<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC to Fortigate in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228115#M59664</link>
    <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;I think we went through this last week, you still cant find that field in smb appliance? By the way, you should really be using ikev2, not ikev1.&lt;/P&gt;
&lt;P&gt;Just saying.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 15:58:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-26T15:58:11Z</dc:date>
    <item>
      <title>IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228113#M59663</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Good afternoon everyone, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I am stuck in a tunnel between Fortigate and Checkpoint Spark, phase 1 is not able to negotiate.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In this case, the Fortigate has a static public IP and the checkpoint has a blocked IP.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; At the checkpoint end we are configuring the Peer ID since I understand that it is common to use it in these scenarios but from the checkpoint I do not see how to enter this Peer&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ftg2.jpg" style="width: 686px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27829iC20D71401641D347/image-size/large?v=v2&amp;amp;px=999" role="button" title="ftg2.jpg" alt="ftg2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Please help me with this question, I am almost sure that this is why phase 1 is not working.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 15:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228113#M59663</guid>
      <dc:creator>GSecurity</dc:creator>
      <dc:date>2024-09-26T15:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228115#M59664</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;I think we went through this last week, you still cant find that field in smb appliance? By the way, you should really be using ikev2, not ikev1.&lt;/P&gt;
&lt;P&gt;Just saying.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 15:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228115#M59664</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-26T15:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228127#M59665</link>
      <description>&lt;P&gt;What is a blocked IP? What settings are under peer options? What does the log show in check point? local mgmt or central mgmt?&lt;/P&gt;
&lt;P&gt;Also change these encryption methods while you are at it. 3DES is not safe and a real performance killer, esp in p2.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Diffie-hellmangroup 14 atleast&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 16:43:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228127#M59665</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-26T16:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228137#M59666</link>
      <description>&lt;P&gt;&lt;SPAN&gt;These logs show me in the Fortigate firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ike 0:VPN-to-Puno:5057: sent IKE msg (P1_RETRANSMIT): 200.123.xx.xx:500-&amp;gt;38.25.17.199:40743, len=168, vrf=0, id=2a7536062b1a05e5/30120e08f9e90f75&lt;BR /&gt;ike 0: comes 38.25.17.199:40743-&amp;gt;200.123.xx.xx:500,ifindex=7,vrf=0....&lt;BR /&gt;ike 0: IKEv1 exchange=Informational id=2a7536062b1a05e5/30120e08f9e90f75:1f0fe142 len=40 vrf=0&lt;BR /&gt;ike 0: in 2A7536062B1A05E530120E08F9E90F750B1005001F0FE142000000280000000C0000000001000004&lt;BR /&gt;ike 0:VPN-to-Puno: HA state master(2)&lt;BR /&gt;ike 0:VPN-to-Puno:5057: ignoring unsupported INFORMATIONAL message 0.&lt;BR /&gt;ike 0:VPN-to-Puno:5057: out 2A7536062B1A05E530120E08F9E90F750110020000000000000000A80D00003800000001000000010000002C010100010000002401010000800100058002000480030001800B0001000C000400015180800400020D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000&lt;BR /&gt;ike 0:VPN-to-Puno:5057: sent IKE msg (P1_RETRANSMIT): 200.123.xx.xx:500-&amp;gt;38.25.17.199:40743, len=168, vrf=0, id=2a7536062b1a05e5/30120e08f9e90f75&lt;BR /&gt;ike 0: comes 38.25.17.199:40743-&amp;gt;200.123.xx.xx:500,ifindex=7,vrf=0....&lt;BR /&gt;ike 0: IKEv1 exchange=Informational id=2a7536062b1a05e5/30120e08f9e90f75:341962f8 len=40 vrf=0&lt;BR /&gt;ike 0: in 2A7536062B1A05E530120E08F9E90F750B100500341962F8000000280000000C0000000001000004&lt;BR /&gt;ike 0:VPN-to-Puno: HA state master(2)&lt;BR /&gt;ike 0:VPN-to-Puno:5057: ignoring unsupported INFORMATIONAL message 0.&lt;BR /&gt;ike ::ffff:104.140.188.58 truncated control message 0 16 0&lt;BR /&gt;ike 0:VPN-to-Puno:5057: negotiation timeout, deleting&lt;BR /&gt;ike 0:VPN-to-Puno: connection expiring due to phase1 down&lt;BR /&gt;ike 0:VPN-to-Puno: deleting&lt;BR /&gt;ike 0:VPN-to-Puno: deleted&lt;BR /&gt;ike shrank heap by 135168 bytes&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 17:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228137#M59666</guid>
      <dc:creator>GSecurity</dc:creator>
      <dc:date>2024-09-26T17:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228138#M59667</link>
      <description>&lt;P&gt;&lt;SPAN&gt;These are the phase 1 and 2 configurations for both ends&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 17:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228138#M59667</guid>
      <dc:creator>GSecurity</dc:creator>
      <dc:date>2024-09-26T17:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228144#M59668</link>
      <description>&lt;P&gt;From the screenshot I cannot see why it should not work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From security point of view. Enable PFS on both sides with minial diffiehellmangroup 14 or higher (not 2)&lt;/P&gt;
&lt;P&gt;Same please for p1. Second change the aes-128 to aes-256 on p1 and p2 and you are good.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do the logs show if you filter on remote public IP you see anything comming in?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 19:50:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228144#M59668</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-26T19:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228164#M59669</link>
      <description>&lt;P&gt;Do basic debugs on both ends.&lt;/P&gt;
&lt;P&gt;CP:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;check vpnd and ike files in $FWDIR/logs&lt;/P&gt;
&lt;P&gt;FGT:&lt;/P&gt;
&lt;P&gt;diag debug app ike -1&lt;/P&gt;
&lt;P&gt;diag debug enable&lt;/P&gt;
&lt;P&gt;-check what comes up on the screen, messages are usually easy to "decipher" as far as the issue&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955" target="_blank" rel="noopener"&gt;https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Just run di de di command once done, though on Fortigate thats usually not even needed to disable the debug, as they are so light, if you left them on for some time, nothing would happen to the box, though by default, they stop after 30 mins, just to save cpu/memory resources.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 01:48:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228164#M59669</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T01:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228197#M59670</link>
      <description>&lt;P&gt;This clearly tells you why its failing...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ike 0:VPN-to-Puno:5057: ignoring unsupported INFORMATIONAL message 0.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ike ::ffff:104.140.188.58 truncated control message 0 16 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ike 0:VPN-to-Puno:5057: negotiation timeout, deleting&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ike 0:VPN-to-Puno: connection expiring due to phase1 down&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 11:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228197#M59670</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T11:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228229#M59671</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107665"&gt;@GSecurity&lt;/a&gt;&amp;nbsp;Did you do debug on CP side?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228229#M59671</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T13:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC to Fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228252#M59672</link>
      <description>&lt;P&gt;I mean Check Point logs / debugs. These are far more superior &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 15:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IPSEC-to-Fortigate/m-p/228252#M59672</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-27T15:48:36Z</dc:date>
    </item>
  </channel>
</rss>

