<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting Up Site-to-Site VPN to 3rd Party Gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59887#M12134</link>
    <description>&lt;P&gt;Did &amp;nbsp;you consult&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&amp;nbsp;already ? This is a valuable document for that kind of issues...&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 14:12:22 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-08-08T14:12:22Z</dc:date>
    <item>
      <title>Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59825#M12113</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;I'm trying to setup a VPN tunnel to a 3rd party and am running into some issues. These are the instructions I have received from the third party regarding the setup:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Encrypt Mode:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IKEv2 only&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IKE (Phase 1) Proposal&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Main Mode&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Encryption Type/Algorithm: AES-256&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Data Integrity: SHA256&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Key&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;DH-Group: 2&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Lifetime: 3600 seconds&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;IKE (Phase 2) Proposal&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Protocol: ESP&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Encryption Type: AES-256&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Data Integrity: SHA256&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Lifetime: 3600 seconds&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Disabled PerfectForward Secrecy (PFS)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;With the exception of setting the protocol to ESP (not been able to find how to do this) I have done everything else according to these instructions:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62803" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62803&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When looking in SmartView Tracker I see an 'traffic selectors unacceptable' log entry. Not quite sure how to proceed with this.&lt;/P&gt;&lt;P&gt;We're running R77.30 take 204&lt;/P&gt;&lt;P&gt;Thanks in advance for any assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 16:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59825#M12113</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-08-07T16:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59834#M12117</link>
      <description>&lt;P&gt;Tbgaz,&lt;/P&gt;&lt;P&gt;As far as I can remember there are some known problems with IKEv2 and third party gateways. I think there was a problem with SecureXL. Did you tried to disable the acceleration ?&lt;/P&gt;&lt;P&gt;Please have a look at the IKEv2 VPN limitations in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104860&amp;amp;partition=General&amp;amp;product=All%22#VPN" target="_self"&gt;VPN limitations in R77.30&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Espacially&amp;nbsp;&lt;SPAN&gt;sk102437,&amp;nbsp;sk114834 and&amp;nbsp;sk112139.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wolfgang&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 19:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59834#M12117</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-08-07T19:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59886#M12133</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;Thanks for the reply. I've made some progress, the tunnel is now showing as up. I checked SecureXL but it isn't configured on the gateway. From the 3rd party endpoint to our gateway a 'child SA is successfully created' log entry is created, but going in the opposite direction I see a log message 'Child SA exchange: Peer's message is unacceptable'.&lt;/P&gt;&lt;P&gt;Is it a case that we have to use IKEv1 or is that less than ideal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 14:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59886#M12133</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-08-08T14:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59887#M12134</link>
      <description>&lt;P&gt;Did &amp;nbsp;you consult&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&amp;nbsp;already ? This is a valuable document for that kind of issues...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 14:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/59887#M12134</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-08T14:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/60216#M12177</link>
      <description>&lt;P&gt;Hi. The issue has been resolved. The 3rd party gateway needed to be tweaked to allow connectivity.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 11:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/60216#M12177</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-08-13T11:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/60222#M12178</link>
      <description>&lt;P&gt;Best is pinching with a sharp needle from behind&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 12:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/60222#M12178</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-13T12:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/74850#M15158</link>
      <description>&lt;P&gt;Is it possible that you share what was being "tweaked"?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 19:09:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/74850#M15158</guid>
      <dc:creator>An_Nguyen</dc:creator>
      <dc:date>2020-02-11T19:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Up Site-to-Site VPN to 3rd Party Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/131393#M23834</link>
      <description>&lt;P&gt;Would it be possible to share what the tweak was?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 17:41:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Setting-Up-Site-to-Site-VPN-to-3rd-Party-Gateway/m-p/131393#M23834</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2021-10-08T17:41:20Z</dc:date>
    </item>
  </channel>
</rss>

