<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122787#M22729</link>
    <description>&lt;P&gt;Im pretty sure I know answer to this, but what is the 3rd party you are referring to?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2021 02:26:02 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-07-02T02:26:02Z</dc:date>
    <item>
      <title>IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122542#M22692</link>
      <description>&lt;P&gt;Hi, we are facing a weird issue with one of out gateways trying to connect to a third party device. The tunnel was working fine until it went down and now it is not even possible to establish phase1. I am seeing the following in the vpn.elg file:&lt;/P&gt;&lt;P&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57] fwipsechost_from_ipxaddr: calling GetEntryXIsakmpObjectsHash for 181.4.26.12 returned obj: 0x9ba1ad0&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57] GetEntryCommunityHashX: received ipaddr: 12.26.4.181 as key, found community: S2S_3Party&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57] FindCommonCommunity: Found common community (IPv4 addr=12.26.4.181) (S2S_3Party) for GW_remote&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57][CPLOG] --&amp;gt; CCplogUtils::FillVarArg&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57][CPLOG] CCplogUtils::FillVarArg: str:&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57][CPLOG] CCplogUtils::FillVarArg: str:&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57][CPLOG] CCplogUtils::FillVarArg: str: IKEv2&lt;BR /&gt;[vpnd 6209 4092888992]@GW1[29 Jun 22:28:57][CPLOG] CCplogUtils::FillVarArg: str: Initial exchange: Exchange failed: timeout reached.&lt;/P&gt;&lt;P&gt;In tcpdump I can see that the IKE negotiation is stuck in IKE_SA_INIT phase, but I can see Initiator Request and Responder Response messages every time, but negotiation fails. Any idea about what could be happening? Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 21:12:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122542#M22692</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-06-29T21:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122770#M22727</link>
      <description>&lt;P&gt;Maybe fw ctl zdebug drop | grep x.y.z.w will tell you if the packet is actually getting dropped for some reason?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 21:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122770#M22727</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-01T21:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122787#M22729</link>
      <description>&lt;P&gt;Im pretty sure I know answer to this, but what is the 3rd party you are referring to?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 02:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122787#M22729</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-02T02:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122818#M22736</link>
      <description>&lt;P&gt;My thoughts exactly, the remote device is not a Cisco and is probably a Juniper/Fortinet/Sonicwall which will silently discard any&amp;nbsp; subnet/Proxy-IDs proposals it doesn't like.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 13:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122818#M22736</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-02T13:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122821#M22737</link>
      <description>&lt;P&gt;I was more thinking one of the cloud providers actually.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 14:01:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/122821#M22737</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-02T14:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123044#M22753</link>
      <description>&lt;P&gt;Thank you, going to do that if the tunnel goes down again. It is UP now and working for some days for some reason.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 08:38:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123044#M22753</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-07-06T08:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123046#M22755</link>
      <description>&lt;P&gt;3rd party is a cloud provider and using an unknown device based on Linux.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 08:52:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123046#M22755</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-07-06T08:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN Stuck in IKE_SA_INIT (IKEv2)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123047#M22756</link>
      <description>&lt;P&gt;It looked more like an issue from Check Point side, because I was seeing incoming&amp;nbsp;&lt;SPAN&gt;Responder Response packets from the cloud provider, and the Check Point was showing messages related to timeout and invalid incomming message.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, the tunnel has been up since some days ago and I have opened a case to TAC.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone for your help and messages.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 08:58:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN-Stuck-in-IKE-SA-INIT-IKEv2/m-p/123047#M22756</guid>
      <dc:creator>Debon27</dc:creator>
      <dc:date>2021-07-06T08:58:47Z</dc:date>
    </item>
  </channel>
</rss>

