BR /&gt;If on an earlier release, some other host will need to periodically generate traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 20:29:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250094#M48851</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-28T20:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250165#M48857</link>
      <description>&lt;P&gt;Curious... what do you mean by "after a while"? &amp;nbsp;What time interval (be as precise as you can) is this?&lt;/P&gt;
&lt;P&gt;I'll hazard a guess, however: if it's 1 hour, then this is an IPsec phase 2 re-key issue. &amp;nbsp;Make sure you have the VPN control connections enabled in your Global Properties, or be certain to have IPsec NAT-Traversal (UDP 4500) allowed in your ruleset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 15:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250165#M48857</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-05-29T15:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250626#M49009</link>
      <description>&lt;P&gt;Hello PhoneBoy&lt;BR /&gt;Thank you very much for your response. We're using DAIP in this case to use certificates.&lt;BR /&gt;I asked you, would DPD also be a viable option, or would the survey you mentioned earlier only work for us in this case?&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 16:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250626#M49009</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2025-06-04T16:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250639#M49013</link>
      <description>&lt;P&gt;DPD will definitely help here.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 20:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250639#M49013</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-04T20:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with site Certificate Based VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250643#M49015</link>
      <description>&lt;P&gt;Implementing DPD definitely won't hurt here.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 20:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-site-Certificate-Based-VPNs/m-p/250643#M49015</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-04T20:54:57Z</dc:date>
    </item>
  </channel>
</rss>

