<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93788#M18582</link>
    <description>&lt;P&gt;Those messages indicate that the Check Point expired or otherwise removed an existing IPSec VPN tunnel, yet the AWS side still thinks it is up and is sending traffic which the Check Point cannot decrypt because the tunnel no longer exists.&lt;/P&gt;
&lt;P&gt;I assume you have already seen this SK, as AWS will only allow 2 SPIs:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113561&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk113561: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Tunnel to Amazon Web Services (&lt;STRONG&gt;AWS&lt;/STRONG&gt;) is unstable&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Assuming it is not that, make sure the Phase 1 and Phase 2 SA Lifetimes match *exactly* between the configuration on both sides.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 18:16:56 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-08-10T18:16:56Z</dc:date>
    <item>
      <title>Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93763#M18578</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have several VPNs against AWS, it happens that at random the traffic falls and come back again .sometimes I have to install policy to make come back again&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it was with 5900 and 80.10 , and now again with a new 6700 and 80.40&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what&amp;nbsp; I see in the logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IKE_NAT_TRAVERSAL Traffic Dropped from aws to cp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Packet is dropped because an IPsec SA associated with the SPI on the received IPsec packet could not be found"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Unknown SPI: 0x8799740b for UDP encapsulated IPsec packet"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;any idea? cp tech are trying to resolve it for a long time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 13:30:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93763#M18578</guid>
      <dc:creator>kobi_rudy</dc:creator>
      <dc:date>2020-08-10T13:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93788#M18582</link>
      <description>&lt;P&gt;Those messages indicate that the Check Point expired or otherwise removed an existing IPSec VPN tunnel, yet the AWS side still thinks it is up and is sending traffic which the Check Point cannot decrypt because the tunnel no longer exists.&lt;/P&gt;
&lt;P&gt;I assume you have already seen this SK, as AWS will only allow 2 SPIs:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113561&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk113561: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Tunnel to Amazon Web Services (&lt;STRONG&gt;AWS&lt;/STRONG&gt;) is unstable&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Assuming it is not that, make sure the Phase 1 and Phase 2 SA Lifetimes match *exactly* between the configuration on both sides.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 18:16:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93788#M18582</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-08-10T18:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93790#M18583</link>
      <description>&lt;P&gt;We had a similar issue with Amazon AWS; it was fixed by setting the CheckPoint gateway to respond to DPD packets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check for "&lt;EM&gt;DPD responder mode&lt;/EM&gt;" in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec#Scenario%205" target="_blank" rel="noopener"&gt;sk108600&lt;/A&gt;.&amp;nbsp; You have to turn it on via a&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;ckp_regedit&lt;/STRONG&gt;&lt;/EM&gt; on each gateway of the checkpoint cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 18:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/93790#M18583</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2020-08-10T18:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/94006#M18620</link>
      <description>&lt;P&gt;when you change to "dpd responder mode" do you have to cpstop, cpstart ? did you leave the MTU on 1500 or it changed too?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 10:15:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/94006#M18620</guid>
      <dc:creator>kobi_rudy</dc:creator>
      <dc:date>2020-08-13T10:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/94229#M18655</link>
      <description>&lt;P&gt;cp tech said it wont help since we see on the debug files that we are getting "DPD Hello " from amazon, and cp answers "DPD Ack" but some times we don't get the "DPD Hello" from amazon and than the vpn get a reset&amp;nbsp; . amazon checked and say they are sending it- so its a mystery why cp does'nt get it ...&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 05:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/94229#M18655</guid>
      <dc:creator>kobi_rudy</dc:creator>
      <dc:date>2020-08-16T05:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with VPN AMAZON(AWS) ​​CHECK POINT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/131945#M23886</link>
      <description>&lt;P&gt;Hello, kobi.&lt;/P&gt;&lt;P&gt;Have you ever solved s2s vpn between AWS and CP?&lt;/P&gt;&lt;P&gt;I wonder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 09:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-VPN-AMAZON-AWS-CHECK-POINT/m-p/131945#M23886</guid>
      <dc:creator>Jung_Patrick</dc:creator>
      <dc:date>2021-10-18T09:08:34Z</dc:date>
    </item>
  </channel>
</rss>

