<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S2S VPN problems continue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265299#M60787</link>
    <description>&lt;P&gt;I've been working on a site to site VPN to a Palo Alto recently, that needs to be certificate based.&lt;/P&gt;&lt;P&gt;We have finally made progress, but now have a very unusual situation, or at least it's unusual to me, but I'm hoping someone else has come across this before!&lt;/P&gt;&lt;P&gt;From the PA end, a ping brings up the tunnel, but from the Checkpoint end a ping does not bring up the tunnel, it gives an authentication failure!&lt;/P&gt;&lt;P&gt;I'm sure this must be related to the certificate but I don't know why.&lt;/P&gt;&lt;P&gt;Has anyone else seen this before I raise it with TAC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Dec 2025 13:38:32 GMT</pubDate>
    <dc:creator>StevePearson</dc:creator>
    <dc:date>2025-12-15T13:38:32Z</dc:date>
    <item>
      <title>S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265299#M60787</link>
      <description>&lt;P&gt;I've been working on a site to site VPN to a Palo Alto recently, that needs to be certificate based.&lt;/P&gt;&lt;P&gt;We have finally made progress, but now have a very unusual situation, or at least it's unusual to me, but I'm hoping someone else has come across this before!&lt;/P&gt;&lt;P&gt;From the PA end, a ping brings up the tunnel, but from the Checkpoint end a ping does not bring up the tunnel, it gives an authentication failure!&lt;/P&gt;&lt;P&gt;I'm sure this must be related to the certificate but I don't know why.&lt;/P&gt;&lt;P&gt;Has anyone else seen this before I raise it with TAC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 13:38:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265299#M60787</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T13:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265300#M60788</link>
      <description>&lt;P&gt;Interesting issue Steve. Any relevant logs in smart console ot just says authentication failure?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 13:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265300#M60788</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T13:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265301#M60789</link>
      <description>&lt;P&gt;Nothing relevant I can see, just authentication failed in the vpn debugs, and in the PA logs too!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 13:42:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265301#M60789</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T13:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265303#M60790</link>
      <description>&lt;P&gt;Just curious, is it set as permanent tunnel on CP side? IM referring to this setting:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32433iD38105A752BF233B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 13:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265303#M60790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T13:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265306#M60791</link>
      <description>&lt;P&gt;No it's not set to permanent, and it's set to one tunnel per subnet pair.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 13:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265306#M60791</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T13:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265309#M60792</link>
      <description>&lt;P&gt;K, fair enough, probably not overly relevant here. What do you see if you search logs in smart console, just filter for community name, thats it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Like below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32435i1565264362567CBC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 14:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265309#M60792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T14:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265320#M60793</link>
      <description>&lt;P&gt;I get a repeating pattern of key installs and rejections (Auth failure):&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sshot1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32437i895E31077D58647D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sshot1.png" alt="Sshot1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Reject.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32438iD8D926971F2C8B0E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Reject.png" alt="Reject.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Key Install.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32439i8E4458D07D409477/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Key Install.png" alt="Key Install.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 14:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265320#M60793</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T14:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265321#M60794</link>
      <description>&lt;P&gt;Thats typical message people would see, but really begs the question why it gets rejeced...is tunnel showing as UP or keeps getting reset constantly?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 15:04:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265321#M60794</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T15:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265322#M60795</link>
      <description>&lt;P&gt;I don't see the tunnel as up in SmartView Monitor at all, vpn tu confirms this.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 15:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265322#M60795</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T15:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265324#M60796</link>
      <description>&lt;P&gt;I really have a gut feeling its something related to the cert on CP side. Are you able to send some screenshots of how its configured? Please blur out any sensitive data.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 16:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265324#M60796</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T16:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265330#M60797</link>
      <description>&lt;P&gt;I tend to agree, but can't see what!&lt;/P&gt;&lt;P&gt;The interoperable device has the community listed with matching criteria, but there is not much else to configure.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interop.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32442i2E38B62E26C3E30C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Interop.png" alt="Interop.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;They provided their CA and sub ordinate certs and I created objects for them. I then created the CSR using the sub ordinate, sent it to them to sign, and completed using the returned file. So the certificate is listed in the grid of available certs under the IPSEC VPN tab of the cluster.&lt;/P&gt;&lt;P&gt;What bothers me is that the matching criteria say that the gateway must present a certificate issued by the named CA, which suggests this is for incoming connections, and maybe I need to do something more for outgoing connections (which is whats failing)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 17:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265330#M60797</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T17:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265332#M60798</link>
      <description>&lt;P&gt;Might be worth TAC case...hard to say for sure without doing remote.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 17:00:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265332#M60798</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T17:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265334#M60799</link>
      <description>&lt;P&gt;Yeah, thats were I was heading but this customer has collaborative support which takes a lot longer to get raised.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 17:03:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265334#M60799</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-15T17:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265344#M60800</link>
      <description>&lt;P&gt;In the meantime, maybe check this link, just to make sure the steps were followed.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/td-p/73299" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/td-p/73299&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 19:32:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265344#M60800</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T19:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265348#M60801</link>
      <description>&lt;P&gt;I also attached a doc I got from community while ago about this.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 19:45:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265348#M60801</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-15T19:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265398#M60802</link>
      <description>&lt;P&gt;Thanks Andy, I've had a look at this and the previous link. The link refers to CP to Cp connections so nothing much in there, but this document is interesting. It details adding topology on the Interop device, which I've never had to do in the past but may be worth a try!&lt;/P&gt;&lt;P&gt;I've also had info back from the PA end, the error they are seeing is "RSA_verify failed on 256 bytes sig using SHA256", It then falls back to SHA1&amp;nbsp; and fails again in the same way.&lt;/P&gt;&lt;P&gt;I've opened a ticket with collaborative support now to see what they come up with.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 09:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265398#M60802</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-16T09:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265407#M60803</link>
      <description>&lt;P&gt;Just wondering...is it possible certificate itself might be using wrong auth methods?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 11:49:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265407#M60803</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T11:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265417#M60804</link>
      <description>&lt;P&gt;Hello Steve,&lt;/P&gt;
&lt;P&gt;Your configuration looks good to me. Were you able to collect a debug during the failed negotiation? you can check the certificates you send with ikeview utility and there you will know if the issue is on CP or PA side. The file you must open on ikeview changes depending on the version of IKE and version of the gateway. See sk30994&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30994" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30994&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 13:17:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265417#M60804</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-12-16T13:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265438#M60805</link>
      <description>&lt;P&gt;I didn't think so as it works when initiated from the PA end&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 15:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265438#M60805</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2025-12-16T15:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN problems continue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265439#M60806</link>
      <description>&lt;P&gt;Might be worth simple vpn debug:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;fw ctl debug 0&lt;/P&gt;
&lt;P&gt;Look for vpnd and iked* files in $FWDIR/log dir&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 15:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-problems-continue/m-p/265439#M60806</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T15:29:24Z</dc:date>
    </item>
  </channel>
</rss>

