<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN &amp; fwconn_key_init_links (OUTBOUND) failed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9717#M548</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are working on a migration project and we are facing a strange issue.&lt;/P&gt;&lt;P&gt;The architecture is quite simple :&lt;/P&gt;&lt;P&gt;- Cluster of 5800 appliances, R80.10 + jumbo 154&lt;/P&gt;&lt;P&gt;- Management is a R80.10 VM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything seems fine except VPN. Only 4 VPN amongs 7 are working. Not always the same, but never more than 4.&lt;/P&gt;&lt;P&gt;For the failed VPNs, we've discovered that outgoing IKE packet are dropped by the active member :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;[cpu_7];[fw4_0];fw_log_drop_ex: Packet proto=17 a.a.a.a:500 -&amp;gt; b.b.b.b:500 dropped by fw_conn_post_inspect Reason: fwconn_key_init_links (OUTBOUND) failed;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a.a.a.a : cluster IP&lt;/P&gt;&lt;P&gt;b.b.b.b : peer IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have contacted the TAC and they've collected multiples captures. For now, nobody seems to be able to explain why the gateway drops its own IKE packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to TAC, sk124732 doesn't applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone knows what "fwconn_key_init_links (OUTBOUND) failed" could means ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Nov 2018 21:42:45 GMT</pubDate>
    <dc:creator>Benoit_Verove</dc:creator>
    <dc:date>2018-11-27T21:42:45Z</dc:date>
    <item>
      <title>VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9717#M548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are working on a migration project and we are facing a strange issue.&lt;/P&gt;&lt;P&gt;The architecture is quite simple :&lt;/P&gt;&lt;P&gt;- Cluster of 5800 appliances, R80.10 + jumbo 154&lt;/P&gt;&lt;P&gt;- Management is a R80.10 VM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything seems fine except VPN. Only 4 VPN amongs 7 are working. Not always the same, but never more than 4.&lt;/P&gt;&lt;P&gt;For the failed VPNs, we've discovered that outgoing IKE packet are dropped by the active member :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;;[cpu_7];[fw4_0];fw_log_drop_ex: Packet proto=17 a.a.a.a:500 -&amp;gt; b.b.b.b:500 dropped by fw_conn_post_inspect Reason: fwconn_key_init_links (OUTBOUND) failed;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a.a.a.a : cluster IP&lt;/P&gt;&lt;P&gt;b.b.b.b : peer IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have contacted the TAC and they've collected multiples captures. For now, nobody seems to be able to explain why the gateway drops its own IKE packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to TAC, sk124732 doesn't applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone knows what "fwconn_key_init_links (OUTBOUND) failed" could means ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2018 21:42:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9717#M548</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-11-27T21:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9718#M549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error message seems to be NAT related, specifically when the attempt to NAT fails for one reason or another.&lt;/P&gt;&lt;P&gt;It comes up here (among other places):&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk124732" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk124732"&gt;Traffic is not NATed correctly&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2018 04:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9718#M549</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-28T04:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9719#M550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the hint. Indeed something seems to go wrong with NAT. I will also check if the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk41916&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk41916&lt;/A&gt; might applied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benoit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2018 08:28:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9719#M550</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-11-28T08:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9720#M551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also make sure it is not the backup firewall sending out packets through the primary.&lt;/P&gt;&lt;P&gt;This is something we see a lof if people start to monitor both firewalls with SNMP over the VPN connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2018 09:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9720#M551</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-11-28T09:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9721#M552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We finaly solved our issue. It was a simple NAT rules that was conflicting with IKE trafic.... Rebuilding a narrowed NAT rule, and all the VPN came up !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benoit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 14:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/9721#M552</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-12-11T14:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/214995#M41073</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How did you resolved? My customer is using a openserver cluster with R80.40 take 161 and we have an issue related to VPN Site-to-site. The tunnel is established but during the day, some times the tunnel is disconnected and come up later. We´ve tried some configurations to avoid it but the tunnel still come down few times on the day.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 12:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-fwconn-key-init-links-OUTBOUND-failed/m-p/214995#M41073</guid>
      <dc:creator>jslima</dc:creator>
      <dc:date>2024-05-22T12:40:41Z</dc:date>
    </item>
  </channel>
</rss>

