<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121917#M22589</link>
    <description>&lt;P&gt;Can you show Tunnels on Community and double-click it to see if VPN is up both ways? And show the policy the error refers to ?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 11:26:30 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-06-23T11:26:30Z</dc:date>
    <item>
      <title>VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121912#M22586</link>
      <description>&lt;P&gt;Hello Mates,&lt;/P&gt;&lt;P&gt;I am configuring VPN IPSEC between Juniper SRX and Checkpoint R80.10 like this topology. The tunnel already is UP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tp1.png" style="width: 848px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12290i04F0EF8C91366DA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="tp1.png" alt="tp1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;TUNNEL is UP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tp2.png" style="width: 827px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12291i5F77814D07298DB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="tp2.png" alt="tp2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I ping from Juniper-LAN to Checkpoint-LAN. Not success! I saw log in checkpoint,it says that &lt;STRONG&gt;"According to the policy the packet should not be decrypted"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tp3.png" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12292iB654A68211FDA3AF/image-size/large?v=v2&amp;amp;px=999" role="button" title="tp3.png" alt="tp3.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I search on some forums, &lt;STRONG&gt;they said that is because of overlapping subnets of two site (Juniper and Checkpoint). But in my topology, it is definitely&amp;nbsp;not overlapping anything.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Could someone please help me know why?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 10:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121912#M22586</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-06-23T10:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121914#M22587</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk167655 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 11:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121914#M22587</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-06-23T11:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121916#M22588</link>
      <description>&lt;P&gt;Hello bro,&lt;/P&gt;&lt;P&gt;Here I'm not using NAT in my topology (is this OK?), Here is my VPN Domain&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tp3.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12293iD07F4EED8723434B/image-size/large?v=v2&amp;amp;px=999" role="button" title="tp3.png" alt="tp3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 11:12:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121916#M22588</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-06-23T11:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121917#M22589</link>
      <description>&lt;P&gt;Can you show Tunnels on Community and double-click it to see if VPN is up both ways? And show the policy the error refers to ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 11:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121917#M22589</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-06-23T11:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121930#M22591</link>
      <description>&lt;P&gt;Here is an excerpt from a VPN Interoperability handout I provide when teaching the CCTA class that explains this somewhat confusing error message, based on your log entry it looks like either your firewall's VPN domain or the peer object's VPN domain are not defined correctly and completely:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Packet was Decrypted, but Policy Says Packet Should not have been&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;decrypted&lt;/STRONG&gt; – An encrypted packet was received by your firewall that was&lt;BR /&gt;decrypted successfully but one of the following has occurred:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;• The source IP address on the decrypted packet does not correspond to&lt;BR /&gt;the known VPN domain of the VPN peer, or the destination IP address&lt;BR /&gt;does not fall within your own firewall's defined VPN domain. This is&lt;BR /&gt;most commonly caused by inappropriate NAT rules being applied to VPN&lt;BR /&gt;traffic on the VPN peer side; selecting Disable NAT in VPN Community&lt;BR /&gt;on the VPN peer’s settings will usually solve this problem.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;• There is an overlap between the VPN domain of your firewall and the&lt;BR /&gt;VPN domain definition of the peer firewall; you or your peer may have&lt;BR /&gt;defined an overly-generous conflicting network such as 10.0.0.0/8 or&lt;BR /&gt;192.168.0.0/16 in your VPN domain and/or antispoofing setup. The&lt;BR /&gt;command &lt;STRONG&gt;vpn overlap_encdom communities –s&lt;/STRONG&gt; run on the Security&lt;BR /&gt;Gateway will display any VPN Domain overlap conditions. Consider using&lt;BR /&gt;a Group w/ Exclusion object (where the peer’s VPN domain is excluded)&lt;BR /&gt;as your firewall’s VPN domain to get around this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 13:21:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121930#M22591</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-23T13:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121934#M22593</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;brought up a good suggestion. Try command vpn overlap_encdom and see if you get any results. That would tell you 100% for sure if it overlaps or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 13:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121934#M22593</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-23T13:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121995#M22617</link>
      <description>&lt;P&gt;Hello Mr. Timothy_Hall,&lt;/P&gt;&lt;P&gt;After I run command&amp;nbsp;&lt;STRONG&gt;vpn overlap_encdom communities –s ,&lt;/STRONG&gt; it show no overlap domain&lt;STRONG&gt;. &lt;/STRONG&gt;Then I re-configure VPN from the begin on Checkpoint side, and then found that I forgot to adjust "Topology section" of LAN-Juniper-subnet in "Interoperable Device" like below: from "external" to "internal". Then error was resolved. Thanks for support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tp1.png" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12298iDADF4E83CD23BB08/image-size/large?v=v2&amp;amp;px=999" role="button" title="tp1.png" alt="tp1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for support!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 07:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/121995#M22617</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-06-24T07:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSEC between Juniper SRX and Checkpoint R80.10 error</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/122131#M22637</link>
      <description>&lt;P&gt;Ok, great...so really nothing terribly wrong you did, thats small mistake anyone can make.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 22:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSEC-between-Juniper-SRX-and-Checkpoint-R80-10-error/m-p/122131#M22637</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-24T22:59:55Z</dc:date>
    </item>
  </channel>
</rss>

