<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phase 2 Site-to-site VPN error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262688#M51559</link>
    <description>&lt;P&gt;3120, we are hobbling along though we just re-negotiate every 2 minutes.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Nov 2025 20:30:45 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2025-11-12T20:30:45Z</dc:date>
    <item>
      <title>Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124158#M17881</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I have a Site-to-site VPN configured between checkpoint and cisco ASA.&lt;BR /&gt;When I check through SmartView Monitor, I see that my tunnel is up.&lt;/P&gt;&lt;P&gt;But when I start communication, the first phase goes well, but on the second phase I receive a message&lt;/P&gt;&lt;P&gt;Child SA exchange: Received notification from peer: No proposal chosen MyMethods Phase2: AES-256 + HMAC-SHA2-256, No IPComp, No ESN, Group 14&lt;/P&gt;&lt;P&gt;Please tell me what this means.&lt;BR /&gt;Because on my part exactly the same parameters are set.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.jpg" style="width: 499px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12703i8F700665D5F53738/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.jpg" alt="Screenshot_1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 06:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124158#M17881</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2021-07-16T06:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124171#M17882</link>
      <description>&lt;P&gt;The Log message and the screenshot you posted here both shows us the configuration on Check Point side.&lt;/P&gt;
&lt;P&gt;You have to compare it with the configuration on Cisco side.&lt;/P&gt;
&lt;P&gt;Either ask the Cisco admin on the other side what is configured there or better check it yourself by checking the debug logs.&lt;/P&gt;
&lt;P&gt;If you can force the Cisco side to initiate the connection, the debug logs on Check Point side will show you what the ASA is trying to do:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Start debug on Expert Shell: # vpn debug trunc&lt;/LI&gt;
&lt;LI&gt;Let's the Cisco side initiate the tunnel (verify in Check Point Log that they really did try it).&lt;/LI&gt;
&lt;LI&gt;Stop debug on Expert Shell: # vpn debug off; vpn debug ikeoff&lt;/LI&gt;
&lt;LI&gt;Look at $FWDIR/log/ikev2.xmll with &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994" target="_self"&gt;IKEView&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 09:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124171#M17882</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-07-16T09:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124179#M17883</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1408"&gt;@Tobias_Moritz&lt;/a&gt;&amp;nbsp;has already mentioned. This points to the proposal on phase 2 to not be equal on the Check Point side as on the CISCO side.&lt;BR /&gt;&lt;BR /&gt;We know from the logs that Check Point is proposing:&lt;BR /&gt;&lt;SPAN&gt;AES-256 + HMAC-SHA2-256, PFS Group 14.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We don't know what the CISCO firewall on the other end has configured for phase 2. There seems to be a mismatch here.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;By doing the debug that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1408"&gt;@Tobias_Moritz&lt;/a&gt;&amp;nbsp;suggested you will most likely see whatever the CISCO is trying to use for its phase 2 negotiating and you will most likely see that something is off and you will have to correct it so both sides are on terms when it comes to whatever settings are being used for phase 2.&lt;BR /&gt;&lt;BR /&gt;If you are communicating with whoever is controlling the CISCO firewall you could always ask them for details on what they have configured for phase 2 / IP-sec encryption. Might it be that they are not using PFS? Might they be using different algorithms?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 10:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/124179#M17883</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2021-07-16T10:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252871#M49525</link>
      <description>&lt;P&gt;I have the same issue, it's been solved? And if so how?&lt;BR /&gt;I know it's old post but i'm ensure the same issue&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252871#M49525</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T16:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252884#M49527</link>
      <description>&lt;P&gt;You should start a new thread with all of your details so we can provide better context.&amp;nbsp;&lt;SPAN&gt;No proposal chosen is generally both sides are not agreeing on the same security ciphers.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 17:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252884#M49527</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-07-09T17:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252885#M49528</link>
      <description>&lt;P&gt;Hey bro, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp;, definitely better start a new thread, so we can assist you.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 18:21:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252885#M49528</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T18:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252908#M49541</link>
      <description>&lt;P&gt;No Proposal chosen means that both GWs cannot agree on the Phase 2 encryption algorithm and hence cannot set a symmetric key. It usually means that the Phase 2 settings list different algorithms.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I agree with a suggestion to open a different thread for your specific issue, so we could dig into the root cause properly in an independent discussion.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 08:10:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/252908#M49541</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T08:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262397#M51483</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you mention that reading “start the connection” once you have placed the debug commands, this way for the peer to start the connection, can it be through a VPN restart from your FW?&lt;/P&gt;
&lt;P&gt;I assume so, or am I mistaken?&lt;/P&gt;
&lt;P&gt;Or does starting a connection refer only to traffic from Phase 2 selectors?&lt;/P&gt;
&lt;P&gt;In a VSX, where is the debug result hosted? Is it kept in the same path as a traditional FW?&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 23:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262397#M51483</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-11-10T23:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262686#M51557</link>
      <description>&lt;P&gt;I'm having a similar issue and it's Turning out the cisco is proposing several groups, 21, 20, and 14.&amp;nbsp; That being said JHF99 was handling that ok, JHF118 is not.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 20:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262686#M51557</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-11-12T20:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262687#M51558</link>
      <description>&lt;P&gt;Really? Never heard of that before...Cisco asa or something else?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 20:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262687#M51558</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T20:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262688#M51559</link>
      <description>&lt;P&gt;3120, we are hobbling along though we just re-negotiate every 2 minutes.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 20:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262688#M51559</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-11-12T20:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262689#M51560</link>
      <description>&lt;P&gt;I know every time I dealt with Cisco TAC, they would always change those settings via ssh, never ASDM. Not sure if there is something in newer versions thats different, but when I dealt with Cisco VPNs 7-8 years ago, I never encountered that problem.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 20:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/262689#M51560</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T20:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/263239#M51678</link>
      <description>&lt;P&gt;The cisco engineer found the solution, an odd one.&amp;nbsp; TAC is reviewing this but unchecking this specific config to sent VTI ip address to the peers fixed it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn/route-based-ikev2-vpn-issue-between-cisco-ftd-and-checkpoint/td-p/5322472" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/vpn/route-based-ikev2-vpn-issue-between-cisco-ftd-and-checkpoint/td-p/5322472&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 21:44:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/263239#M51678</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-11-19T21:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Site-to-site VPN error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/263243#M51680</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 22:19:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Phase-2-Site-to-site-VPN-error/m-p/263243#M51680</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-19T22:19:15Z</dc:date>
    </item>
  </channel>
</rss>

