<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VTI tunnel problems with vpn accel on in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168451#M28027</link>
    <description>&lt;P&gt;He mentioned vpn accel off, but not sure if that changes the situation...&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 22:31:48 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-19T22:31:48Z</dc:date>
    <item>
      <title>S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168433#M28020</link>
      <description>&lt;P&gt;I'm trying to setup a Site2Site tunnel and it seems "half" working.&lt;/P&gt;&lt;P&gt;For now I'll only troubleshoot one side of the connection:&lt;/P&gt;&lt;P&gt;The remote side is 10.40.171.0/26&lt;/P&gt;&lt;P&gt;Local side is: 10.30.171.0/26&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.40.171.5 can wget a http page on 10.30.171.62 but cannot ping it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firewall which has the directional matching for this site2site is allowing all and I can see the ping coming in. And tcpdump on 10.30.171.62 also sees it, but the reply doesn't seem to come back to 10.40.171.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if I turn off vpn accel (vpn accel off) - it works. And I'm not sure why.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:03:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168433#M28020</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2023-01-19T20:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168438#M28021</link>
      <description>&lt;P&gt;I dont know for sure if regular VPN debugs would help when that feature is off, but TAC case might be worth it to confirm. Maybe do comparison of vpnd.elg file when it works and when it fails.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:13:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168438#M28021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T20:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168449#M28026</link>
      <description>&lt;P&gt;If disabling SecureXL "solves" an issue, the TAC needs to be involved.&lt;BR /&gt;However, I suspect the directional match may be the issue (or at least related).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 21:35:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168449#M28026</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T21:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168451#M28027</link>
      <description>&lt;P&gt;He mentioned vpn accel off, but not sure if that changes the situation...&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 22:31:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168451#M28027</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T22:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168452#M28028</link>
      <description>&lt;P&gt;Yeah, it's still effectively disabling SecureXL (albeit for VPN traffic).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 22:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168452#M28028</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T22:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VTI tunnel problems with vpn accel on</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168454#M28029</link>
      <description>&lt;P&gt;Ah, I see what you mean.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 00:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VTI-tunnel-problems-with-vpn-accel-on/m-p/168454#M28029</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-20T00:50:28Z</dc:date>
    </item>
  </channel>
</rss>

