<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN is going down in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58804#M84843</link>
    <description>&lt;P&gt;The issue is that the tunnel goes down but even with interesting traffic is not coming up. WE need to renegotiate the tunnel in order to go up again.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2019 11:28:12 GMT</pubDate>
    <dc:creator>Jesus_Cano</dc:creator>
    <dc:date>2019-07-23T11:28:12Z</dc:date>
    <item>
      <title>VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58789#M84837</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We Just configured a VPN between Checkpoint R80.10 and Fortigate. The VPN is up and traffic is flowing. The issue is that sometime the tunnel stop processing traffic and we need to renew in order to work again. So why the tunnel goes down? its because inactivity?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 07:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58789#M84837</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-23T07:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58794#M84838</link>
      <description>&lt;P&gt;This is diffcult to diagnose without seeing the full VPN configuration of both the CheckPoint and Fortigate.&lt;/P&gt;&lt;P&gt;Checkpoint uses DPD and I believe Fortigate uses Auto Keep Alive so, even if these are configured and working, dropping the tunnel due to inactivity may not be the problem.&lt;/P&gt;&lt;P&gt;Before you go to deep into troubleshooting, however, one thing I would ask you to check is the LifeTimes on the CheckPoint side for Phase I and Phase II match the Fortigate side and that on the Fortigate side, the Phase II KeyLife is set to &lt;STRONG&gt;Seconds&lt;/STRONG&gt; and &lt;STRONG&gt;not&lt;/STRONG&gt; "KiloBytes" or "Both" . If the Fortigate is using KiloBytes as the key life time, it could try to create new keys before the CheckPoint is ready. This makes the re-key unpredictable as it's dependent on how much data has been processed in any given time period.&lt;/P&gt;&lt;P&gt;If one side tries to regenerate keys before the other side is ready you will have problems with the tunnel.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 11:34:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58794#M84838</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-23T11:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58795#M84839</link>
      <description>&lt;P&gt;Where its configured DPD in R80.10, i can not find this config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 10:44:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58795#M84839</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-23T10:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58797#M84840</link>
      <description>Sorry - I'm calling it DPD out of old habits. It's Permanent Tunnels in Tunnel Management.</description>
      <pubDate>Tue, 23 Jul 2019 10:52:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58797#M84840</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-23T10:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58798#M84841</link>
      <description>&lt;P&gt;OK, but i read that permanent tunnels is only working between Checkpoint appliances. In this case one is CPK and the peer is fortigate.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 10:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58798#M84841</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-23T10:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58800#M84842</link>
      <description>So if Permanent Tunnels are not configured on the CheckPoint (and you've not configured DPD Responder Mode for permanent tunnels to 3rd party) and if Auto Keep Alive is not configured on the Fortigate, the tunnel should drop due to inactivity and re-establish when interesting traffic is processed.</description>
      <pubDate>Tue, 23 Jul 2019 11:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58800#M84842</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-23T11:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58804#M84843</link>
      <description>&lt;P&gt;The issue is that the tunnel goes down but even with interesting traffic is not coming up. WE need to renegotiate the tunnel in order to go up again.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 11:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58804#M84843</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-23T11:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58805#M84844</link>
      <description>So, have you checked the LifeTimes on the CheckPoint side for Phase I and Phase II match the Fortigate side and that on the Fortigate side, the Phase II KeyLife is set to Seconds and not "KiloBytes" or "Both" ?</description>
      <pubDate>Tue, 23 Jul 2019 11:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58805#M84844</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-23T11:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58807#M84845</link>
      <description>&lt;P&gt;This is CPK config. I will ask the config in the peer (fortigate).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="config.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1962iF02A6D0F3FF195D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="config.JPG" alt="config.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 11:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58807#M84845</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-23T11:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58815#M84846</link>
      <description>&lt;P&gt;Let me guess, when interesting traffic arrives at the Fortigate it is able to successfully start a new VPN tunnel and start passing traffic.&amp;nbsp; However when interesting traffic arrives at the Check Point, IKE negotiations fail in Phase 2 and the traffic cannot pass.&amp;nbsp; Fortigates are similar to Juniper/Sonicwall in that Phase 2 subnet/Proxy-ID proposals presented to it must match its configuration &lt;EM&gt;&lt;STRONG&gt;precisely&lt;/STRONG&gt;&lt;/EM&gt;, unlike Cisco and Check Point who will accept a subset of their subnet/Proxy-ID configuration in a Phase 2 proposal.&amp;nbsp; You must adjust the Check Point configuration to present the exact subnet/Proxy-IDs that the Fortigate wants in Phase 2.&lt;/P&gt;
&lt;P&gt;Read scenario 1 of this SK: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with 3rd party&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And this SK for the proper filename of user*def file to edit: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98239&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk98239: Location of 'user.def' files on Security Management Server&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You pretty much are stuck going down this road with Fortigate/Juniper/Sonicwall and to some degree Palo Alto interoperable VPNs.&lt;/P&gt;
&lt;P&gt;Also as noted earlier make sure the Phase 1 and Phase 2 lifetimes match exactly, as Delete SA processing upon tunnel expiration does not always work correctly in an interoperable scenario and can cause tunnel hangs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 13:46:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58815#M84846</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-07-23T13:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58849#M84847</link>
      <description>Please check with the Fortigate people if they have set the rekey based on Kbytes. If they do they need to disable that, Check Point does not support this.</description>
      <pubDate>Tue, 23 Jul 2019 21:08:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58849#M84847</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-23T21:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58893#M84848</link>
      <description>When the Other party has set the rekey on KBytes, this exactly the behavior you would see. They  Reset the tunnel when they recieved/sent the number they set and then drop the tunnel from their end, you do not notice this as they expect you to do the same.</description>
      <pubDate>Wed, 24 Jul 2019 11:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58893#M84848</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-24T11:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58894#M84849</link>
      <description>&lt;P&gt;rekey is 28800 secons. (not KB).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fortinet side has enabled el Autokey keep alive, we will monitor how it works now&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 11:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/58894#M84849</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-07-24T11:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59937#M84850</link>
      <description>&lt;P&gt;Issue is still happening, when not traffic is in the tunnel goes down. And we need to renegotiate in order to up again. Why is this happening, how can we know the reason?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 11:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59937#M84850</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-08-09T11:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59946#M84851</link>
      <description>&lt;P&gt;As a last resort, try checking the boxes keep_IKE_SAs and ike_send_initial_contact on the Global Properties...Advanced...Configure...VPN Advanced Properties...VPN IKE Properties screen and reinstall policy to the gateway.&amp;nbsp; Note that these are global settings (not per VPN Community) and may impact the operation of other unrelated VPN tunnels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 12:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59946#M84851</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-08-09T12:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN is going down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59955#M84852</link>
      <description>&lt;P&gt;I had a similar issue between R80.10 and SMB 730 gateways before. (Used Dynamic IP of the remote SMB gateways)&lt;BR /&gt;Needed to force a reset of the tunnel before it went back.&lt;BR /&gt;&lt;BR /&gt;I got a hotfix from CheckPoint that solved my problem.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 14:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-is-going-down/m-p/59955#M84852</guid>
      <dc:creator>Oskar_Svedman</dc:creator>
      <dc:date>2019-08-09T14:37:38Z</dc:date>
    </item>
  </channel>
</rss>

