<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site-to-site vpn Tunnel to a non Checkpoint Gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18981#M3414</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a site-to-site VPN tunnel between our Checkpoint R80.1 Cluster Gateway and an external Site with a Cisco gateway. Since a few hours the tunnel is still there but seems to run in one direction only or somehow not healthy. I see the packes leaving but no real communications is done.&lt;/P&gt;&lt;P&gt;We also have other pure Checkpoint site-to-site tunnels and I can control those using the "user and tunnel management" oder the "vpn tu" util. But those options are not there for a tunnel to a non-checkpoint gateway. How can I reset the tunnel without doing a cpstop of the cluster?&lt;/P&gt;&lt;P&gt;Any advice?&lt;/P&gt;&lt;P&gt;Thanks. Uwe&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Dec 2018 17:31:22 GMT</pubDate>
    <dc:creator>Uwe_Konrad</dc:creator>
    <dc:date>2018-12-20T17:31:22Z</dc:date>
    <item>
      <title>Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18981#M3414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a site-to-site VPN tunnel between our Checkpoint R80.1 Cluster Gateway and an external Site with a Cisco gateway. Since a few hours the tunnel is still there but seems to run in one direction only or somehow not healthy. I see the packes leaving but no real communications is done.&lt;/P&gt;&lt;P&gt;We also have other pure Checkpoint site-to-site tunnels and I can control those using the "user and tunnel management" oder the "vpn tu" util. But those options are not there for a tunnel to a non-checkpoint gateway. How can I reset the tunnel without doing a cpstop of the cluster?&lt;/P&gt;&lt;P&gt;Any advice?&lt;/P&gt;&lt;P&gt;Thanks. Uwe&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18981#M3414</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-20T17:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18982#M3415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;vpn tu from expert and select your option:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@FW02:0]# vpn tu&lt;/P&gt;&lt;P&gt;********** Select Option **********&lt;/P&gt;&lt;P&gt;(1) List all IKE SAs&lt;BR /&gt;(2) List all IPsec SAs&lt;BR /&gt;(3) List all IKE SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(4) List all IPsec SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(5) Delete all IPsec SAs for a given peer (GW)&lt;BR /&gt;(6) Delete all IPsec SAs for a given User (Client)&lt;BR /&gt;&lt;STRONG&gt;(7) Delete all IPsec+IKE SAs for a given peer (GW)&lt;/STRONG&gt;&lt;BR /&gt;(8) Delete all IPsec+IKE SAs for a given User (Client)&lt;BR /&gt;(9) Delete all IPsec SAs for ALL peers and users&lt;BR /&gt;(0) Delete all IPsec+IKE SAs for ALL peers and users&lt;/P&gt;&lt;P&gt;(Q) Quit&lt;/P&gt;&lt;P&gt;*******************************************&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 18:25:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18982#M3415</guid>
      <dc:creator>Jenni_Guerrica</dc:creator>
      <dc:date>2018-12-20T18:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18983#M3416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Hi Uwe&lt;/P&gt;&lt;P class=""&gt;I have in my settings to multiple site2site tunnels put ike rekey to 3600 sec (60 minuts) and ipsec rekey to 3600 sec.&lt;/P&gt;&lt;P class=""&gt;I would check ike Phase 1 and ipsec phase 2 are the same.&lt;/P&gt;&lt;P class=""&gt;Also found out to disable dead peer detection (dpd) keepalive on Cisco router/firewall&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;I often use from expert mode ssh to gwcluster active node or cluster ip addr&lt;/P&gt;&lt;P class=""&gt;vpn tu&lt;/P&gt;&lt;P class=""&gt;To reset vpn tunnel I use option 7&lt;/P&gt;&lt;P class=""&gt;Check if IKE phase 1 have been establish option 3&lt;/P&gt;&lt;P class=""&gt;Check if Ipsec phase 2 have been establish option 4&lt;/P&gt;&lt;P class=""&gt;To check tunnel list&lt;/P&gt;&lt;P class=""&gt;vpn tu tlist -p &amp;lt;remote peer address&amp;gt;&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;I hope that could help your search for help&lt;/P&gt;&lt;P class=""&gt;Best regards&lt;/P&gt;&lt;P class=""&gt;Kim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 18:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18983#M3416</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-12-20T18:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18984#M3417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;&lt;A _jive_internal="true" class="" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko Ankenbrand&amp;nbsp;&lt;/A&gt;did provide a great hint to to use vpn tu via commandline.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;&lt;A _jive_internal="true" data-containerid="2057" data-containertype="14" data-objectid="3021" data-objecttype="102" href="https://community.checkpoint.com/docs/DOC-3021-show-vpn-routing-on-cli"&gt;https://community.checkpoint.com/docs/DOC-3021-show-vpn-routing-on-cli&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;Commands are:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del ipsec all &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del ipsec ip-addr&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del ipsec ip-addr username&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del all &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del ip-addr&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;vpn tu del ip-addr username&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto; background-color: rgba(255, 255, 255, 0);"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto;"&gt;I use this Command quite often on daily basis&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN style="-webkit-text-size-adjust: auto;"&gt;vpn shell show tunnels ipsec all | grep “&amp;lt;ip address or any info I would like to search for &amp;gt;”&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 18:56:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18984#M3417</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-12-20T18:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18985#M3418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, the syntax with those 3 characters had to be considered, that was my fault!&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 07:15:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18985#M3418</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-21T07:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18986#M3419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, great help! There are different tunnels for the different subnetwork pairs shown. Some show i1 .. i5 and other only i1 .. i2?&amp;nbsp; But this changes frequently. Tunnels seem to be OK now. Merry Xmas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 07:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18986#M3419</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-21T07:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18987#M3420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked the settings: IKE Phase 1 is set to 1.440 min and IPsec to 28.800 seconds, so are not equal and quite large. Could that cause problems?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 07:39:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18987#M3420</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-21T07:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18988#M3421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;Remember timing is your friend.&lt;/P&gt;&lt;P class=""&gt;Make you date and time is correct in both ends.&lt;/P&gt;&lt;P class=""&gt;Secondly check ike rekey is the same as remote peer&lt;/P&gt;&lt;P class=""&gt;Third check ipsec rekey also is the same as remote peer&lt;/P&gt;&lt;P class=""&gt;If for example the check point firewall rekey is every 86400 sec and remote wants to rekey every 28800 the rekey is not in time and sync. Yes I belive this is the reason why it might stop working and you need to reset vpn tunnel.&lt;/P&gt;&lt;P class=""&gt;Merry Christmas&lt;/P&gt;&lt;P class=""&gt;Kim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 10:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18988#M3421</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-12-21T10:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18989#M3422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, what a great help!&lt;/P&gt;&lt;P&gt;I will change this to have it in sync! But do I have to change those settings at both sites? The remote (Cisco) device is operated by a partner institution and I personally have no access to it at the moment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 10:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18989#M3422</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-21T10:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18990#M3423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How large they are does not matter, what does matter is that they match between the Check Point settings and the Cisco settings or you will get intermittent tunnel failures.&amp;nbsp; Note that the Phase 1 timer is expressed by Check Point in minutes, while the Phase 2 timer is expressed in seconds.&amp;nbsp; Most other vendors express both values in seconds so watch out for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other things that can cause intermittent interoperable tunnel failures are data lifesizes and VPN idle timers, make sure these are disabled or set to unreachably high values on the Cisco.&amp;nbsp; Basically anything that causes the tunnel to be brought down early prior to expiration of the SA lifetimes will cause a tunnel hang because the "Delete SA" mechanism does not work reliably in an interoperable VPN scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 13:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18990#M3423</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-12-21T13:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18991#M3424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SA lifetimes (timers) are required on both sides and must be set.&amp;nbsp; Data Lifesizes are off by default on Check Point (but can be enabled via file editing) so it is generally easier to turn them off on the Cisco.&amp;nbsp; Check Point does not support a VPN idle timer for site-to-site VPNs.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 15:25:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18991#M3424</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-12-21T15:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site vpn Tunnel to a non Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18992#M3425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have put the settings of both sides to equal values. Eveything runs smooth and fine now. Thanks to all of you , I will come back for help if needed! Merry Christmas.May be some tome I will have hints for other newbees... Uwe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2018 13:36:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-vpn-Tunnel-to-a-non-Checkpoint-Gateway/m-p/18992#M3425</guid>
      <dc:creator>Uwe_Konrad</dc:creator>
      <dc:date>2018-12-23T13:36:01Z</dc:date>
    </item>
  </channel>
</rss>

