<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN is UP, but the VPN traffic is sent in clear although the traffic matches all community criteria in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105865#M8398</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a strange issue with my S2S VPN between my R80.40 3600 cluster and Cisco ASA device. The tunnels is established and I see encrypted traffic coming from remote end, but the traffic sent in opposite way from the CheckPoint to ASA is sent as a clear text. I am positive that my traffic matches all community criteria.&lt;/P&gt;&lt;P&gt;I am doing Manual hide NAT for outgoing traffic from CheckPoint to ASA. Here are the details about relevant networks:&lt;/P&gt;&lt;P&gt;My office LAN networks are source NATed to 172.21.230.5 (hide NAT)&lt;/P&gt;&lt;P&gt;Remote subnets are 192.168.15.25/32 192.168.15.26/32 an 192.168.1.34/32&lt;/P&gt;&lt;P&gt;When I try ping or telnet to remote end 192.168.15.25, the traffic is going out as unencrypted on my external interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# vpn tu tlist&lt;/P&gt;&lt;P&gt;+-----------------------------------------+-----------------------+---------------------+&lt;BR /&gt;| Peer: x.x.x.x - VPN_FZO_GW | MSA: 7fe3df728cd8 | i: 1 ref: 1 |&lt;BR /&gt;| Methods: ESP Tunnel PFS AES-256 SHA1 g..| | i: 2 ref: 2 |&lt;BR /&gt;| My TS: 172.21.230.0/28 | | |&lt;BR /&gt;| Peer TS: 192.168.15.25 | | |&lt;BR /&gt;| MSPI: 100001e (i: 2, p: 0) | Out SPI: 73a8ce4f | |&lt;BR /&gt;| Tunnel created: Dec 18 16:11:31 | | |&lt;BR /&gt;| Tunnel expiration: Dec 19 00:11:31 | | |&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;/P&gt;&lt;P&gt;(2) Site-to-Site tunnels are up:&lt;BR /&gt;IPSEC 2&lt;BR /&gt;NAT-T 0&lt;/P&gt;&lt;P&gt;(0) Clients Are Connected:&lt;BR /&gt;NAT-T 0&lt;BR /&gt;Visitor Mode 0&lt;BR /&gt;SSL 0&lt;BR /&gt;L2TP 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 15:33:14 GMT</pubDate>
    <dc:creator>MladenAntesevic</dc:creator>
    <dc:date>2020-12-18T15:33:14Z</dc:date>
    <item>
      <title>VPN is UP, but the VPN traffic is sent in clear although the traffic matches all community criteria</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105865#M8398</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a strange issue with my S2S VPN between my R80.40 3600 cluster and Cisco ASA device. The tunnels is established and I see encrypted traffic coming from remote end, but the traffic sent in opposite way from the CheckPoint to ASA is sent as a clear text. I am positive that my traffic matches all community criteria.&lt;/P&gt;&lt;P&gt;I am doing Manual hide NAT for outgoing traffic from CheckPoint to ASA. Here are the details about relevant networks:&lt;/P&gt;&lt;P&gt;My office LAN networks are source NATed to 172.21.230.5 (hide NAT)&lt;/P&gt;&lt;P&gt;Remote subnets are 192.168.15.25/32 192.168.15.26/32 an 192.168.1.34/32&lt;/P&gt;&lt;P&gt;When I try ping or telnet to remote end 192.168.15.25, the traffic is going out as unencrypted on my external interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# vpn tu tlist&lt;/P&gt;&lt;P&gt;+-----------------------------------------+-----------------------+---------------------+&lt;BR /&gt;| Peer: x.x.x.x - VPN_FZO_GW | MSA: 7fe3df728cd8 | i: 1 ref: 1 |&lt;BR /&gt;| Methods: ESP Tunnel PFS AES-256 SHA1 g..| | i: 2 ref: 2 |&lt;BR /&gt;| My TS: 172.21.230.0/28 | | |&lt;BR /&gt;| Peer TS: 192.168.15.25 | | |&lt;BR /&gt;| MSPI: 100001e (i: 2, p: 0) | Out SPI: 73a8ce4f | |&lt;BR /&gt;| Tunnel created: Dec 18 16:11:31 | | |&lt;BR /&gt;| Tunnel expiration: Dec 19 00:11:31 | | |&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;/P&gt;&lt;P&gt;(2) Site-to-Site tunnels are up:&lt;BR /&gt;IPSEC 2&lt;BR /&gt;NAT-T 0&lt;/P&gt;&lt;P&gt;(0) Clients Are Connected:&lt;BR /&gt;NAT-T 0&lt;BR /&gt;Visitor Mode 0&lt;BR /&gt;SSL 0&lt;BR /&gt;L2TP 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 15:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105865#M8398</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-12-18T15:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is UP, but the VPN traffic is sent in clear although the traffic matches all community crite</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105866#M8399</link>
      <description>&lt;P&gt;Looks like it is treated internal traffic on screenshot ! Which rule is matched and how is the encryption domain defined ?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 15:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105866#M8399</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-12-18T15:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is UP, but the VPN traffic is sent in clear although the traffic matches all community crite</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105874#M8403</link>
      <description>&lt;P&gt;If you do a NAT on your internal network for the VPN you have to include the original source in the encryption domain as well.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 17:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105874#M8403</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2020-12-18T17:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is UP, but the VPN traffic is sent in clear although the traffic matches all community crite</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105923#M8421</link>
      <description>&lt;P&gt;Thanks guys,&lt;/P&gt;&lt;P&gt;I just have included my original sources in the encryption domain for the VPN and the traffic is now correctly encrypted. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 09:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-UP-but-the-VPN-traffic-is-sent-in-clear-although-the/m-p/105923#M8421</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-12-19T09:20:55Z</dc:date>
    </item>
  </channel>
</rss>

