<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem IP Sec VPN Checkpoint &amp;gt; Juniper no response from peer. IKE failuret in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2711#M125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-weight: normal; font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Hi Tim Hall &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Thanks for your answer , from juniper side he have a question about why he need to configuration Proxy IDs &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Because Connection can operation normally (Problem&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-weight: bold; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt;"no response from peer. IKE failure happen some time ")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-weight: bold; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;I mean if not configuration proxy ID tunnel can operation but problem found randomly time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;Ake V&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Oct 2016 08:42:21 GMT</pubDate>
    <dc:creator>Ake_Veeraolansi</dc:creator>
    <dc:date>2016-10-06T08:42:21Z</dc:date>
    <item>
      <title>Problem IP Sec VPN Checkpoint &gt; Juniper no response from peer. IKE failuret</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2709#M123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;Hi ,&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;&amp;nbsp;&amp;nbsp; I have a question about IP Sec VPN Connection&amp;nbsp; Checkpoint &amp;gt; Juniper &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;Some times I found error message from checkpoint "no response from peer. IKE failure "&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt; As i check on juniper srx did't set Proxy ID configuration So , If Someone here have&amp;nbsp; &lt;A href="https://dict.longdo.com/search/experience" rel="nofollow noopener noreferrer" style="font-style: inherit; font-weight: inherit; font-family: inherit; color: inherit;" target="_blank"&gt;experience&lt;/A&gt; with &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;IP Sec VPN checkpoint and Juniper srx&amp;nbsp; please suggest solution or basic investigate problem&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;Thanks you &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;BR,&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Antenna Light'; font-size: 12px; color: #5f5f5f;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"&gt;&lt;STRONG style="font-family: Antenna;"&gt;Ake V&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Oct 2016 12:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2709#M123</guid>
      <dc:creator>Ake_Veeraolansi</dc:creator>
      <dc:date>2016-10-03T12:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Problem IP Sec VPN Checkpoint &gt; Juniper no response from peer. IKE failuret</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2710#M124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the subnets/Proxy-IDs proposal made by the Check Point in IKE Phase 2 does not match the Juniper subnet definitions EXACTLY (matching subsets are not allowed on Juniper/Fortinet/Sonicwall whereas they are allowed on Cisco/Check Point), the Juniper will discard the request and not answer.&amp;nbsp; Either the Juniper administrator needs to modify their policy to match the subnets/masks your Check Point is proposing, or you need to explicitly define the subnets you want to propose to the Juniper in a user.def file on the Security Management Server.&amp;nbsp; See sk62590 for the proper user.def.* file to edit as there are numerous variants depending on the version of the security gateway, and see sk108600 for the proper syntax definition of the Proxy-IDs in the user.def.* file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;My book "Max Power: Check Point Firewall Performance Optimization"&lt;/P&gt;&lt;P&gt;now available via &lt;A href="http://maxpowerfirewalls.com/" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2016 15:47:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2710#M124</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2016-10-05T15:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem IP Sec VPN Checkpoint &gt; Juniper no response from peer. IKE failuret</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2711#M125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-weight: normal; font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Hi Tim Hall &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Thanks for your answer , from juniper side he have a question about why he need to configuration Proxy IDs &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.5pt; font-family: Tahoma, sans-serif;"&gt;Because Connection can operation normally (Problem&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-weight: bold; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt;"no response from peer. IKE failure happen some time ")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-weight: bold; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: 'Tahoma','sans-serif';"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;I mean if not configuration proxy ID tunnel can operation but problem found randomly time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-size: 16px; font-family: Tahoma, sans-serif;"&gt;Ake V&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2016 08:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2711#M125</guid>
      <dc:creator>Ake_Veeraolansi</dc:creator>
      <dc:date>2016-10-06T08:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem IP Sec VPN Checkpoint &gt; Juniper no response from peer. IKE failuret</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2712#M126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To have a basic information to start to investigate , you could do :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ike debug on check point firewall&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;vpn debug ikeon&lt;/P&gt;&lt;P&gt;vpn debug ikeoff&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FWDIR/log/ike.elg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FWDIR/log/ikev2.xmll&lt;/P&gt;&lt;P&gt;Tool -&amp;gt; IKEview&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2016 15:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-IP-Sec-VPN-Checkpoint-gt-Juniper-no-response-from-peer/m-p/2712#M126</guid>
      <dc:creator>L_Rossi_89</dc:creator>
      <dc:date>2016-10-06T15:34:58Z</dc:date>
    </item>
  </channel>
</rss>

