<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177544#M29600</link>
    <description>&lt;P&gt;All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2023 12:02:16 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-04-06T12:02:16Z</dc:date>
    <item>
      <title>encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortigate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177519#M29592</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, I face an issue whereby the vpn peer site (fortigate 60F fortiOS 6.2.4) need to restart tunnel manually to let traffic run normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually, there is a symptom whereby peer site's encrypted packet being drop by checkpoint firewall (R77.30) with the reason:&amp;nbsp; "encryption failed : clear text should be encrypted" (refer to image below). Hence, appreciate if someeone able to share me the meaning of the message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 09:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177519#M29592</guid>
      <dc:creator>LeeBingKang</dc:creator>
      <dc:date>2023-04-06T09:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177526#M29594</link>
      <description>&lt;P&gt;R77.30 is End of Support.&lt;BR /&gt;However, the message means the gateway received a cleartext packet that it expects to receive encrypted.&lt;BR /&gt;This is quite likely Scenario 3 in:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 09:40:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177526#M29594</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-06T09:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177528#M29595</link>
      <description>&lt;P&gt;Hi phoneboy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the explanation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another things seek your suggestion. Based on the screenshot provided, i found out there is a "PFS" mentioned in the&amp;nbsp; data encryption method and there is no PFS enable both sides based on the current vpn configuration on both site (fortigate and checkpoint).&lt;/P&gt;&lt;P&gt;Hence, is that possible cause checkpoint think that this packet is clear text as it being encrypted with PFS as well?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 10:03:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177528#M29595</guid>
      <dc:creator>LeeBingKang</dc:creator>
      <dc:date>2023-04-06T10:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177530#M29596</link>
      <description>&lt;P&gt;PFS use is very usual, so i do not think that it could be an issue here...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 10:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177530#M29596</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-04-06T10:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177531#M29597</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hmm... PFS is usually use. However, I'm this PFS also use as data encryption is normal in my scenario whereby both sites dont have enable PFS...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 10:40:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177531#M29597</guid>
      <dc:creator>LeeBingKang</dc:creator>
      <dc:date>2023-04-06T10:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177543#M29599</link>
      <description>&lt;P&gt;Can you get ike.elg file from $FWDIR/log directory on the fw and open it in ikeview and see where exactly the connection fails? What phase/packet?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 12:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177543#M29599</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-06T12:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failed : clear text should be encrypted - tunnel between checkpoint firewall, fortiga</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177544#M29600</link>
      <description>&lt;P&gt;All PFS does is compute a fresh encryption key via Diffie Hellman for the Phase2/IPSec tunnel instead of reusing the key calculated during Phase 1, the state of PFS should not affect whether traffic is encrypted or not on either side.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 12:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failed-clear-text-should-be-encrypted-tunnel-between/m-p/177544#M29600</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-06T12:02:16Z</dc:date>
    </item>
  </channel>
</rss>

