<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/81681#M16513</link>
    <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;&lt;P&gt;We had DPD enabled but that did not fix the issue. We are still working with Checkpoint support for investigating the issue.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Apr 2020 09:35:36 GMT</pubDate>
    <dc:creator>Albert_Chang</dc:creator>
    <dc:date>2020-04-13T09:35:36Z</dc:date>
    <item>
      <title>Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56364#M11355</link>
      <description>&lt;P&gt;Our security gateway sometimes drops packets from IPSec tunnel. The workaround is usually to reinstall policy and the issue will be fixed for a few days.&lt;/P&gt;&lt;P&gt;By using the "fw ctl zdebug drop" to capture the drop message, it says &lt;SPAN class="TextRun SCXO26026582 BCX2"&gt;&lt;SPAN class="NormalTextRun SCXO26026582 BCX2"&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXO26026582 BCX2"&gt;&lt;SPAN class="NormalTextRun SCXO26026582 BCX2"&gt;failed to resolve SA (VPN Error code 01)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXO26026582 BCX2"&gt;&lt;SPAN class="NormalTextRun SCXO26026582 BCX2"&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;But in the kernel debug, it looks like it cannot find the connection in the connections table.&lt;/P&gt;&lt;P&gt;Has anyone encounter similar issue and has a solution? Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466084;[cpu_1];[fw4_2];&lt;/SPAN&gt;&lt;SPAN&gt;fwconn_lookup: not found in connections table;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466088;[cpu_1];[fw4_2];&lt;/SPAN&gt;&lt;SPAN&gt;forward_if_not_mine: forwarded to another instance (rc=0);&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466102;[cpu_1];[fw4_2];&lt;/SPAN&gt;&lt;STRONG&gt;fwconn_key_lookup_ex: conn &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.13.1.29:0 IPP 10,0,0,0,0,UUID: 00000000-0000-0000-00-0-0-0-0-0-0-0, 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0&amp;gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;not found in connections table;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;.....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466268;[cpu_1];[fw4_2];fwconn_key_lookup_ex: conn &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;172.28.0.126:15 IPP 10,0,0,0,0,UUID: 00000000-0000-0000-00-0-0-0-0-0-0-0, 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;not found in connections table;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466282;[cpu_1];[fw4_2];&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;vpnk_conn_log: in the kernel&amp;nbsp; - calling fwchainlog_delayed_rulebase_log with alert -1 ;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;;20Jun2019&amp;nbsp; 3:30:27.466284;[cpu_1];[fw4_2];&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;action = 0 &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;schemename = IKE &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;user = &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;methods = ESP: AES-256 + SHA384 + PFS (group 2) &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fail_reason = &lt;/SPAN&gt;&lt;STRONG&gt;Encryption/Decryption failure, failed to resolve SA&lt;/STRONG&gt;&lt;SPAN&gt; (VPN Error code 01) &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;xpo_loghandle = 0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;community_loghandle = 0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56364#M11355</guid>
      <dc:creator>Albert_Chang</dc:creator>
      <dc:date>2019-06-21T11:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56475#M11372</link>
      <description>Have you opened a TAC case on this by chance?</description>
      <pubDate>Sun, 23 Jun 2019 20:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56475#M11372</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T20:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56497#M11376</link>
      <description>Yes, I have opened several cases for this issue in the past. The last one I opened is SR# 6-0001657403. Solutions provided included install Jumbo takes, adjust IKE connections and others. But none of these solved the issue. When the issue happen, the pepd process runs high cpu usage. I am not sure which one is the cause and which is the effect.</description>
      <pubDate>Mon, 24 Jun 2019 01:49:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/56497#M11376</guid>
      <dc:creator>Albert_Chang</dc:creator>
      <dc:date>2019-06-24T01:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61803#M12529</link>
      <description>&lt;P&gt;Did you ever get a solution to this? We have the exact same problem on R80.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed sk122532 which did not solve.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 01:42:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61803#M12529</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-04T01:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61804#M12530</link>
      <description>&lt;P&gt;Assuming you have at least Jumbo HFA 47 installed, try disabling SecureXL acceleration for VPN with the &lt;STRONG&gt;vpn accel off&lt;/STRONG&gt; command.&amp;nbsp; Note that doing so will cause a disruption of all current VPN tunnels, read &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk151114&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk151114: "fwaccel &lt;STRONG&gt;off&lt;/STRONG&gt;" does not affect disabling acceleration of &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnels in R80.20 and above&lt;/A&gt; thoroughly before doing anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 02:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61804#M12530</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-04T02:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61807#M12531</link>
      <description>&lt;P&gt;Thanks, yes we are JHF 47.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will give this a try, unfortunately it is a bit difficult to test if it was successful, we have the issue happen only once every 2 weeks or so. I like doing it on the basis of per peer, as only 2 route based vpn's are affected where-as my dozen policy based vpn's have never had a hitch in years.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 02:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/61807#M12531</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-04T02:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62231#M12632</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately turning VPN accel off has not solved the issue. I performed that change for two peer IP's last week but we had another re-occurrence of the issue after that,&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC has not been able to assist, just told me to try my luck with the latest Jumbo. (I will patch the gateways so they continue to investigate).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a debug taken from when the issue occurred if you are interested to take a look?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One new message I hadn't noticed before was this:&lt;/P&gt;&lt;P&gt;dropped by vpn_encrypt_chain Reason: Could not change connection vpn interface.;&lt;/P&gt;&lt;P&gt;that is showing for every session&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2019 23:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62231#M12632</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-08T23:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62805#M12723</link>
      <description>&lt;P&gt;Is this a route-based VPN using VTI's?&amp;nbsp; If so check this out:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119143&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk119143: "encryption fail reason: Cannot change dynamic &lt;STRONG&gt;vpn&lt;/STRONG&gt; &lt;STRONG&gt;interface&lt;/STRONG&gt; - new interface not accepted by rule" log in SmartView Tracker&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 18:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62805#M12723</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-15T18:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62908#M12757</link>
      <description>&lt;P&gt;Hello, yes its route based with VTI's (static routing only though)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly, i did have to delete and re-create the interfaces for a separate reason (and did the JHF 91) and have not had a reoccurance of the issue.. so far &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 06:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/62908#M12757</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-17T06:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80552#M16294</link>
      <description>&lt;P&gt;Should give an update, issue still reoccurs once a week roughly. Previously it was every day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only notable thing with this vpn is, remote side gets switched off every night to save money on azure. The live ones that don't get switched off have never once had this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17421"&gt;@Albert_Chang&lt;/a&gt;&amp;nbsp;did you ever get a fix for this?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 22:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80552#M16294</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-04-01T22:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80553#M16295</link>
      <description>&lt;P&gt;OK so if turning off SecureXL had no effect it is not an issue with IPSec, but IKE.&amp;nbsp; Interoperable VPNs have had a longstanding problem with not handling "Delete SA" notifications correctly when one side of the tunnel goes down prior to the SA Lifetime expiration.&amp;nbsp; See if you have any interesting error messages getting logged to $FWDIR/log/vpnd.elg around the time of the issue.&lt;/P&gt;
&lt;P&gt;Looks like Azure supports DPD in a route-based configuration, enabling that would be the best way to deal with this issue.&amp;nbsp; See &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;, scenario 5, be sure to enable DPD on the Azure end too.&amp;nbsp; Alternatively you could try to significantly shorten up your IKE Phase 1 and Phase 2 SA Lifetimes on both ends so it detects the problem quicker and recovers from it.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 22:20:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80553#M16295</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-01T22:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80555#M16296</link>
      <description>&lt;P&gt;Thanks for reply, that is not a bad idea, I had tried the other method and made the lifetimes the longest supported values which seemed to make it a bit better but still had occurrences weekly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've turned it down to 10 minute p1 and 5 min p2. Will see if that helps. If not ill take a look into DPD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 23:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80555#M16296</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-04-01T23:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80879#M16352</link>
      <description>&lt;P&gt;Unfortunately, 5 minute lifetime has not solved the issue. tunnel still went down and doesn't come back up until a policy push is completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ill look into DPD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2020 21:52:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/80879#M16352</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-04-05T21:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/81681#M16513</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;&lt;P&gt;We had DPD enabled but that did not fix the issue. We are still working with Checkpoint support for investigating the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2020 09:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/81681#M16513</guid>
      <dc:creator>Albert_Chang</dc:creator>
      <dc:date>2020-04-13T09:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/81684#M16516</link>
      <description>&lt;P&gt;Bummer, sounds like you may be in bug territory now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2020 12:18:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/81684#M16516</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-13T12:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/95770#M18857</link>
      <description>&lt;P&gt;Hello&amp;nbsp; Ryan,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Did someone provided any update, as we are receiving the exact same issue on are checkpoint G/Ws running on R80.10 Take 272.&lt;/P&gt;&lt;P&gt;vpn_drop_and_log Reason: Encryption/Decryption failure, failed to resolve SA (VPN Error code 01);&lt;/P&gt;&lt;P&gt;vpn_encrypt_chain Reason: Could not change connection vpn interface.;&lt;/P&gt;&lt;P&gt;And we have static route-based VPN tunnels integrated with&amp;nbsp; AWS.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mrigen&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 14:19:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/95770#M18857</guid>
      <dc:creator>Mrigen_Sane</dc:creator>
      <dc:date>2020-09-01T14:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Packets from IPSec tunnel were dropped. It seems there is an issue on the coreXL connections tab</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/97521#M19139</link>
      <description>&lt;P&gt;I had the same error (encryption/decryption failure, failed to resolve sa (vpn error code 01))... and it does seem to be related to a Checkpoint bug.&lt;/P&gt;&lt;P&gt;I can get the VPN tunnel up and running again by just publishing any change associated with the gateway and installing the policy. In my case I change the vpn interface description.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 09:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Packets-from-IPSec-tunnel-were-dropped-It-seems-there-is-an/m-p/97521#M19139</guid>
      <dc:creator>Andrew_Tonna</dc:creator>
      <dc:date>2020-09-25T09:01:26Z</dc:date>
    </item>
  </channel>
</rss>

