<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS VPN Setup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67320#M9557</link>
    <description>Wouldn't you want the protocol signature not set, since that seems to be the issue?&lt;BR /&gt;That said, we should fix the protocol signature, which means some packet traces and a TAC case are in order.</description>
    <pubDate>Wed, 13 Nov 2019 18:08:09 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-11-13T18:08:09Z</dc:date>
    <item>
      <title>AWS VPN Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67279#M9556</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have setup a new VPN from Checkpoint R80.10 to AWS. We are getting the below message in tracker though the packet is accepting.&lt;/P&gt;&lt;P&gt;Firewall - Protocol violation detected with protocol:(IKE-UDP), matched protocol sig_id:(4), violation sig_id:(13). (500)&lt;/P&gt;&lt;P&gt;I have created the new UDP IKE service with Protocol signature enabled and allowed the access to peer but still the same. May i know what could be the reason?&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 11:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67279#M9556</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2019-11-13T11:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VPN Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67320#M9557</link>
      <description>Wouldn't you want the protocol signature not set, since that seems to be the issue?&lt;BR /&gt;That said, we should fix the protocol signature, which means some packet traces and a TAC case are in order.</description>
      <pubDate>Wed, 13 Nov 2019 18:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67320#M9557</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-13T18:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VPN Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67445#M9558</link>
      <description>So TAC case is must you say? Never enabled protocal signature for any other AWS VPN till date. And for this i enabled and implemented though the issue persists.</description>
      <pubDate>Thu, 14 Nov 2019 16:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67445#M9558</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2019-11-14T16:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VPN Setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67466#M9559</link>
      <description>In your original post, you said: "I have created the new UDP IKE service with Protocol signature enabled"&lt;BR /&gt;I just checked the original definition of IKE, and it does not have Protocol Signature enabled.&lt;BR /&gt;I can't think of any reason why you should enable this, either. &lt;BR /&gt;&lt;BR /&gt;In any case, I would consult with the TAC as this is clearly not expected behavior.</description>
      <pubDate>Thu, 14 Nov 2019 19:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AWS-VPN-Setup/m-p/67466#M9559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-14T19:25:52Z</dc:date>
    </item>
  </channel>
</rss>

