<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Untrusted Gateway - Remote Fix in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64358#M13110</link>
    <description>&lt;P&gt;Hi. Thanks for the response. Sorry, wrong terminology. I meant it's a single firewall (no HA)!&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2019 11:11:35 GMT</pubDate>
    <dc:creator>Wyman</dc:creator>
    <dc:date>2019-10-04T11:11:35Z</dc:date>
    <item>
      <title>Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64354#M13108</link>
      <description>&lt;P&gt;Hi all. Our standalone firewall in our remote office has an 'untrusted' status due to a SIC reset from what I understand from a CP article (only SNMP settings and FW rules were configured). Trouble is, there is no-one at the office at the moment and I was wondering whether I could do anything remotely to bring the firewall back up.&lt;/P&gt;&lt;P&gt;I have done a 'vpu tu' on our local gateway and can see the remote firewall SA in the list of IKE SAs.&lt;/P&gt;&lt;P&gt;If I reset the tunnel would this fix the issue, or would I have to get someone on-site to physically reset the box?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 10:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64354#M13108</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-10-04T10:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64357#M13109</link>
      <description>&lt;P&gt;A StandAlone Firewall has SIC only with itself - so i do not quite understand the issue. To fix this from Remote (or at least try to) i would involve TAC for a quick RAS...&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 11:08:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64357#M13109</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-04T11:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64358#M13110</link>
      <description>&lt;P&gt;Hi. Thanks for the response. Sorry, wrong terminology. I meant it's a single firewall (no HA)!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 11:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64358#M13110</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-10-04T11:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64365#M13114</link>
      <description>Tbgaz,&lt;BR /&gt;Please share with us which model do you have on your branch office and on your HQ as well as Gaia OS versions installed.&lt;BR /&gt;&lt;BR /&gt;What happens when you try yo test SIC from the management?&lt;BR /&gt;&lt;BR /&gt;You can try to reset the tunnel but it seems that you will need someone on the other side to reboot it.&lt;BR /&gt;For next time set up a backup entry on your branch office firewall like a remote VPN o allowing only some IPs (Such as the one from your HQ) to access it via the public IP.&lt;BR /&gt;___</description>
      <pubDate>Fri, 04 Oct 2019 12:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64365#M13114</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-04T12:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64367#M13115</link>
      <description>&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;It is a R77.20 (an upgrade is imminent) 1450 Appliance. When I test the status it says 'Could not establish TCP connection with &amp;lt;public IP&amp;gt;'.&lt;/P&gt;&lt;P&gt;I am waiting for a colleague to get into the office so they can connect to the Gaia config page on the LAN to reboot as the FW is behind a locked door (serviced office) for which we have to open a ticket for IT to give us physical access.&lt;/P&gt;&lt;P&gt;Hopefully a reboot will fix.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 13:19:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64367#M13115</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2019-10-04T13:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64368#M13116</link>
      <description>&lt;P&gt;Can you confirm that the site has internet connectivity? If yes then it seems that reboot is your only option. You may want to set up an alternative way to access the gateway in the future&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 13:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64368#M13116</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-04T13:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Untrusted Gateway - Remote Fix</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64408#M13125</link>
      <description>If SIC trust is truly broken through a reset, there's nothing you can do remotely unless you have some sort of out-of-band access.</description>
      <pubDate>Sat, 05 Oct 2019 04:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Untrusted-Gateway-Remote-Fix/m-p/64408#M13125</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-05T04:17:57Z</dc:date>
    </item>
  </channel>
</rss>

