<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Loosing SMS to FW connectivity after applied IPsec VPN configuration in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Loosing-SMS-to-FW-connectivity-after-applied-IPsec-VPN/m-p/102747#M19834</link>
    <description>&lt;P&gt;Management traffic does NOT go through the VPN by design.&lt;BR /&gt;That said, there must be a static NAT to the management server that the remote gateways can reach.&lt;BR /&gt;Refer to:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2020 03:54:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-20T03:54:10Z</dc:date>
    <item>
      <title>Loosing SMS to FW connectivity after applied IPsec VPN configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loosing-SMS-to-FW-connectivity-after-applied-IPsec-VPN/m-p/102404#M19810</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am quite new on Checkpoint VPN blade that's why sorry for stupid question !&lt;/P&gt;&lt;P&gt;Basically I am trying to establish IPsec VPN(mesh community) tunnels between HQ and branch sites as below diagram.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture111.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9034iCB26F1DC04740C30/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture111.JPG" alt="Capture111.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However once I apply IPsec configuration, I lost SMS and FW connectivity. I suspect somehow SMS traffic goes into VPN tunnel that's why I lost connectivity between SMS and FW. See below Dubai-FW is disconnected after I push policy.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture123.JPG" style="width: 982px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9037i17F55D6EFE2F3893/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture123.JPG" alt="Capture123.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Even though Dubai-FW is disconnected from SMS, Clients start to ping remote site that means IPSec VPN config successfull&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="client11.JPG" style="width: 589px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9036iE1E5EC1AC4B319C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="client11.JPG" alt="client11.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_up.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9042iC4918C11A63492A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN_up.JPG" alt="VPN_up.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In HQ-FW, I have only defined HQ-LAN-NET [10.1.0.0/24] network.(not added MGMT 192.168.1.0/24)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HQ-1.JPG" style="width: 624px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9035iDB31BA1DD14C1F46/image-size/large?v=v2&amp;amp;px=999" role="button" title="HQ-1.JPG" alt="HQ-1.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;- I have also defined VPN access policies on both Branch and HQ(rule 3 and 4)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HQ_123.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9038i503F259C171B7628/image-size/large?v=v2&amp;amp;px=999" role="button" title="HQ_123.JPG" alt="HQ_123.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Defined NAT policy between branch and HQs( rule 1 and 2) [Not performing NAT between HQ and Branch Networks but SMS]&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HQ_NAT.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9039iE5A1C167F9DD765E/image-size/large?v=v2&amp;amp;px=999" role="button" title="HQ_NAT.JPG" alt="HQ_NAT.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I see from Logs that the traffic between Clients are encrypted and decrypted as below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn_encrypt.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9040iE45A9714CF98C0EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn_encrypt.JPG" alt="vpn_encrypt.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I check VPN blade logs and realized that many drops here below you can see one of them's detail. It specifies "&lt;STRONG&gt;Clear text packet should be encrypted&lt;/STRONG&gt;"&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logg.JPG" style="width: 650px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9041i3CDAEDB7607074D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="logg.JPG" alt="logg.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my perspective the SMS traffic goes into VPN tunnel even though I have excluded 192.168.1.0/24 network from VPN domain in HQ-FW. But don't understand the reason why.&lt;BR /&gt;&lt;BR /&gt;Is anyone help me what couldn't I figure out in this&amp;nbsp; set up ?&lt;BR /&gt;&lt;BR /&gt;I would be appreciated if you have a look.&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 00:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loosing-SMS-to-FW-connectivity-after-applied-IPsec-VPN/m-p/102404#M19810</guid>
      <dc:creator>mely</dc:creator>
      <dc:date>2020-11-18T00:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing SMS to FW connectivity after applied IPsec VPN configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loosing-SMS-to-FW-connectivity-after-applied-IPsec-VPN/m-p/102747#M19834</link>
      <description>&lt;P&gt;Management traffic does NOT go through the VPN by design.&lt;BR /&gt;That said, there must be a static NAT to the management server that the remote gateways can reach.&lt;BR /&gt;Refer to:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 03:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loosing-SMS-to-FW-connectivity-after-applied-IPsec-VPN/m-p/102747#M19834</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-20T03:54:10Z</dc:date>
    </item>
  </channel>
</rss>

