<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ikev2 Phase2 is not getting up in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236061#M39476</link>
    <description />
    <pubDate>Tue, 17 Dec 2024 16:50:33 GMT</pubDate>
    <dc:creator>MaheshCheck</dc:creator>
    <dc:date>2024-12-17T16:50:33Z</dc:date>
    <item>
      <title>Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236013#M39450</link>
      <description>&lt;P&gt;Can anyone help me to resolve the issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKEv2 Phase2 is not getting up and configuration seems to be fine from both the sides&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version :R81.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 13:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236013#M39450</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T13:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236018#M39453</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/115227"&gt;@MaheshCheck&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Everyone of us, were is similiar situations. Please provide more&amp;nbsp; info about the issue.&lt;/P&gt;
&lt;P&gt;I suppose this is a s2s VPN connection.&lt;/P&gt;
&lt;P&gt;What is GW version and jumbo take?&lt;/P&gt;
&lt;P&gt;Until this try the followings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;reset the tunnel on both sides&lt;/LI&gt;
&lt;LI&gt;check the ENC_DOMs on both sides, maybe eg.: somewhere the netmask is wrong&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;And check this SK:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk60318" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk60318&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 14:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236018#M39453</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-17T14:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236021#M39455</link>
      <description>&lt;P&gt;We need way more info in order to help properly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, what is the other side? Do enc settings match? route or domain based? star or mesh? How is tunnel mgmt option configured? ikev1 or ikev2?&lt;/P&gt;
&lt;P&gt;Any logs indicating the failure?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 14:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236021#M39455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-17T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236055#M39470</link>
      <description>&lt;P&gt;Yes ,its S2S VPN&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall version is &lt;SPAN&gt;R81.20 Jumbo Hotfix Take 84&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When we select single host ,the tunnel is getting up however whenever we select network , the tunnel is not coming up&lt;/P&gt;&lt;P&gt;We have checked the configuration from both the sides and all network details are correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;reset the tunnel on both sides-tried but not working&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 17 Dec 2024 16:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236055#M39470</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T16:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236057#M39472</link>
      <description>&lt;P&gt;Domain based ,Star,IKev2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco is peer&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 16:31:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236057#M39472</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T16:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236058#M39473</link>
      <description>&lt;P&gt;If its combo of hosts/subnets. then please try "per gateway"&lt;/P&gt;
&lt;P&gt;If that fails, run simple vpn debug.&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;fw ctl debug 0&lt;/P&gt;
&lt;P&gt;Get ike* and vpnd* files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Message me directly, we can do remote, Im confident I can help you.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 16:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236058#M39473</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-17T16:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236059#M39474</link>
      <description />
      <pubDate>Tue, 17 Dec 2024 16:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236059#M39474</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T16:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236060#M39475</link>
      <description>&lt;P&gt;There are so manu Ike fiels so which one i have to take&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;attached screenshot for reference&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 16:49:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236060#M39475</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T16:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236061#M39476</link>
      <description />
      <pubDate>Tue, 17 Dec 2024 16:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236061#M39476</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-17T16:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236062#M39477</link>
      <description>&lt;P&gt;I would review whatever is today's date. Honestly, I feel your best bet is to call TAC, do remote session and Im sure they would be able to figure it out quick. Its not so easy to tell based on these screenshots.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 17:02:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236062#M39477</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-17T17:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236066#M39478</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Im in the zoom meeting waiting, so if you are free, please join, Im good till 2.30 pm est.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 18:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236066#M39478</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-17T18:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236071#M39481</link>
      <description>&lt;P&gt;Hey Mahesh,&lt;/P&gt;
&lt;P&gt;Just send me your email in direct message, we can connect offline. Not sure what country you are in, but Im in Canada EST (GMT-5)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 20:26:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236071#M39481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-17T20:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236185#M39494</link>
      <description>&lt;P&gt;I am in india(IST) GMT+5:30&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 15:44:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236185#M39494</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-18T15:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236186#M39495</link>
      <description>&lt;P&gt;Just messaged you offline.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 15:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236186#M39495</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T15:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236191#M39496</link>
      <description>&lt;P&gt;Hey everyoone,&lt;/P&gt;
&lt;P&gt;Just to update on this, had zoom remote with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/115227"&gt;@MaheshCheck&lt;/a&gt;&amp;nbsp;and below are my notes. I feel good now if Cisco side resets the tunnel, it will work fine, but Mahesh will let us know for sure once they do it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NOTES FROM THE CALL:&lt;/P&gt;
&lt;P&gt;-zoom with Mahesh&lt;BR /&gt;-we enabled tunnel mgmt as per gateway since its combo of hosts/subnets&lt;BR /&gt;-installed policy&lt;BR /&gt;-first time config, never worked before&lt;BR /&gt;-Cisco mentioned phase 2 selectors are not matching&lt;BR /&gt;-peer ip x.x.x.x&lt;/P&gt;
&lt;P&gt;below guidbedit settings should be set to FALSE to avoid any supernetting:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ike_enable_supernet&lt;/P&gt;
&lt;P&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P&gt;ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;peer -&amp;gt; xyz_gateway&lt;/P&gt;
&lt;P&gt;we made sure guidbedit settings were set to false, changed last one -&amp;gt; ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P&gt;installed policy -&amp;gt; now tunnel shows UP&lt;/P&gt;
&lt;P&gt;Mahesh will ask other side to check tomorrow and let us know&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 01:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236191#M39496</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-19T01:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236205#M39499</link>
      <description>&lt;P&gt;Hey Mahesh,&lt;/P&gt;
&lt;P&gt;Im sure you are sleeping as Im writting this, but in case tunnel still does not work when Cisco side checks, they can use below simple commands to do a debug and its very light. This is what guy I used to work with who worked for Cisco TAC gave me once.&lt;/P&gt;
&lt;P&gt;Hope it helps (if needed)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;debug vpn:&lt;/P&gt;
&lt;P&gt;debug crypto condition peer x.x.x.x&lt;/P&gt;
&lt;P&gt;debug crypto ikev1 200&lt;/P&gt;
&lt;P&gt;debug crypto ipsec 200&lt;/P&gt;
&lt;P&gt;to cancel all debugs-&amp;gt; undebug all&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 18:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236205#M39499</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T18:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236314#M39508</link>
      <description>&lt;P&gt;Thanks Andy. I have shared the above output with Vendor and will let you know results once i hear back from him.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 08:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236314#M39508</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-19T08:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236339#M39510</link>
      <description>&lt;P&gt;Sounds good, I feel good about the outcome...fingers crossed!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 12:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236339#M39510</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-19T12:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236407#M39514</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;The tunnel is not coming up .I took debug output from cisco vendor and also attached Tunnel details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please look into debug output and is cisco sending wrong proposal? please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;attached files&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 18:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236407#M39514</guid>
      <dc:creator>MaheshCheck</dc:creator>
      <dc:date>2024-12-19T18:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Phase2 is not getting up</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236408#M39515</link>
      <description>&lt;P&gt;Thats a bummer : -(. O well, lets see what we can do. I will review soon.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 18:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ikev2-Phase2-is-not-getting-up/m-p/236408#M39515</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-19T18:02:30Z</dc:date>
    </item>
  </channel>
</rss>

