<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10: IPsec VPN - allow unencrypted pings between gateways in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22105#M4183</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe useful to mention this part of the SK:&lt;/P&gt;&lt;H2 style="color: #333333; background-color: #ffffff; font-weight: bold; font-size: 22px; padding: 10px 0px 0px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Scenario 3 - Implied inclusion of Check Point Security Gateway's / 3rd party VPN Peer's interfaces&lt;/SPAN&gt;&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2019 12:33:08 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-01-09T12:33:08Z</dc:date>
    <item>
      <title>R80.10: IPsec VPN - allow unencrypted pings between gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22102#M4180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is my very first question on CheckMates. Exciting! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I’m struggling with an IPsec VPN issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m setting up a very basic VPN between our Check Point gateway (R80.10) in Brussels and one peer gateway in Amsterdam, non-Check Point, managed by a business partner of ours.&lt;/P&gt;&lt;P&gt;I’m configuring that VPN as a “star” VPN community with one “center” gateway (our own) and one “satelite” gateway (the one in Amsterdam).&lt;BR /&gt; VPN comes up and is working. So far, so good.&lt;BR /&gt; &lt;BR /&gt; Now, this particular partner in Amsterdam has the requirement to be able to ping from their gateway to ours. That is: unencrypted, straight over internet.&lt;/P&gt;&lt;P&gt;Those pings are blocked by our firewall with the message “&lt;EM&gt;Encryption Failure - Clear text packet should be encrypted&lt;/EM&gt;”&lt;/P&gt;&lt;P&gt;That seems logical, because in the VPN community I created, I read following remark: “&lt;EM&gt;All the connections between the Gateways below and the Satellite Gateways will be encrypted.&lt;/EM&gt;”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within that same VPN community I have the option to “Exclude Services” from the community, resulting in these services not being encrypted.&lt;BR /&gt; When I add “echo-request” and “echo-reply” services in there, the peer gateway indeed is able to ping our gateway.&lt;/P&gt;&lt;P&gt;However, at the same time, pings between endpoint devices, that should be routed and encrypted throught the VPN are no longer working at that moment, and blocked by our gateway with the message: “&lt;EM&gt;Encryption Failure - According to the policy the packet should not have been decrypted&lt;/EM&gt;”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I solve this deadlock and allow un-encrypted pings between gateways and, at the same time, allow encrypted pings between endpoints passing through the VPN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m not quickly finding a solution on Google or CP’s KB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your advice!&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Lode&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 09:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22102#M4180</guid>
      <dc:creator>Lode_De_Feyter</dc:creator>
      <dc:date>2019-01-08T09:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10: IPsec VPN - allow unencrypted pings between gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22103#M4181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;welcome to the club &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see this article first:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/10807-vpn-exclusions-made-inside-fwdirlibcryptdef-does-not-work"&gt;https://community.checkpoint.com/thread/10807-vpn-exclusions-made-inside-fwdirlibcryptdef-does-not-work&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then if not helpful search for crypt..def and exclusions you do on Management server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 09:36:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22103#M4181</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-08T09:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10: IPsec VPN - allow unencrypted pings between gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22104#M4182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;$FWDIR/lib/crypt.def&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sk86582&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;modify according to the sk's and CCC from Dany &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 09:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22104#M4182</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-08T09:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10: IPsec VPN - allow unencrypted pings between gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22105#M4183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe useful to mention this part of the SK:&lt;/P&gt;&lt;H2 style="color: #333333; background-color: #ffffff; font-weight: bold; font-size: 22px; padding: 10px 0px 0px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Scenario 3 - Implied inclusion of Check Point Security Gateway's / 3rd party VPN Peer's interfaces&lt;/SPAN&gt;&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:33:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22105#M4183</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-01-09T12:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10: IPsec VPN - allow unencrypted pings between gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22106#M4184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your replies, &lt;A href="https://community.checkpoint.com/migrated-users/47446"&gt;Jerry Szpinak&lt;/A&gt;‌ and &lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;‌&lt;BR /&gt;Both were usefull!&lt;BR /&gt;&lt;BR /&gt;I solved it by modifying the $FWDIR/lib/crypt.def file as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Replaced these 3 lines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #ifndef NON_VPN_TRAFFIC_RULES&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #define NON_VPN_TRAFFIC_RULES 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #endif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With these lines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FW-MYCOMPANY_BRUS={12.34.56.78};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FW-PARTNER_AMST={87.65.43.21};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #ifndef NON_VPN_TRAFFIC_RULES&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #ifndef IPV6_FLAVOR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #define NON_VPN_TRAFFIC_RULES (((src in FW-&lt;SPAN&gt;MYCOMPANY_BRUS&lt;/SPAN&gt;) and (dst in FW&lt;SPAN&gt;PARTNER_AMST&lt;/SPAN&gt;)) or ((src in FW&lt;SPAN&gt;PARTNER_AMST&lt;/SPAN&gt;) and (dst in FW-&lt;SPAN&gt;MYCOMPANY_BRUS&lt;/SPAN&gt;)))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #else&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #define NON_VPN_TRAFFIC_RULES 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #endif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #endif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also removed the "echo-request" and "echo-reply" services again from "Exclude Services" within the VPN community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After policy install, pings between VPN gateways are possible and not encrypted.&lt;/P&gt;&lt;P&gt;Pings between endpoints are working too and being encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Lode&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 15:50:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-IPsec-VPN-allow-unencrypted-pings-between-gateways/m-p/22106#M4184</guid>
      <dc:creator>Lode_De_Feyter</dc:creator>
      <dc:date>2019-01-11T15:50:40Z</dc:date>
    </item>
  </channel>
</rss>

