<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN DOWN When? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244368#M40776</link>
    <description>&lt;P&gt;Unless you have Permanent Tunnels/DPD enabled it is possible for your VPN peer to go down or become unreachable, but the tunnel still looks "up" from your end, at least until the next Phase 2 re-key which could be up to 60 minutes later by default.&amp;nbsp; At that point you would get an error about the tunnel being down, but it could have actually died up to 60 minutes ago.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have Permanent Tunnels (CP gateways) or DPD (interoperable gateways) enabled, there is a setting in the VPN Community that can fire an alert when the tunnel is detected down, which should happen within roughly 60 seconds of the failure.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Mar 2025 18:11:28 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2025-03-20T18:11:28Z</dc:date>
    <item>
      <title>S2S VPN DOWN When?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244329#M40771</link>
      <description>&lt;P&gt;Hi All&lt;BR /&gt;&lt;BR /&gt;is it possible to know exactly when a vpn went down? are we talking about an s2s vpn? is there a command that can help?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 14:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244329#M40771</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-03-20T14:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN DOWN When?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244332#M40772</link>
      <description>&lt;P&gt;Maybe this helps:&lt;/P&gt;
&lt;P&gt;vpn tu tlist&lt;/P&gt;
&lt;P&gt;But it is a difficult question, because if the tunnel is ''up'' with p1 p2 it still can be that for the user the tunnel is not working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or a part of the tunnel works and other part does not work (if you have more subnets in one tunnel).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check the firewall logs and check for logs from local enc domain towards remote and the other way around. Good indication is also to check logs from and towards remote peer IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tunnel config also has p1 and p2 timers, most of the time if timer is reached new p2 or p1 is created.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In R82 you can configure VPN probes, those are hosts that you ping via the tunnel to check the status. Check it here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181994" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181994&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 14:38:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244332#M40772</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-03-20T14:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN DOWN When?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244368#M40776</link>
      <description>&lt;P&gt;Unless you have Permanent Tunnels/DPD enabled it is possible for your VPN peer to go down or become unreachable, but the tunnel still looks "up" from your end, at least until the next Phase 2 re-key which could be up to 60 minutes later by default.&amp;nbsp; At that point you would get an error about the tunnel being down, but it could have actually died up to 60 minutes ago.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have Permanent Tunnels (CP gateways) or DPD (interoperable gateways) enabled, there is a setting in the VPN Community that can fire an alert when the tunnel is detected down, which should happen within roughly 60 seconds of the failure.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 18:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244368#M40776</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-20T18:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN DOWN When?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244370#M40777</link>
      <description>&lt;P&gt;Something like what I attached, though someone from TAC gave me this while back, but they said it might not always be 100% reliable.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 18:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244370#M40777</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-20T18:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN DOWN When?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244372#M40778</link>
      <description>&lt;P&gt;You can also probably use tool called checkmk or something along those lines. I tested it in the lab last year, looked pretty reliable.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 18:54:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S2S-VPN-DOWN-When/m-p/244372#M40778</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-20T18:54:01Z</dc:date>
    </item>
  </channel>
</rss>

