<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permanent Tunnel with inter-operable Device   in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16058#M2664</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info, Gunther.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem here is the peer end ( AWS) uses a permanent tunnel with DPD which cannot be changed. Hence it is required to enable the same at CheckPoint end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have referred the mentioned SK and also the VPN admin guide but still, I feel that it is clearly not stated whether to enable both the Permanent tunnel option from the VPN community and DPD or just the DPD from Guidbedit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested this in the lab between to Check Point device enabling both Permanent tunnel&amp;nbsp;option and changing&amp;nbsp;the tunnel testing to DPD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Observation: In spite of disabling the default "tunnel testing" feature which works on port 18234 I can still see traffic exchanged with these ports as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76392_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Dec 2018 14:02:29 GMT</pubDate>
    <dc:creator>amith_rao</dc:creator>
    <dc:date>2018-12-14T14:02:29Z</dc:date>
    <item>
      <title>Permanent Tunnel with inter-operable Device</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16056#M2662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a requirement to Establish a Permanent Tunnel between CheckPoint and Interoperable device(AWS). To do so does the configuration only involve enabling DPD from Guidbedit or also&amp;nbsp;it is required to enable the "permanent tunnel" option in the VPN community?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 13:21:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16056#M2662</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2018-12-14T13:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent Tunnel with inter-operable Device</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16057#M2663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is very good explanation:&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative would be to send packets from client at Site behind CP GW to another client behind peer GW in a regular intervall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 13:43:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16057#M2663</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-12-14T13:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Permanent Tunnel with inter-operable Device</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16058#M2664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info, Gunther.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem here is the peer end ( AWS) uses a permanent tunnel with DPD which cannot be changed. Hence it is required to enable the same at CheckPoint end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have referred the mentioned SK and also the VPN admin guide but still, I feel that it is clearly not stated whether to enable both the Permanent tunnel option from the VPN community and DPD or just the DPD from Guidbedit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested this in the lab between to Check Point device enabling both Permanent tunnel&amp;nbsp;option and changing&amp;nbsp;the tunnel testing to DPD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Observation: In spite of disabling the default "tunnel testing" feature which works on port 18234 I can still see traffic exchanged with these ports as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76392_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 14:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permanent-Tunnel-with-inter-operable-Device/m-p/16058#M2664</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2018-12-14T14:02:29Z</dc:date>
    </item>
  </channel>
</rss>

