<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Tunnel Failing to establish in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64649#M13190</link>
    <description>&lt;P&gt;Hi both,&lt;/P&gt;&lt;P&gt;Thanks for the pointers, we'd come across the source IP setting during our troubleshooting and already set it as the external IP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourceAddress.PNG" style="width: 433px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2724i67C1188AD9C58168/image-size/large?v=v2&amp;amp;px=999" role="button" title="sourceAddress.PNG" alt="sourceAddress.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afraid we're still seeing the same thing in IKEview that the peer target for site B is the private rather than public IP of the site A gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to look at removing the site A Gw and adding it back in with it's WAN IP to the SMS. Feels like a bug somewhere?&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Dan&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 14:26:02 GMT</pubDate>
    <dc:creator>C2CDan</dc:creator>
    <dc:date>2019-10-09T14:26:02Z</dc:date>
    <item>
      <title>IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64487#M13138</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm having issues establishing an IPSec tunnel between two R80.30 open servers. There's nothing particularly special setup, just two sites A &amp;amp; B. Site A has the SMS and one firewall and B has just a firewall. Communication with the Site B firewall is fine (although we’ve had to add an explicit allow rule for any traffic originating from Site A to manage the Site B firewall, as if the implied rule isn’t working??) until we try to push a VPN community to it, at which point we lose SIC to the Site B firewall and see the following output on the B firewall with fw ctl zdebug drop&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;@;23607731;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 xx.xx.xx.xx:27047 -&amp;gt; xx.xx.xx.xx:18191 dropped by vpn_drop_and_log Reason: Clear text packet should be encrypted;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;A SIC reset goes through fine and all other management of the firewall in B seems ok, albeit requiring an explicit allow rule.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We've yet to see the tunnel establish but expect if we resolve the above we'll get resolution on the tunnel establishment&lt;/P&gt;&lt;P&gt;Grateful for any pointers!&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 16:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64487#M13138</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-07T16:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64493#M13139</link>
      <description>Normally all management traffic is passed outside the tunnel, this way you cannot lock yourself out. It looks like either side thinks the traffic still should be encrypted, which it should not. You can try to add the management ports explicitly in the exclusion list for the specific VPN community.&lt;BR /&gt;Also make sure you have a proper NAT setup for the SMS (make sure to use a separate NAT-IP for the SMS)</description>
      <pubDate>Mon, 07 Oct 2019 21:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64493#M13139</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-07T21:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64499#M13142</link>
      <description>&lt;P&gt;Additionally to what Maarten stated: Make sure that encryption domains don't include GWs public IPs, also make sure to check this option in your management NAT settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-10-07 21_39_35-Window.png" style="width: 446px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2709i435F32CBFB156277/image-size/large?v=v2&amp;amp;px=999" role="button" title="2019-10-07 21_39_35-Window.png" alt="2019-10-07 21_39_35-Window.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 00:40:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64499#M13142</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-08T00:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64573#M13166</link>
      <description>&lt;P&gt;Hi Maarten, Frederico,&lt;/P&gt;&lt;P&gt;Thanks for the pointers re management traffic, we'd missed having a dedicated NAT and since breaking the SMS out to it's own WAN IP we've stopped the issue of losing management control of the remote gateway, thank you!&lt;/P&gt;&lt;P&gt;Sadly, we're still struggling to get the tunnel going, Maarten, I suspect you may be right with regards ensuring the encryption domains don't include the public IPs of the gateways. That being said, everything on the VPN setup is very 'vanilla'. Where/how can we double check this?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;BR /&gt;Dan&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 22:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64573#M13166</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-08T22:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64582#M13168</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;FYI, in the course of troubleshooting this I've come across the following output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpntutlist.JPG" style="width: 731px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2719i91B3F271ECE46F0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpntutlist.JPG" alt="vpntutlist.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm assuming, the 'My TS' information should be the local subnet being presented to the opposite Gateway, in the same way the Peer TS is a local subnet? In our case, My TS is showing the WAN address of this gateway?&lt;/P&gt;&lt;P&gt;Also, seeing 'No outbound SA', would this indicate the local Gw we're ssh'd into isn't attempting to initiate connections at all?&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Dan&lt;/P&gt;&lt;P&gt;PS Peer in this instance, I assume is not the peer ID but rather the text description from the SMS?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 23:37:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64582#M13168</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-08T23:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64584#M13169</link>
      <description>&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;You are managing both gateways with the same management right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check if you can manually set the encryption domain for both gateways so you can share specific subnets, by default its configured to share all topology.&lt;/P&gt;&lt;P&gt;VPN Domain - Manually defined. Don't look at the other red squares &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="enc dom.png" style="width: 577px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2720iF3AA93A3DDF8AF49/image-dimensions/577x545?v=v2" width="577" height="545" role="button" title="enc dom.png" alt="enc dom.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Finally I highly suggest you to use&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994" target="_self"&gt;IKEView&lt;/A&gt;&amp;nbsp;to further debug your VPN, this will give us a closer hint. This will tell us which Phase is failing and mostly why. This tool is safe to use on production.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 02:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64584#M13169</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-09T02:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64614#M13175</link>
      <description>&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;Thanks for the hint re IKEView, looks to be a really good tool and has certainly illuminated the path!&lt;/P&gt;&lt;P&gt;From IKEView we can see the following:&lt;/P&gt;&lt;P&gt;Site A GW -&amp;nbsp;Local host ==&amp;gt; Remote peer(Public IP)&lt;/P&gt;&lt;P&gt;However from the Site B GW IKE log we're seeing:&amp;nbsp;Local host ==&amp;gt; Remote peer(192.168.xx.xx) where 192.168.xx.xx is the private IP of the Site A GW&lt;/P&gt;&lt;P&gt;It looks to me like the main/management IP of the Site A GW is being presented as the peering IP, however, we've explicitly set this to be the WAN IP of Site A GW as per the below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="selectedAddress.PNG" style="width: 451px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2722i6D378DC73468C7B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="selectedAddress.PNG" alt="selectedAddress.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We did wonder if we should remove the Site A GW from the SMS and re-add with it's main WAN IP? But equally, would expect the above to take care of the peering element?&lt;/P&gt;&lt;P&gt;Many thanks for the help so far!&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Dan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 10:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64614#M13175</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-09T10:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64618#M13176</link>
      <description>You also need to make sure the Outgoing part is configured to properly use the External IP, you do this in the Source IP address settings set to manual and selected IP from topology.</description>
      <pubDate>Wed, 09 Oct 2019 11:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64618#M13176</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-09T11:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64642#M13186</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="24_1.png" style="width: 773px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2723iB91D56B327903CEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="24_1.png" alt="24_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64642#M13186</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-09T14:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64649#M13190</link>
      <description>&lt;P&gt;Hi both,&lt;/P&gt;&lt;P&gt;Thanks for the pointers, we'd come across the source IP setting during our troubleshooting and already set it as the external IP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourceAddress.PNG" style="width: 433px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2724i67C1188AD9C58168/image-size/large?v=v2&amp;amp;px=999" role="button" title="sourceAddress.PNG" alt="sourceAddress.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afraid we're still seeing the same thing in IKEview that the peer target for site B is the private rather than public IP of the site A gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to look at removing the site A Gw and adding it back in with it's WAN IP to the SMS. Feels like a bug somewhere?&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Dan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64649#M13190</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-09T14:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64654#M13194</link>
      <description>removing is not needed, you can change the IP on the object and do not need to replace it to do so.&lt;BR /&gt;Have you pushed policy to both gateways, after changing this setting?</description>
      <pubDate>Wed, 09 Oct 2019 14:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64654#M13194</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-09T14:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64658#M13195</link>
      <description>&lt;P&gt;Hi Maarten,&lt;/P&gt;&lt;P&gt;Thanks for the response, yes we've installed the policy since making the change&lt;/P&gt;&lt;P&gt;Re changing the IP, is it normal to chance the IP to the WAN IP or should it not really matter and should be picking up the route setting?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Dan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 15:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64658#M13195</guid>
      <dc:creator>C2CDan</dc:creator>
      <dc:date>2019-10-09T15:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Failing to establish</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64664#M13196</link>
      <description>It really should not matter at all. As you are managing the gateway from the LAN side it is normal to use that interface as the object IP.&lt;BR /&gt;It would not hurt to change tge setting, publish, change it back and publish and push the policy again.</description>
      <pubDate>Wed, 09 Oct 2019 15:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-Failing-to-establish/m-p/64664#M13196</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-09T15:27:53Z</dc:date>
    </item>
  </channel>
</rss>

