<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206690#M34298</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is just setup as a site to site vpn, we do not use vti's on our CP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 15:08:05 GMT</pubDate>
    <dc:creator>JonWilliams</dc:creator>
    <dc:date>2024-02-21T15:08:05Z</dc:date>
    <item>
      <title>IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206681#M34294</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup a site to site vpn to third party (amazonaws) from our CP R81.20 but the tunnel is not coming up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;initiating traffic on our back end, i&amp;nbsp; can see on the tcpdump ext int that we are sending a isakmp and receive 1 back but thats where it stops. Tunnel does not come up&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas please ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP xxxxxxx.co.uk.isakmp &amp;gt; xxxxxxxxxxxx.amazonaws.com.isakmp: isakmp: parent_sa ikev2_init[I]&lt;/P&gt;&lt;P&gt;&amp;nbsp;IPxxxxxxxxxxxamazonaws.com.isakmp &amp;gt; xxxxxxxxx.co.uk.isakmp: isakmp: parent_sa ikev2_init[R]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 14:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206681#M34294</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2024-02-21T14:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206686#M34295</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Are you using numbered or unnumbered vti's? Set as permanent tunnel? Mesage me offline, happy to do remote if you allow it. Im fairly experienced with Azure VPN tunnels, though have done couple with AWS as well.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 14:43:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206686#M34295</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T14:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206690#M34298</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is just setup as a site to site vpn, we do not use vti's on our CP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206690#M34298</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2024-02-21T15:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206693#M34299</link>
      <description>&lt;P&gt;Okay..is it set as permanent tunnel via community object tunnel management or no? How do you have below configured?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24581i3F2A2D2989DEF040/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206693#M34299</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T15:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206694#M34300</link>
      <description>&lt;P&gt;And which documentation did you follow when configuring the S2S VPN ?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:11:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206694#M34300</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-02-21T15:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206695#M34301</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set Permanent is not ticked and vpn tunnel sharing is "one vpn tunnel per subnet pair"&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:16:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206695#M34301</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2024-02-21T15:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206698#M34302</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just followed the phase 1 and 2 proposals set by the third party. Sorry im not great on CP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the third party use vti im guessing that would not be an issue if we dont ?&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206698#M34302</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2024-02-21T15:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206703#M34303</link>
      <description>&lt;P&gt;Thats fine, dont worry, we are here to help! Put it this way, for route based VPN, you need VTI. Have a look at my post below, I know its about Azure, but I explained it the best I could. Happy to do remote if you allow that, not an issue. I really feel I could help you with it.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:23:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206703#M34303</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T15:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206704#M34304</link>
      <description>&lt;P&gt;Ok, no problem. All debug shows is that you guys are I as initiator, and AWS is R, as in responder, but clearly config is not matching somewhere, as even phase 1 does not seem to be working.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:25:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206704#M34304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T15:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206725#M34307</link>
      <description>&lt;P&gt;Did you also do simple vpn debug?&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-try generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff (after 2-3 mins)&lt;/P&gt;
&lt;P&gt;Look for ike and vpnd files in $FWDIR.log dir&lt;/P&gt;
&lt;P&gt;Get them off the fw and examine for any relevant IPs, or you can simply grep -i from ssh as well&lt;/P&gt;
&lt;P&gt;ie from expert mode -&amp;gt; grep -i 2.3.4.5 vpnd.elg (just replace 2.3.4.5 with actual peer external IP)&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 17:09:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-VPN/m-p/206725#M34307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T17:09:52Z</dc:date>
    </item>
  </channel>
</rss>

