<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN setup on a 5400 cluster with multiple external interfaces in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98389#M7645</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just have check it with tcpdump and everything is fine, I am sending and receiving ISAKMP IKE packets with correct source/destination address.&lt;/P&gt;&lt;P&gt;I am editing this reply, so to be more precise, src/dst IP address of our IKE message is fine, but inside the IKE MM5 message we have our PeerID set to wrong address, so instead of our MPLS interface, we have our Main Public Internet address set as a PeerID.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 12:14:07 GMT</pubDate>
    <dc:creator>MladenAntesevic</dc:creator>
    <dc:date>2020-10-08T12:14:07Z</dc:date>
    <item>
      <title>S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98341#M7640</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a cluster with more external interfaces, two interfaces are Internet peers and third external interface is connected to telecom MPLS service. I am trying do do S2S VPN setup from MPLS interface towards the remote Sophos Cyberoam device. Anyway, my tunnel is not coming UP although I checked all VPN parameters, I am suspecting it has something to do with this strange IKE behavior.&amp;nbsp; Other end device is Sophos Cyberoam device and it reports error message that we are using wrong PeerID, it sees our main Internet interface address as our PeerID instead of our MPLS interface address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 12:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98341#M7640</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-08T12:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98344#M7641</link>
      <description>&lt;P&gt;Need some basic information like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Version/JHF level&lt;/LI&gt;
&lt;LI&gt;What is the other end of the VPN exactly?&lt;/LI&gt;
&lt;LI&gt;What is your Link Selection setting for the cluster?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Also, I don't understand what you mean by "more external interfaces."&lt;BR /&gt;Please describe your configuration more precisely.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 23:38:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98344#M7641</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-06T23:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98370#M7643</link>
      <description>&lt;P&gt;Hello Phoneboy,&lt;/P&gt;&lt;P&gt;Here is my version:&amp;nbsp;R80.40,&amp;nbsp;OS build 294, take 78 on both cluster members.&lt;/P&gt;&lt;P&gt;I do not have exact information about the other end of VPN, it is a Sophos&amp;nbsp;Cyberoam device, I will try to get more detail information since it is a device from other organization.&lt;/P&gt;&lt;P&gt;Link Selection is left as default, I am sending screenshot with my settings. I have declared other end VPN gateway as interoperable device and it has the same Link selection settings.&lt;/P&gt;&lt;P&gt;I have three interfaces which are declared as external in my Network topology, two of them have public addresses and this third interface has private address and it is used for connecting to other organization over the MPLS VPN service. So, we are trying to establish S2S VPN over this third external interface. Besides these external interfaces, I have several interfaces declared as internal.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 07:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98370#M7643</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-07T07:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98380#M7644</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45729"&gt;@MladenAntesevic&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do a tcpdump/cppcap on your third external interface (MPLS) and have a look at the source and destination IPs of your IPSEC packets.&lt;/P&gt;
&lt;P&gt;I suggest to change the link selection to "IP address of chosen interface" in the source IP address settings. With this change the IP address of your MPLS interface should be use for connection to the Sophos device. The Sophos device should use your MPLS IP address as destination for the IPSEC tunnel.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 08:05:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98380#M7644</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-07T08:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98389#M7645</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just have check it with tcpdump and everything is fine, I am sending and receiving ISAKMP IKE packets with correct source/destination address.&lt;/P&gt;&lt;P&gt;I am editing this reply, so to be more precise, src/dst IP address of our IKE message is fine, but inside the IKE MM5 message we have our PeerID set to wrong address, so instead of our MPLS interface, we have our Main Public Internet address set as a PeerID.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 12:14:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98389#M7645</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-08T12:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98391#M7646</link>
      <description>&lt;P&gt;I see IKE Phase 1 is establishing, something is wrong with the Phase 2. I will try to verify the networks with the remote end administrator.&lt;/P&gt;&lt;P&gt;I am editing this reply, even Phase 1 is not establishing since PeerID address is set to wrong address.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 12:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98391#M7646</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-08T12:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98414#M7651</link>
      <description>&lt;P&gt;You need to find out precisely how the Sophos is configured as far as what networks (and their subnet masks) it is expecting from your gateway during the Phase 2 negotiation, as well as precisely what networks (and their subnet masks) the Sophos is providing to you, and then the per-community VPN domains settings to match the Sophos exactly as shown here (this is a new feature in R80.40):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNDomain.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8301i08C3CDD247A3EBDC/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPNDomain.png" alt="VPNDomain.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 12:10:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98414#M7651</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-10-07T12:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98425#M7652</link>
      <description>&lt;P&gt;Thanks for your advice. I have now arranged with remote administrator to do first setup with just one network on each side and I have configured VPN domains accordingly. I believe the problem is because remote device sees my public IP address as Peer ID instead of my private IP address from interface towards MPLS link.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 13:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98425#M7652</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-07T13:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98438#M7653</link>
      <description>&lt;P&gt;Right, you need to change VPN Link Selection from "Always use this address" to "Calculate IP based on network topology" to ensure your firewall uses the correct source address.&amp;nbsp; Making this change should not disrupt your existing Internet VPNs but you may want to make the change outside regular business hours, and immediately reset all Site-To-Site VPNs with &lt;STRONG&gt;vpn tu&lt;/STRONG&gt;&amp;nbsp;(option 0) to ensure they will come back properly with the new setting.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 13:58:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98438#M7653</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-10-07T13:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98481#M7658</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have done it just as you described, followed by resetting all VPNS, but my problematic VPN is still down. I have noticed one interesting thing, I have declared 192.168.70.21/32 as my local network, as you described above, but when I list the tunnels with the vpn tu tlist command, it is showing the complete subnet 192.168.70.0/24 as a local TS, which is very strange, here it is:&lt;/P&gt;&lt;P&gt;[Expert@CP2:0]# vpn tu tlist&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;BR /&gt;| Peer: xx.xx.xx.x - VPN_GW_P1 | MSA: ffffc900a1e14128 | i: 0 ref: 1 |&lt;BR /&gt;| Methods: ESP Tunnel PFS AES-128 SHA1 g..| | i: 1 ref: 1 |&lt;BR /&gt;| My TS: 192.168.70.0/24 | | |&lt;BR /&gt;| Peer TS: x.x.x.x | | |&lt;BR /&gt;| MSPI: 8000ad (i: 1, p: 0) | No outbound SA | |&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 22:14:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98481#M7658</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-07T22:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98547#M7670</link>
      <description>&lt;P&gt;We have tried everything, trying all possible settings from the Link Selection menu, we have tried different option from both Global Link Selection menu and Link Selection menu from the Interoperable device but without any success. We have performed IKE debug for all scenarios and PeerID is always set to our Internet address instead of our MPLS interface. We see from our IKE debug that once remote end detect wrong PeerID address, the negotiation immediately fails.&lt;/P&gt;&lt;P&gt;One more fact to know, we are using L2 MPLS service, so remote Sophos Cyberoam device IP address is in the same subnet as our MPLS interface address. Is there any option to set our PeerID to address of outgoing interface during the Phase1 IKE negotiation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 12:05:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98547#M7670</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-08T12:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98553#M7672</link>
      <description>&lt;P&gt;Yes, see scenario 2 of this SK:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with 3rd &lt;STRONG&gt;party&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 13:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98553#M7672</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-10-08T13:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN setup on a 5400 cluster with multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98685#M7697</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;excellent, this was very valuable information for us, after appending SenderIP into gateways registry our tunnel went UP. Seems that remote Cyberoam device is checking value of this field in order to do key install. Thank you very much for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 21:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-setup-on-a-5400-cluster-with-multiple-external/m-p/98685#M7697</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-10-09T21:04:21Z</dc:date>
    </item>
  </channel>
</rss>

