<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/253113#M49604</link>
    <description>&lt;P&gt;Hi, the tunnel is now authenticated from the changes you suggested on both CP and Fortigates side, now Fortigate just needs to allow the traffic through the firewall haha&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2025 14:28:31 GMT</pubDate>
    <dc:creator>Sph1nX</dc:creator>
    <dc:date>2025-07-14T14:28:31Z</dc:date>
    <item>
      <title>Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252221#M49387</link>
      <description>&lt;P&gt;Good Day,&lt;BR /&gt;&lt;BR /&gt;I am struggling with an IPsec Tunnel between a CP device and a Fortinet device, Using AES-256, SHA256 and Group19 for both Phase 1 and Phase 2 encryption yet get the above error. First time I am doing an IPsec tunnel between the two devices would anyone be able to advise me as to what the problems could be&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 08:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252221#M49387</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-06-30T08:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252458#M49413</link>
      <description>&lt;P&gt;This usually points to a mismatch in configuration.&lt;BR /&gt;Refer to #11 here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181787" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181787&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 17:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252458#M49413</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-02T17:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252466#M49419</link>
      <description>&lt;P&gt;Do you even see phase 1 completing? You can check that via vpn tu on CP and from gui on Fortigate. Debugs you can do. I would still double check to make sure all settings do match, but debug would 100% confirm that. If it fails phase 1, depending where, it could be PSK issue or basic settings are mismatched. If phase 2, than most likely vpn domains.&lt;/P&gt;
&lt;P&gt;CP:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;get iked and vpnd files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Fortigate:&lt;/P&gt;
&lt;P&gt;di de di&lt;/P&gt;
&lt;P&gt;di de application ike -1&lt;/P&gt;
&lt;P&gt;di de en&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 17:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252466#M49419</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-02T17:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252824#M49503</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Encryption groups are configured the same but get the below&lt;BR /&gt;457126603; 9Jul2025 10:45:01.279891;[kern];[tid_1];[SIM-241580892];sim (vpn_encrypt): drop due vpn_ipsec_encrypt returns PKT_DROP(3);&lt;BR /&gt;457126603; 9Jul2025 10:45:01.279897;[kern];[tid_1];[SIM-241580892];handle_vpn_encryption: ipsec_encrypt failed: failed to find SA. Dropping packet;&lt;BR /&gt;457126605; 9Jul2025 10:45:01.279902;[kern];[tid_1];[SIM-241580892];sim_pkt_send_drop_notification: (0,1) received drop, reason: Encryption Failed, conn;&lt;BR /&gt;457126605; 9Jul2025 10:45:01.279907;[kern];[tid_1];[SIM-241580892];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn;&lt;BR /&gt;457126605; 9Jul2025 10:45:01.279911;[kern];[tid_1];[SIM-241580892];sim_pkt_send_drop_notification: sending single drop notification, conn;&lt;BR /&gt;457126606; 9Jul2025 10:45:01.279917;[kern];[tid_1];[SIM-241580892];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 09:21:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252824#M49503</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T09:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252833#M49507</link>
      <description>&lt;P&gt;The Check Point "traffic selectors unacceptable" message should include the networks it is sending to the Fortinet, see the highlighted section below. Do the networks in that message match on the Fortinet side? If not, that is the problem.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CheckPoint_TS.png" style="width: 567px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30914iC8A899F19A2E1BBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="CheckPoint_TS.png" alt="CheckPoint_TS.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;How do you have the addresses setup on the Fortinet side for Phase 2 selectors? Do you have it configured as "IP Address" or "Subnet"? You have to have the tunnel sharing mode setup on the Check Point side to match. Ideally you should be defining a subnet for the Fortinet Phase 2 selector and using the Check Point "One VPN tunnel per subnet pair" option for tunnel sharing.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:59:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252833#M49507</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-07-09T12:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252834#M49508</link>
      <description>&lt;P&gt;What CP device is that ? GAiA ? Version ? Jumbo ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252834#M49508</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-09T13:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252836#M49509</link>
      <description>&lt;P&gt;Have it configured as IP's on the Fortigates side, One VPN tunnel per subnet pair. No Message comes up on the Fortigate side with Traffic selectors being a problem only on Checkpont side&lt;BR /&gt;&lt;BR /&gt;I get a lot on MyTSi and some on Peer TSr, we did try and configure the ones missing on the Fortinet side but just added more on their side after doing so&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252836#M49509</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T13:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252838#M49510</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Check Point 3800, GAiA, Build 335, Kernel 3.10.0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252838#M49510</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T13:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252839#M49511</link>
      <description>&lt;P&gt;R81.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:17:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252839#M49511</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T13:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252840#M49512</link>
      <description>&lt;P&gt;Setting them as IP addresses on the Fortigate side means you need to use the Check Point VPN tunnel sharing mode as "One VPN tunnel per each pair of hosts". You will also need to make sure that those IP addresses are defined as hosts within your Check Point VPN domain.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:19:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252840#M49512</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-07-09T13:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252841#M49513</link>
      <description>&lt;P&gt;What do you see on Fortigate side?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252841#M49513</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T13:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252843#M49515</link>
      <description>&lt;P&gt;The traffic is coming through on their side so they can see the ping request coming through and no errors show up&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:26:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252843#M49515</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T13:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252850#M49517</link>
      <description>&lt;P&gt;I have changed it to One VPN tunnel per each pair of hosts, but also see that there was no VPN domain setup, I took over from the last guy and he wasn't motivated to continue with it so it wasn't completed when he left so now left with trying to get this working&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 13:41:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252850#M49517</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T13:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252852#M49518</link>
      <description>&lt;P&gt;Is it combo of hosts/subnets? If so, then choose per gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252852#M49518</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T14:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252854#M49519</link>
      <description>&lt;P&gt;I know the Fortigate side has /32s and CP side has /24&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252854#M49519</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T14:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252858#M49521</link>
      <description>&lt;P&gt;Thats fine, then choose subnets on CP side and on Fortigate, you dont need to do universal tunnel, just do whatever hosts needed. I attached an example, you can just keep adding needed entries.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252858#M49521</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T14:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252860#M49522</link>
      <description>&lt;P&gt;Just want to confirm that they need to config the MyTSi from CP side onto the fortigate side is that correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252860#M49522</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-09T14:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252861#M49523</link>
      <description>&lt;P&gt;Did you review&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;? Had a Forti once where the customer had to exclude WAN GW IP from Enc Domain to make it work. I would ask CP TAC for help!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:34:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252861#M49523</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-09T14:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252863#M49524</link>
      <description>&lt;P&gt;They do, yes. It has to match 100%, otherwise, it wont work.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/252863#M49524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T14:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/253088#M49587</link>
      <description>&lt;P&gt;This is what I can get from the Fortinet side, I see the SA=1 which refers to traffic selectors being acceptable but still doesn't pass through to either side&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 11:54:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Child-SA-exchange-Sending-notification-to-peer-Traffic-selectors/m-p/253088#M49587</guid>
      <dc:creator>Sph1nX</dc:creator>
      <dc:date>2025-07-14T11:54:55Z</dc:date>
    </item>
  </channel>
</rss>

