<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN downtime in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188465#M31592</link>
    <description>&lt;P&gt;Hello, my friend.&lt;/P&gt;
&lt;P&gt;Just so that the concept can be clear to me, Phase 2 of the default VPNs, it is clear that it comes set to 3600 seconds.&lt;/P&gt;
&lt;P&gt;This means that if in 1 hour there is no traffic between a Site1 HOST and a Site2 HOST, "visually" the VPN in phase 2 will appear as "down", right?&lt;/P&gt;
&lt;P&gt;And I would understand that the VPN in general, if in 1 day, there is no traffic at all, visually, it will also be "down", until traffic is generated again, is my interpretation correct?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 14:42:12 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-08-02T14:42:12Z</dc:date>
    <item>
      <title>S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188314#M31572</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;A query, &lt;BR /&gt;I am aware that, in a Checkpoint S2S VPN against third parties, when there is no interesting traffic "crossing" the VPN for a certain period of time, these VPNs "go down".&lt;/P&gt;
&lt;P&gt;My question is, how much time does Checkpoint "count" to "down the VPN"?&lt;/P&gt;
&lt;P&gt;Assuming that the VPN will be up again, when interesting traffic is generated again.&lt;/P&gt;
&lt;P&gt;Hopefully, someone can clarify this doubt for me, please.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 20:01:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188314#M31572</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-01T20:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188316#M31573</link>
      <description>&lt;P&gt;I would think the VPN would go down once the IPSec SA expires.&lt;/P&gt;&lt;P&gt;From the CLI you can type "vpn tu tlist -p x.x.x.x" and see a tunnel expiration time.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 20:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188316#M31573</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2023-08-01T20:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188319#M31574</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thank you for your comment.&lt;/P&gt;
&lt;P&gt;The output of the command shows me the following.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNS2S.png" style="width: 989px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21927i624EED5F68A50783/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPNS2S.png" alt="VPNS2S.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Trying to interpret the information correctly, I can assume that if there is no more interesting traffic through the tunnel, the VPN will be down today?&lt;/P&gt;
&lt;P&gt;In other words, the tunnel will only "hold" for 1 hour, if it does not see any traffic passing through it?&lt;/P&gt;
&lt;P&gt;Is there any way to "extend" this time?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 20:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188319#M31574</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-01T20:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188325#M31575</link>
      <description>&lt;P&gt;Looking at this closer with some of my VPNs, the tunnel status is based off two items:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;State = "UP" - Means Phase 1 and Phase 2 are proper. Everything should be working.&lt;/LI&gt;&lt;LI&gt;State = "UP - Phase1" - Means you only have Phase 1 and Phase 2 is not working because of configuration or the IPSec SA has expired, if it has expired, you can bring it to "UP" by generating the interesting traffic to make a new IPSec SA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The CLI I provided is only giving insight for Phase 2, so once that tunnel has "expired" the tunnel will show "UP - Phase1" until that ages out. I cannot find how to view the expiration for Phase 1 (by default Phase1 is 24hours).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to extend the time. If you want to keep the tunnel online you can configure permanent tunnels between 2 Check Point firewalls, or with a third-party you can use DPD. You can always add a monitor system to the VPN and just send constant pings across too.&lt;/P&gt;&lt;P&gt;If you mean how to adjust the hour window, you can change those settings within the advanced options of the VPN community you are working with. By default Phase 1 is setup for 1440 minutes (24hours) and Phase 2 is setup for 3600 seconds (1hour), if you change these timers, they need to match on both sides of the VPN tunnel.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 21:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188325#M31575</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2023-08-01T21:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188331#M31576</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;So, to keep the VPN "up" (My environment is a VPN against a third party, not Checkpoint), it is advisable for us to enable DPD (As I remember, DPD is disabled by default, right?).&lt;/P&gt;
&lt;P&gt;Does DPD affect a particular community, or is it something that affects all the VPNs I have in my GW?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 22:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188331#M31576</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-01T22:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188333#M31577</link>
      <description>&lt;P&gt;Bro, there is old school way to keep any VPN tunnel up. Just keep constant ping going to something on the other end and that will have tunnel UP all the time...same goes for say vpn client inactivity set. I know its not the best way, but it works. Otherwise, just set DPD method, or permanent tunnel.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 23:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188333#M31577</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-01T23:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188336#M31578</link>
      <description>&lt;P&gt;You can also use this script as per below link.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/One-liner-to-show-VPN-S2S-tunnels-on-gateway/m-p/150205#M962" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/One-liner-to-show-VPN-S2S-tunnels-on-gateway/m-p/150205#M962&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 23:48:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188336#M31578</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-01T23:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188340#M31579</link>
      <description>&lt;P&gt;Bro,&lt;/P&gt;
&lt;P&gt;So, activating DPD for a single community will guarantee me that the tunnel will stay up all the time?&lt;/P&gt;
&lt;P&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 00:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188340#M31579</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-02T00:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188341#M31580</link>
      <description>&lt;P&gt;Bro, no offense, I dont even guarantee I will be alive tomorrow LOL&lt;/P&gt;
&lt;P&gt;Anyway, yes, DPD means peer is configured for permanent tunnel. Make sure community is set that way too and config is indeed set for such a tunnel.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 01:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188341#M31580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-02T01:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188343#M31581</link>
      <description>&lt;P&gt;Does activating DPD "alter" all the VPNs I have in my GW?&lt;/P&gt;
&lt;P&gt;Or can DPD be activated for each community independently?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 01:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188343#M31581</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-02T01:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188344#M31582</link>
      <description>&lt;P&gt;It can be done independently, but it goes by interoperable object. In R81+, if you set community as permanent tunnel type, it sets object as DPD automatically.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 01:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188344#M31582</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-02T01:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188465#M31592</link>
      <description>&lt;P&gt;Hello, my friend.&lt;/P&gt;
&lt;P&gt;Just so that the concept can be clear to me, Phase 2 of the default VPNs, it is clear that it comes set to 3600 seconds.&lt;/P&gt;
&lt;P&gt;This means that if in 1 hour there is no traffic between a Site1 HOST and a Site2 HOST, "visually" the VPN in phase 2 will appear as "down", right?&lt;/P&gt;
&lt;P&gt;And I would understand that the VPN in general, if in 1 day, there is no traffic at all, visually, it will also be "down", until traffic is generated again, is my interpretation correct?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188465#M31592</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-02T14:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188467#M31594</link>
      <description>&lt;P&gt;Shortly, no. Phase 2 timer only defines how long the symmetric key is valid. Once it is timed out, it will be renegotiated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188467#M31594</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-02T14:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188470#M31596</link>
      <description>&lt;P&gt;I understand.&lt;/P&gt;
&lt;P&gt;What we are looking for, is to have an "idea" of how long is the maximum time that the tunnel can be without traffic crossing through it, so that the VPN visually looks "down".&lt;/P&gt;
&lt;P&gt;Is this something that is defined in the configuration of a VPN community?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188470#M31596</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-02T15:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN downtime</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188478#M31598</link>
      <description>&lt;P&gt;One of our customers had the same question few years back and we thought it was possible to define it in Guidbedit, but TAC was not successful either, so we never really got an official answer if there was any sort of time that needs to pass by before tunnel is officially considered as down.&lt;/P&gt;
&lt;P&gt;You can open a case and ask about it I guess, but I hardly doubt its different.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-downtime/m-p/188478#M31598</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-02T15:57:28Z</dc:date>
    </item>
  </channel>
</rss>

