<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234770#M39227</link>
    <description>&lt;P&gt;Are you sure the Sophos is not set for AES-256-GCM in Phase 2?&amp;nbsp; Not the same as AES-256.&amp;nbsp; As a test try setting P2 to AES-128 and see what happens.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2024 14:12:01 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2024-12-05T14:12:01Z</dc:date>
    <item>
      <title>Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234752#M39221</link>
      <description>&lt;P&gt;Site-to-Site IPSec&amp;nbsp;between Check Point and&amp;nbsp;3rd Party Gateway: Sophos&lt;/P&gt;&lt;P&gt;Issue is present on VSX deployment on one Virtual System&lt;/P&gt;&lt;P&gt;&lt;U&gt;We've checked the policy several times, and there is no issues like lifetime mismatch, etc...&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN Tunnel is up but we keep receiving errors:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Informational Exchange Received: Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tunnel with IKEv1 is up, with IKEv2 is down with error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Quick Mode Failed to match proposal: Transform: AES-256, SHA1, Group 2 (1024 bit), Tunnel; Reason: Wrong value for: Key Length&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DPD Responder Mode:&lt;STRONG&gt;is enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Note: The DPD mechanism is based on IKE SA keys. In some situations, the Check Point Security Gateway deletes IKE SAs, and a VPN peer, usually a 3rd Party gateway, sends DPD requests and does not receive a response. As a result, the VPN peer concludes that the Check Point Security Gateway is down. The VPN peer can then delete the IKE and IPsec keys, which causes encrypted traffic from the Check Point Security Gateway to be dropped by the remote peer."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Tunnel-Management.htm#" target="_blank" rel="noopener"&gt;SmartConsole&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt;click&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Menu&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Global properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Advanced&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Configure&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;VPN Advanced Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;VPN IKE properties&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;keep_IKE_SAs&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;OK&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Install the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Access Control&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Policy. - &lt;STRONG&gt;this is already enable&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I try to&amp;nbsp; change the settings with&amp;nbsp;GuiDBEdit Tool?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;DPD responder mode&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Permanent tunnel mode based on DPD&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;___________________________________________________________________&lt;/P&gt;&lt;P&gt;I have no experience in working with DPD and I need someone who can help me with that.&lt;/P&gt;&lt;P&gt;Am I even looking in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 13:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234752#M39221</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234757#M39222</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/90937"&gt;@SinisaZG&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version is this? I ask, because I believe back in R80.40, when permanent tunnel option is enabled in vpn community, there is no need to change anything in guidbedit for dpd and Im referring to below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28676i1F914105A3BF62AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 13:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234757#M39222</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T13:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234759#M39224</link>
      <description>&lt;P&gt;Sorry I&amp;nbsp;I forgot to put the version. R81.20, Take 76.&lt;/P&gt;&lt;P&gt;The settings are the same as yours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 13:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234759#M39224</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T13:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234761#M39225</link>
      <description>&lt;P&gt;On your CP object participating in the vpn tunnel, IF its set to permant tunnel as below, then guidbedit should say dpd, NOT tunnel test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28677iFEA9269ACB2D21C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 13:43:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234761#M39225</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T13:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234769#M39226</link>
      <description>&lt;P&gt;I tried that already... same error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 14:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234769#M39226</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T14:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234770#M39227</link>
      <description>&lt;P&gt;Are you sure the Sophos is not set for AES-256-GCM in Phase 2?&amp;nbsp; Not the same as AES-256.&amp;nbsp; As a test try setting P2 to AES-128 and see what happens.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 14:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234770#M39227</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-12-05T14:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234771#M39228</link>
      <description>&lt;P&gt;I would make sure both cp object AND interoperable are set to dpd and same in the community and then install policy and test. If same issue, then run basic vpn debug and see what shows up on the other end.&lt;/P&gt;
&lt;P&gt;I would also confirm 100% phase 2 settings do indeed match on both sides.&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-replicate the issue&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;disable debug -&amp;gt; fw ctl debug 0&lt;/P&gt;
&lt;P&gt;get ike* and vpnd* files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 14:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234771#M39228</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T14:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234772#M39229</link>
      <description>&lt;P&gt;Yep, I am sure that settings are the same. Already tried with AES-128.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 14:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234772#M39229</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T14:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234773#M39230</link>
      <description>&lt;P&gt;See if either of below helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Informational-Exchange-Received-Delete-IKE-SA-from-Peer-xx-xx-xx/td-p/61000" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Informational-Exchange-Received-Delete-IKE-SA-from-Peer-xx-xx-xx/td-p/61000&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk13836" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk13836&lt;/A&gt;&lt;/P&gt;
&lt;P lang="x-none"&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/VPN-Check-Point-Palo-Alto-issue/m-p/220276#M42146" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/VPN-Check-Point-Palo-Alto-issue/m-p/220276#M42146&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 14:17:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234773#M39230</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234796#M39232</link>
      <description>&lt;P&gt;&lt;SPAN&gt;100% phase 2 settings do indeed match on both sides - checked several times.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VPN: 'iked' is disabled. or&amp;nbsp;vpn: Address 'X.X.X.X' is not handled by any IKED daemon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I will create a TAC case for this, thanks for help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 17:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234796#M39232</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T17:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234797#M39233</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will create a TAC case for this, thanks for help.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 17:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234797#M39233</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-12-05T17:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Informational Exchange Received Delete IPSEC-SA from Peer: X.X.X.X; SPIs: 00003ada</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234798#M39234</link>
      <description>&lt;P&gt;Happy to do remote if you are allowed to, let me know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 17:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Informational-Exchange-Received-Delete-IPSEC-SA-from-Peer-X-X-X/m-p/234798#M39234</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T17:39:52Z</dc:date>
    </item>
  </channel>
</rss>

