<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issues with VPN directional  match conditioin in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/issues-with-VPN-directional-match-conditioin/m-p/120405#M22384</link>
    <description>&lt;P&gt;You need to use Route-Based VPNs with an AWS endpoint.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;More details about what exactly you configured and how you observed the failed behavior would be helpful.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Jun 2021 03:22:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-06-05T03:22:59Z</dc:date>
    <item>
      <title>issues with VPN directional  match conditioin</title>
      <link>https://community.checkpoint.com/t5/General-Topics/issues-with-VPN-directional-match-conditioin/m-p/120241#M22360</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; i am trying to set up a site-to-site VPN with AWS. i have already followed the instructions generated by AWS with regard to configuring the Checkpoint side. i have created the necessary VPN tunnel interfaces, interoperable devices, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp; i have set up awsvpn VPN Community, and set our Checkpoint gateway as central gateway, and the defined interoperable device as satellite gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; i have set up security policy rules for the subnets in question, and have set up Directional Matching conditions as follows:&lt;/P&gt;&lt;P&gt;Internal_clear -&amp;gt; awsvpn&lt;/P&gt;&lt;P&gt;awsvpn -&amp;gt; awsvpn&lt;/P&gt;&lt;P&gt;awsvpn -&amp;gt; Internal_clear&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; On the AWS side, the vpn tunnel is reported to be Available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; i can see tunnel_traffic going back and forth from AWS and our Checkpoint gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Despite all that, traffic coming from our onprem subnet is still being blocked despite the defined rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Removing the Directional Match Conditions seems to fix the blocking issue, and i can see packets being allowed through...but end result is both ends still cannot reach the other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Any suggestions on where i should check? Any help would be much appreciated. Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 02:40:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/issues-with-VPN-directional-match-conditioin/m-p/120241#M22360</guid>
      <dc:creator>albertcuy</dc:creator>
      <dc:date>2021-06-03T02:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: issues with VPN directional  match conditioin</title>
      <link>https://community.checkpoint.com/t5/General-Topics/issues-with-VPN-directional-match-conditioin/m-p/120405#M22384</link>
      <description>&lt;P&gt;You need to use Route-Based VPNs with an AWS endpoint.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;More details about what exactly you configured and how you observed the failed behavior would be helpful.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 03:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/issues-with-VPN-directional-match-conditioin/m-p/120405#M22384</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-05T03:22:59Z</dc:date>
    </item>
  </channel>
</rss>

