<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One way traffic is dropping in Site to Site VPN with DAIP gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/208968#M34623</link>
    <description>&lt;P&gt;I would contact CP TAC to get this resolved asap!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 08:44:30 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2024-03-18T08:44:30Z</dc:date>
    <item>
      <title>One way traffic is dropping in Site to Site VPN with DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/208954#M34621</link>
      <description>&lt;P&gt;I have configured site to site VPN between Checkpoint(R81.20 JHF T41) and Strongswan in Ubuntu(DAIP gateway).&lt;/P&gt;&lt;P&gt;Assume Host-A is behind Checkpoint and Host-B is behind&amp;nbsp;Strongswan&amp;nbsp;in Ubuntu.&lt;BR /&gt;One way traffic is dropping in Site to Site VPN with DAIP gateway&lt;/P&gt;&lt;P&gt;I have configured site to site VPN between Checkpoint(R81.20 JHF T41) and Strongswan in Ubuntu(DAIP gateway).&lt;/P&gt;&lt;P&gt;Assume Host-A is behind Checkpoint and Host-B is behind&amp;nbsp;Strongswan&amp;nbsp;in Ubuntu.&lt;/P&gt;&lt;P&gt;VPN tunnel is up and traffic initiated from Host-B to Host-A is working, But traffic initiated from Host-A to Host-B is not working.&lt;/P&gt;&lt;P&gt;Smartlog shows traffic is accepted and encrypted in community, But when checked on zdebug it is getting dropped with below error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zdebug when pinging from Host-A to Host-B:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ping.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24885iCD75A4A3279BEF9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="ping.JPG" alt="ping.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;zdebug when initiating telnet from Host-A to Host-B on port 443:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="telnet.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24886i6243C609C401E498/image-size/large?v=v2&amp;amp;px=999" role="button" title="telnet.JPG" alt="telnet.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;CP VPN status:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp vpn.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24887i6FFFA19BE7AB65DA/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp vpn.JPG" alt="cp vpn.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Strongswan VPN status:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="strongswan vpn.JPG" style="width: 927px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24888iFF94026B33AF6A1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="strongswan vpn.JPG" alt="strongswan vpn.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My understating as per the logs, Checkpoint instead of sending traffic on existing tunnel, It is trying to create new tunnel for the encryption domain and failing in process as the peer is dynamic in interoperable object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to fix this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 06:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/208954#M34621</guid>
      <dc:creator>Pavan_Kumar</dc:creator>
      <dc:date>2024-03-18T06:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: One way traffic is dropping in Site to Site VPN with DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/208968#M34623</link>
      <description>&lt;P&gt;I would contact CP TAC to get this resolved asap!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:44:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/208968#M34623</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-18T08:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: One way traffic is dropping in Site to Site VPN with DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/209050#M34649</link>
      <description>&lt;P&gt;StrongSWAN is treated as a Remote Access Client, to the best of my knowledge.&lt;BR /&gt;Which means: make sure this is enabled:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24891i6C5EC2E60A7235FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, I suggest a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 16:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/209050#M34649</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-18T16:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: One way traffic is dropping in Site to Site VPN with DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/209165#M34671</link>
      <description>&lt;P&gt;Hi.. The issue is resolved. Sharing my findings and fix, thought it might help community members.&lt;/P&gt;&lt;P&gt;In my configuration, local encryption domain is 172.28.1.10/32(Specific vpn domain for the community) and remote encryption domain is 10.203.144.0/30.&lt;BR /&gt;As my local encryption domain is single host, I created a group and added Host Object 172.28.1.10/32, and called the group on specific vpn domain for the community&lt;/P&gt;&lt;P&gt;As per vpn debug, when host behind the checkpoint initiates traffic it is not considering the Host Object used on specific vpn domain on the community, Instead checkpoint is considering Network Object(which the IP 172.28.1.10 belongs) from the default vpn domain, and trying to negotiate new phase-2(local 172.28.1.0/24 in my case and remote 10.203.144.0/30). As the peer end phase-2 configured with only /32, the new phase-2 negotiation is failing. Due to this traffic initiated from host behind checkpoint is not working.&lt;/P&gt;&lt;P&gt;Assuming checkpoint doesn't consider host object on encryption domain, I created Network Object 172.28.1.10/32 and replaced it with host object on the group. Post that issue resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 18:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-way-traffic-is-dropping-in-Site-to-Site-VPN-with-DAIP/m-p/209165#M34671</guid>
      <dc:creator>Pavan_Kumar</dc:creator>
      <dc:date>2024-03-19T18:55:30Z</dc:date>
    </item>
  </channel>
</rss>

