<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN tunnel without public IP on the External interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50622#M9737</link>
    <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That solution works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had trouble because&amp;nbsp; of duplicate interoperable device objects on the Check Point side… The Cisco device was created twice, but with different Topology.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2019 15:30:56 GMT</pubDate>
    <dc:creator>Louis_Poulin</dc:creator>
    <dc:date>2019-04-11T15:30:56Z</dc:date>
    <item>
      <title>VPN tunnel without public IP on the External interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50473#M9735</link>
      <description>&lt;P&gt;Please consider the following diagram:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN adresse privee.png" style="width: 714px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/749i66156D6DEEDC809E/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN adresse privee.png" alt="VPN adresse privee.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Check Point firewall is a VS on a VSX Cluster running R80.20.&lt;/P&gt;&lt;P&gt;The External interface is assigned a private IP address. But public IP addresses 1.1.1.0/24 are routed to this Check Point firewall.&lt;/P&gt;&lt;P&gt;I need to make a VPN tunnel with a Cisco device with IP 2.2.2.2.&lt;/P&gt;&lt;P&gt;Do you guys have any ideas?&lt;/P&gt;&lt;P&gt;We tried so far to add a dummy interface on the VS that leads to nowhere, but with a Public IP 1.1.1.1. There is a negotiation of the tunnel with the Cisco device, but IKE Phase 1 doesn't go through.&lt;/P&gt;&lt;P&gt;On the Cisco side, we have error messages like:&lt;BR /&gt;%CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 1.1.1.1 was not encrypted and it should've been.&lt;BR /&gt;ISAKMP: (1075):retransmitting phase 1 MM_KEY_EXCH...&lt;/P&gt;&lt;P&gt;On Check Point's side we have:&lt;BR /&gt;Main Mode Sent Notification to Peer: authentication failed&lt;/P&gt;&lt;P&gt;With a public IP address on the external interface, there is no problem.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:09:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50473#M9735</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-04-10T17:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel without public IP on the External interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50496#M9736</link>
      <description>You  need to use VPN link selection on the VS object and assign the 1.1.1 to a interface and set that interface as the interface to use for the VPN. That should do it, also check that the setting for Source IP Address is set to the selected interface.</description>
      <pubDate>Wed, 10 Apr 2019 21:43:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50496#M9736</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-04-10T21:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel without public IP on the External interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50622#M9737</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That solution works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had trouble because&amp;nbsp; of duplicate interoperable device objects on the Check Point side… The Cisco device was created twice, but with different Topology.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 15:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-without-public-IP-on-the-External-interface/m-p/50622#M9737</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-04-11T15:30:56Z</dc:date>
    </item>
  </channel>
</rss>

