<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN reply attack from trusted sources in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-reply-attack-from-trusted-sources/m-p/231840#M38741</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have more gateways on MDS, all managed by us.&lt;/P&gt;&lt;P&gt;They have a vpn site to site with the main gateway, with permanent tunnels.&lt;/P&gt;&lt;P&gt;From time to time I notices messages like this:&lt;/P&gt;&lt;H2&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="4"&gt;encryption_failure:&amp;nbsp;&lt;/FONT&gt;&lt;FONT size="4"&gt;&lt;A href="https://splunk.acs.rolex.com:8000/fr-FR/app/UI-RLX-af_geneva/search?q=search%20index%3Dfirewall_acs_idx%20action!%3Dallowed%20replay%20encryption_failure%3D%22Warning%3A%20possible%20replay%20attack.%20Sequence%20Number%20*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-30d%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1730884861.17905#" target="_blank" rel="noopener"&gt;Warning: possible replay attack. Sequence Number xxx (Expected yyyy)&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;Which could be the most reasonable explaination and how to prevent it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question: what about a real attack from untrusted source, is there any hardening or the normal secury sequence check is enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2024 09:41:28 GMT</pubDate>
    <dc:creator>Ilovecheckpoint</dc:creator>
    <dc:date>2024-11-06T09:41:28Z</dc:date>
    <item>
      <title>VPN reply attack from trusted sources</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-reply-attack-from-trusted-sources/m-p/231840#M38741</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have more gateways on MDS, all managed by us.&lt;/P&gt;&lt;P&gt;They have a vpn site to site with the main gateway, with permanent tunnels.&lt;/P&gt;&lt;P&gt;From time to time I notices messages like this:&lt;/P&gt;&lt;H2&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="4"&gt;encryption_failure:&amp;nbsp;&lt;/FONT&gt;&lt;FONT size="4"&gt;&lt;A href="https://splunk.acs.rolex.com:8000/fr-FR/app/UI-RLX-af_geneva/search?q=search%20index%3Dfirewall_acs_idx%20action!%3Dallowed%20replay%20encryption_failure%3D%22Warning%3A%20possible%20replay%20attack.%20Sequence%20Number%20*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-30d%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1730884861.17905#" target="_blank" rel="noopener"&gt;Warning: possible replay attack. Sequence Number xxx (Expected yyyy)&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;Which could be the most reasonable explaination and how to prevent it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question: what about a real attack from untrusted source, is there any hardening or the normal secury sequence check is enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 09:41:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-reply-attack-from-trusted-sources/m-p/231840#M38741</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2024-11-06T09:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN reply attack from trusted sources</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-reply-attack-from-trusted-sources/m-p/231843#M38742</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk94984" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk94984: VPN traffic is dropped with "&lt;STRONG&gt;Encryption failure&lt;/STRONG&gt;: &lt;STRONG&gt;Warning&lt;/STRONG&gt;: &lt;STRONG&gt;possible&lt;/STRONG&gt; &lt;STRONG&gt;replay&lt;/STRONG&gt; &lt;STRONG&gt;attack&lt;/STRONG&gt;" log&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111156" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111156: VPN traffic dropped with "&lt;STRONG&gt;Encryption failure&lt;/STRONG&gt;: &lt;STRONG&gt;Warning&lt;/STRONG&gt;: &lt;STRONG&gt;possible&lt;/STRONG&gt; &lt;STRONG&gt;replay&lt;/STRONG&gt; &lt;STRONG&gt;attack&lt;/STRONG&gt;" log&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/could-someone-advice-me-how-to-determine-the-value-for-quot/m-p/122345#M17513" target="_blank" rel="noopener"&gt;could someone advice me how to determine the value for "ipsec.&lt;STRONG&gt;replay&lt;/STRONG&gt;_counter_window_size"&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 10:49:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-reply-attack-from-trusted-sources/m-p/231843#M38742</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-11-06T10:49:22Z</dc:date>
    </item>
  </channel>
</rss>

