<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site2Site vpn comunication issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240876#M40197</link>
    <description>&lt;P&gt;AS&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;indicated, this is expected, in other words, somewhere along the lines, 3 way handshake is failing and its NOT because of the fw.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2025 21:54:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-02-10T21:54:28Z</dc:date>
    <item>
      <title>Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240850#M40194</link>
      <description>&lt;P&gt;Hello mates.&lt;/P&gt;&lt;P&gt;I'm facing a wery wird problem with checkpoint S2S vpn comunication.&lt;/P&gt;&lt;P&gt;I have one tunnel between two security gateways configured and established.&lt;/P&gt;&lt;P&gt;The policy rules for the two machine on both sites were defined e verified correctely to comunicate on a bidiretional way, but somehow can only send packets from Machine-A to Machine-B, when i try the reverse path, the following error is presented:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Connection terminated before the Security Gateway was able to make a decision.&amp;nbsp;Insufficient data passed. To learn more see sk113479&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone help, please?! Thanks!!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 18:54:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240850#M40194</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-10T18:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240856#M40195</link>
      <description>&lt;P&gt;This means machine b is not allowed to talk with machine A. This could be acl, firewall on the machine or even routing back from machine a to machine b.&lt;/P&gt;
&lt;P&gt;The error in this case means that machine A sended traffic, syn, but there is no response, syn-ack.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 19:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240856#M40195</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-10T19:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240871#M40196</link>
      <description>&lt;P&gt;This isn't a problem. From &lt;A href="https://support.checkpoint.com/results/sk/sk113479" target="_blank"&gt;sk113479&lt;/A&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Security Gateway did not drop the connection.&lt;/LI&gt;
&lt;LI&gt;There is no drop print in the kernel debug.&lt;/LI&gt;
&lt;LI&gt;The reason for the log is not necessarily because of unwanted behavior of the edge client or the server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A Unified Policy can contain filter criteria that cannot be resolved on the connection's first packet, such as Application or Data. Therefore, on some connections, the final rule match decision occurs on the following data packets. Until the final decision is reached, the rule base accepts the incoming data packets if a rule allows it (meaning: if one of the possibly matched rules does not have a Drop/Reject action).&lt;/P&gt;
&lt;P&gt;In scenarios where the connection ends without application data content (no data packets), or the data quantity is not sufficient for the required engine detection, the rule base issues an Accept log with the first rule that allows the traffic. This rule might not have all the applicable criteria because some have not been detected.&lt;/P&gt;
&lt;P&gt;In other words, this is expected behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 20:09:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240871#M40196</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-10T20:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240876#M40197</link>
      <description>&lt;P&gt;AS&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;indicated, this is expected, in other words, somewhere along the lines, 3 way handshake is failing and its NOT because of the fw.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 21:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240876#M40197</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-10T21:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240900#M40198</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Had the same a two weeks ago after upgrades to R81.20 and a third party VPN.&lt;BR /&gt;In R81.10 VPN was OK and worked both ways. After upgrade to R81.20, we had issues with traffic both ways.&lt;BR /&gt;Nothing was changed on the configuration. Just an upgrade.&lt;BR /&gt;I saw the same message in the log on insufficient traffic, but the problem starts earlier. Check the logs with the IP-address of the VPN peer. I saw IKE failures.&lt;BR /&gt;&lt;BR /&gt;I have done the following to solve this.&lt;BR /&gt;&lt;BR /&gt;1. Configure a specific Encryption Domain per VPN Community with a 100% match with the configuration on the VPN peer.&lt;BR /&gt;2. On the VPN peer object go to Tunnel Management and select 'SA per subnet pair'.&lt;BR /&gt;3. Install policy.&lt;BR /&gt;4. Reset VPN tunnel with 'vpn tu'.&lt;BR /&gt;&lt;BR /&gt;It took a few minutes but VPN tunnel came back, was stable and we could send traffic both ways again.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 13:54:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240900#M40198</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-02-11T13:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240902#M40199</link>
      <description>&lt;P&gt;Good point actually...changing that setting could help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 13:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240902#M40199</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-11T13:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240912#M40201</link>
      <description>&lt;P&gt;Thanks for your contribution!!!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240912#M40201</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-11T14:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240913#M40202</link>
      <description>&lt;P&gt;Thanks for your contribution!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240913#M40202</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-11T15:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240914#M40203</link>
      <description>&lt;P&gt;Thanks for your contribution!!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:00:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240914#M40203</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-11T15:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240915#M40204</link>
      <description>&lt;P&gt;Thanks for your contribution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240915#M40204</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-11T15:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site vpn comunication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240916#M40205</link>
      <description>&lt;P&gt;A appreciate your contribution!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:01:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site2Site-vpn-comunication-issue/m-p/240916#M40205</guid>
      <dc:creator>Dido-Master</dc:creator>
      <dc:date>2025-02-11T15:01:15Z</dc:date>
    </item>
  </channel>
</rss>

