<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.20 Ipsec VPN issues in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60954#M12366</link>
    <description>I've done it yesterday to do some fw monitor, i left it off, guess what, no issues today for AWS vpn... so indeed it's a workaround.&lt;BR /&gt;&lt;BR /&gt;Can you please enlighten me on the core issue ? it's a bit disapointed to disable acceleration to fix this issue.&lt;BR /&gt;&lt;BR /&gt;thx as always.</description>
    <pubDate>Thu, 22 Aug 2019 12:53:49 GMT</pubDate>
    <dc:creator>Khalid_Aftas</dc:creator>
    <dc:date>2019-08-22T12:53:49Z</dc:date>
    <item>
      <title>R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60920#M12359</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrade to r80.20 in multiple gateway, we started having issue with a lot of VPN that were running without problem in 80.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;case 1 : VPN with partner down, i had to make him disable NAT-T option for it to work again.&lt;/P&gt;&lt;P&gt;Case 2 (most critical) : Amazon Web Services, once phase 2 proposition from aws come, CP accept it, then decide to propose again another negotiation, during few minutes complete cut out of the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other cases in other GW with simlar issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Opened a case in the TAC, they made me install some special hotfix, with no succes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What changed in R80.20 regarding vpn ? i hope there is a solution for these issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[CPFC]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;&lt;P&gt;[MGMT]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;&lt;P&gt;[FW1]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;BR /&gt;HOTFIX_R80_20_JHF_T87_190_MAIN&lt;BR /&gt;HOTFIX_R80_20_JHF_T87_174_MAIN&lt;BR /&gt;HOTFIX_R80_20_JHF_87_90_002_MAIN&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R80.20 - Build 100&lt;BR /&gt;kernel: R80.20 - Build 001&lt;/P&gt;&lt;P&gt;[SecurePlatform]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;&lt;P&gt;[CPinfo]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[DIAG]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[PPACK]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;&lt;P&gt;[CVPN]&lt;BR /&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;&lt;P&gt;[CPUpdates]&lt;BR /&gt;BUNDLE_R80_20_JUMBO_HF_MAIN Take: 87&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 07:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60920#M12359</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2019-08-22T07:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60950#M12363</link>
      <description>&lt;P&gt;There were major changes to SecureXL in R80.20.&amp;nbsp; Try disabling SecureXL VPN acceleration for the problematic peers using the &lt;STRONG&gt;vpn accel&lt;/STRONG&gt; command (added in R80.20 Jumbo Take 47) as specified here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk151114&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk151114: "fwaccel &lt;STRONG&gt;off&lt;/STRONG&gt;" does not affect disabling acceleration of &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnels in R80.20 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 12:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60950#M12363</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-08-22T12:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60954#M12366</link>
      <description>I've done it yesterday to do some fw monitor, i left it off, guess what, no issues today for AWS vpn... so indeed it's a workaround.&lt;BR /&gt;&lt;BR /&gt;Can you please enlighten me on the core issue ? it's a bit disapointed to disable acceleration to fix this issue.&lt;BR /&gt;&lt;BR /&gt;thx as always.</description>
      <pubDate>Thu, 22 Aug 2019 12:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60954#M12366</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2019-08-22T12:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60958#M12367</link>
      <description>&lt;P&gt;Actually in R80.20 Jumbo HFA Take 73 and later, you don't need to disable SecureXL to get a complete &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; capture using -F.&lt;/P&gt;
&lt;P&gt;I assume you disabled SecureXL with the &lt;STRONG&gt;fwaccel off&lt;/STRONG&gt; command, which is not a permanent fix and may cause performance issues. Any time that SecureXL needs to be disabled to make things work it is always a good idea to open a TAC case so they can figure out why.&amp;nbsp; That said, I'd recommend the following (note doing the following will cause a brief VPN outage):&lt;/P&gt;
&lt;P&gt;1) Disable SecureXL acceleration for the problematic VPN peers via the &lt;STRONG&gt;vpn accel&lt;/STRONG&gt; command (you can also disable all SecureXL VPN acceleration with the &lt;STRONG&gt;vpn accel off&lt;/STRONG&gt; command).&lt;/P&gt;
&lt;P&gt;2) Turn SecureXL back on with &lt;STRONG&gt;fwaccel on&lt;/STRONG&gt; (or just reboot).&lt;/P&gt;
&lt;P&gt;SecureXL was completely overhauled in R80.20 in preparation for the upcoming Falcon accelerator cards.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60958#M12367</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-10-28T11:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60961#M12368</link>
      <description>i used vpn accel peerip not fwaccel off sorry.&lt;BR /&gt;&lt;BR /&gt;I keep having incidents for s2s vpn poping &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; i guess i need to disable it for almost all of them.&lt;BR /&gt;&lt;BR /&gt;i'll check with the tac also.</description>
      <pubDate>Thu, 22 Aug 2019 14:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/60961#M12368</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2019-08-22T14:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63245#M12823</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've used for the same issue the command &lt;EM&gt;vpn accel off&lt;/EM&gt; for a particular peer and seem to fix the problem but after installation policy the vpn stops to working and I need to use vpn tu to reset the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 11:34:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63245#M12823</guid>
      <dc:creator>wizzolo</dc:creator>
      <dc:date>2019-09-20T11:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63337#M12842</link>
      <description>&lt;P&gt;Hi Khalid,&lt;/P&gt;
&lt;P&gt;I would like to get more details regarding different SXL VPN issues you are having.&lt;/P&gt;
&lt;P&gt;Currently we do not have known VPN issues with SXL which are present in the latest R80.20 JHF.&lt;/P&gt;
&lt;P&gt;In case you still have difficulties with it - I would prioritize it in our group.&lt;/P&gt;
&lt;P&gt;Are you running the latest JHF take?&lt;/P&gt;
&lt;P&gt;Can you share the SRs which are still unresolved, or resolved, but fixes still not inside JHF?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 07:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63337#M12842</guid>
      <dc:creator>Vitaly_Timofeev</dc:creator>
      <dc:date>2019-09-22T07:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63338#M12843</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;wizzolo,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have keep IKE SAs checked?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In any case if it is checked or not I would advise to open a ticket to TAC as it is not an expected behavior.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 07:49:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63338#M12843</guid>
      <dc:creator>Vitaly_Timofeev</dc:creator>
      <dc:date>2019-09-22T07:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63376#M12852</link>
      <description>Hi Vitaly,&lt;BR /&gt;&lt;BR /&gt;Yes i have keep IKE SA enabeld, and we are running Take 87 HF.&lt;BR /&gt;&lt;BR /&gt;I of course have a case with the TAC, now it's with an escalation engineer, he suggested to install latest non GA jumbo as first solution.&lt;BR /&gt;&lt;BR /&gt;Kr,&lt;BR /&gt;&lt;BR /&gt;Khalid</description>
      <pubDate>Mon, 23 Sep 2019 06:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63376#M12852</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2019-09-23T06:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63424#M12862</link>
      <description>&lt;P&gt;Just to share my point, I've the&amp;nbsp; Take: 103 with the issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 10:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/63424#M12862</guid>
      <dc:creator>wizzolo</dc:creator>
      <dc:date>2019-09-23T10:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/73120#M14838</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I had a VPN outage to AWS after installing policy on a R80.20 gateway running Take 87. I installed policy a second time and the tunnels re-established. My community contains 2 tunnels and is configured as per AWS &amp;amp; Check Point documentation, including DPD monitoring.&amp;nbsp; If you try installing policy a second time, does the tunnel come back up?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jonne&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 11:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/73120#M14838</guid>
      <dc:creator>Jonne_Hannon</dc:creator>
      <dc:date>2020-01-23T11:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87324#M17547</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is related to the new VPN acceleration brought in r80.20, TAC was not able to found anything, and we decided to give it a try later in r80.30, and ... same issue.&lt;/P&gt;&lt;P&gt;I hear the same stories with others colleagues working with AWS and CP vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we tackle this ?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 13:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87324#M17547</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-04T13:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87325#M17548</link>
      <description>I've solved with command vpn accel off for a specific peer, try it.&lt;BR /&gt;&lt;BR /&gt;Attention is not fw accel off and is necessary a new entry(rc or script) to make it persistent after reboot</description>
      <pubDate>Thu, 04 Jun 2020 13:06:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87325#M17548</guid>
      <dc:creator>wizzolo</dc:creator>
      <dc:date>2020-06-04T13:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87326#M17549</link>
      <description>Well that is what i explained, vpn accel off is only working for max 2 IPs.&lt;BR /&gt;&lt;BR /&gt;We would like to have this fixed, instead of disabling acceleration and the limitation of 2</description>
      <pubDate>Thu, 04 Jun 2020 13:08:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87326#M17549</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-04T13:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87359#M17555</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;FONT face="&amp;quot;Calibri&amp;quot;,sans-serif" color="#000012"&gt;I believe my issue was solved by assigning an empty group to the AWS peers (Interoperable Devices) VPN Domain to stop the Encryption Fail Reason is "VPN failed to resolve MEP Gateway" error after policy installation.&lt;/FONT&gt;&amp;nbsp; I also had to make sure that ping was enabled on the routes for the AWS peers.&amp;nbsp; I have VPN acceleration enabled and it has been pretty stable for the past few months.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jonne.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 03:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87359#M17555</guid>
      <dc:creator>Jonne_Hannon</dc:creator>
      <dc:date>2020-06-05T03:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87413#M17589</link>
      <description>Well we dont use VTI, as we are running vsx, it's a regular VPN.</description>
      <pubDate>Fri, 05 Jun 2020 09:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87413#M17589</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-05T09:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87542#M17626</link>
      <description>&lt;P&gt;In my experience, AWS VPN isn't very stable as a regular VPN and should be configured with VTIs.&amp;nbsp; We initially had it configured as a regular VPN and it was dropping regularly.&amp;nbsp; Much more stable with VTIs.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 03:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87542#M17626</guid>
      <dc:creator>Jonne_Hannon</dc:creator>
      <dc:date>2020-06-08T03:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87568#M17632</link>
      <description>We had it running for 3 years without issues like that on 77.30 till 80.10, VTIs are still not supported, and i don't think it will change anything, at the end it's the same pipepline.&lt;BR /&gt;&lt;BR /&gt;Since the change of SecureXL from 80.20 it's dropping at every phase 2 timeout.. without acceleration 0 problems.</description>
      <pubDate>Mon, 08 Jun 2020 07:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/87568#M17632</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-08T07:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/100369#M19518</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For issue 1 with NAT-T&amp;nbsp; this is a known issue that is described in &lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165003&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk165003&lt;/A&gt;&amp;nbsp;as the sk state, the fix is integrated into the following jumbo takes&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165456" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.40&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;starting from Take 83&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk153152" target="_blank"&gt;Jumbo Hotfix Accumulator for R80.30&lt;/A&gt;&amp;nbsp;starting from Take 219&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116380" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.10&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;starting from Take 283&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For issue 2 it is very hard to provide any feedback without seeing debugs solely on this description. Is you opened SR for this please message me in private and I will look into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R81 now support VTI with VSX. Please see "what's new" section in the R81&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166715&amp;amp;partition=Basic&amp;amp;product=All" target="_blank" rel="noopener"&gt;sk166715&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Configure Dynamic Routing VPN through Virtual Tunnel Interface (VTI) in VSX mode.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:33:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/100369#M19518</guid>
      <dc:creator>eakselrod</dc:creator>
      <dc:date>2020-10-28T11:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Ipsec VPN issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/100997#M19605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SR sent in DM, with the input of AWS and what they think about this particular issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in summary : the GW send&amp;nbsp;"UDP-Encapsulated-Tunnel" that make the tunnel stuck until rekeying from CP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 10:49:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Ipsec-VPN-issues/m-p/100997#M19605</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-11-03T10:49:49Z</dc:date>
    </item>
  </channel>
</rss>

