<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225008#M37449</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96626"&gt;@Ihenock1011&lt;/a&gt;&amp;nbsp;Were you able to run the debug mate?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 17:44:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-29T17:44:40Z</dc:date>
    <item>
      <title>IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224753#M37422</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have a checkpoint GW r81.10, where we have created multiple S2S IPSec VPN with other clients, but specifically, with 1 client(StronSwan) , we are having communication problems the tunnel shows UP however the endpoints are unable to communicate one thing I observed different from the other 3rd parties tunnels is under the SmartView the tunnel detail shows monitor UDP encapsulation NATT.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm unsure if this is causing the issue. Could you please help?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 08:47:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224753#M37422</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-28T08:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224819#M37434</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;So, lets start with whats logical here...so, if tunnel is UP, that 100% means phase 1 and 2 settings are good, no issues there. Now, if traffic is not working, its possible that something with vpn enc. domains might not be matching.&lt;/P&gt;
&lt;P&gt;Some questions:&lt;/P&gt;
&lt;P&gt;-is it domain or route based?&lt;/P&gt;
&lt;P&gt;-sta or meshed community?&lt;/P&gt;
&lt;P&gt;-if star, how is routing configured within the community?&lt;/P&gt;
&lt;P&gt;-any NAT used?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 12:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224819#M37434</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T12:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224826#M37437</link>
      <description>&lt;P&gt;Hey Andy&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-is it domain or route based?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is Route based&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-sta or meshed community?&lt;/P&gt;&lt;P&gt;Meshed Community&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-any NAT used?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The pure IP goes through the tunnel there is no NAT from my end.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224826#M37437</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-28T13:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224828#M37438</link>
      <description>&lt;P&gt;K, so if its meshed, then no option to set any routing, which is fine, since every "entity" talks to one another, if you will. So, do you have super basic diagram of maybe example of an IP thats fialing? Just scramble something on a piece of paper and take a picture and upload it, not an issue, just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Did you try ip r g command with an IP address in question to make sure it uses correct route? example ip r g 8.8.8.8&lt;/P&gt;
&lt;P&gt;What about simple zdebug and also basic vpn debug?&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic for 1 minute (ping)&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;fw ctl debug 0 (to turn off debugs)&lt;/P&gt;
&lt;P&gt;Look for vpnd* and ike* files in $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224828#M37438</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T13:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224841#M37439</link>
      <description>&lt;P&gt;Andy, does this debug commands create some issue because it is a production environment if the debug command needs maintenance window kindly please let me know.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:59:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224841#M37439</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-28T13:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224843#M37440</link>
      <description>&lt;P&gt;I had done it probably more than 100 times, never had an issue. Those are super light and I know people sometimes leave them on for 2 weeks and its fine. If you want to be super careful and do it after hours, thats your choice, but personally, I never had any issues, even in production.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:07:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/224843#M37440</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T14:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225008#M37449</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96626"&gt;@Ihenock1011&lt;/a&gt;&amp;nbsp;Were you able to run the debug mate?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 17:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225008#M37449</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T17:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225011#M37450</link>
      <description>&lt;P&gt;After discussing with the partner, they informed me that their endpoint machine is behind a NAT device. When traffic reaches the peer IP, which is also their machine's public IP, it will be translated and forwarded to their internal host. As I understand it, IPSec might not function correctly in this scenario. Both machines behind the peer IP should ideally be configured as they are while traversing the tunnel. Is there a workaround for this situation?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 17:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225011#M37450</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-29T17:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225012#M37451</link>
      <description>&lt;P&gt;Did you make sure NAT is NOT disabled inside vpn community? Also, do you have simple diagram that would illustrate this scenario?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 17:56:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225012#M37451</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T17:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225016#M37452</link>
      <description>&lt;P&gt;Inside VPN community I checked on the advanced tab disable NAT b/n communities. I will attach the free sketch of network topology removing sensitive information&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225016#M37452</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-29T18:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225018#M37453</link>
      <description>&lt;P&gt;That could be the issue then, because you need nat, so that option should not be ticked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225018#M37453</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T18:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225026#M37454</link>
      <description>&lt;P&gt;Okay then let me check that way and I will Update you.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225026#M37454</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-29T19:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225028#M37455</link>
      <description>&lt;P&gt;Sounds good, let us know how it goes.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225028#M37455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T19:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225210#M37480</link>
      <description>&lt;P&gt;I tried the enable and disable NAT it doesnt give me a solution.&lt;/P&gt;
&lt;P&gt;after the debug I get the two outputs from the vpnd.elg file&lt;/P&gt;
&lt;P&gt;TSPayload::constructRelevantTS: checking relevancy of range: "Partners Peer IP x.x.x.x"&lt;BR /&gt;TSPayload::isRelevantTS_ipv4 : range&amp;nbsp; is outside of TS range "Partners Peer IP x.x.x.x". TS range is not relevant.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 20:17:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225210#M37480</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-30T20:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225211#M37481</link>
      <description>&lt;P&gt;Sounds like vpn domain issue...&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 20:32:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225211#M37481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-30T20:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225213#M37482</link>
      <description>&lt;P&gt;what does it mean Andy?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 20:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225213#M37482</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-08-30T20:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225214#M37483</link>
      <description>&lt;P&gt;It would appear something with phase 2 is not matching. Based on that message, most likely vpn enc domains.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 20:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225214#M37483</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-30T20:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225223#M37484</link>
      <description>&lt;P&gt;There is a lot of fabric to be cut here... Like master&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;mentioned, it is most likely a phase 2 issue.&lt;BR /&gt;- Is phase 2 tunnel actually being created? as expert, run the command &lt;STRONG&gt;vpn tu tlist -p [peer_ip]&lt;/STRONG&gt;. There should be one or more tunnels depending on your community and domain config. For traffic to be encrypted an Out SPI must exist.&lt;BR /&gt;- If there are no tunnels active, there is definitely an issue with encryption domains.&lt;BR /&gt;- NATT can work with specific Traffic Selectors(TS). For interoperability sake, I would set VPN Tunnel Sharing as &lt;STRONG&gt;"One Tunnel per Gateway pair"&amp;nbsp;&lt;/STRONG&gt;and apply rules accordingly. This will create a tunnel with 0.0.0.0/0 in both TS, like the following example:&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TS.png" style="width: 713px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27461i545D34779CA38A18/image-size/large?v=v2&amp;amp;px=999" role="button" title="TS.png" alt="TS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, you have to do some debugging to determine exactly what is going on. It can be from a bad proposal to a routing issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 21:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225223#M37484</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2024-08-30T21:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel UP but encryption domains unable to communicate(UDP encapsulation NATT)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225224#M37485</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28648"&gt;@Zolocofxp&lt;/a&gt;&amp;nbsp;for that, but im FAR from being a master lol&lt;/P&gt;
&lt;P&gt;But yes, I agree with your assesment, definitely phase 2 issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2024 01:43:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-Tunnel-UP-but-encryption-domains-unable-to-communicate-UDP/m-p/225224#M37485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-31T01:43:43Z</dc:date>
    </item>
  </channel>
</rss>

