<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN issue stuck in Phase 1 and sometimes disconnects in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/256908#M43264</link>
    <description>&lt;P&gt;Its really difficult issue to troubleshoot, since best way to go about it would be to either check the relevant log or have some sort of cron job running that would catch the issue when it happens.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 09 Sep 2025 16:07:08 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-09T16:07:08Z</dc:date>
    <item>
      <title>VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254319#M42732</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;Apologies for my beginners knowledge regarding Checkpoint , but I am having an issue with VPN tunnel from our HQ in Germany to one of the office in US. VPN gets stuck at phase 1 most of the times and sometimes it gets disconnected too but it is rare. As primary responsible is not available for some days and its a production environment , I need to find a fix. to make it work temporarily, I have to reset the tunnel and it starts working for some random time.&amp;nbsp; I could not find the issue via smart console logs. Has anyone experienced something like this and secondly has anyone used a script to reset tunnel whenever it is down or after an hour or so as a work around or some other solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2025 08:11:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254319#M42732</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-07-31T08:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254497#M42768</link>
      <description>&lt;P&gt;Is the VPN failing or is it running OK? I have seen the GUI say 'UP - Phase 1' without there being any issues reported.&lt;/P&gt;&lt;P&gt;Go onto the CLI in expert mode and do&lt;/P&gt;&lt;P&gt;#vpn tu&lt;/P&gt;&lt;P&gt;Option 3, put in the remote gateway address&lt;/P&gt;&lt;P&gt;Option 4, put in the remote gateway address&lt;/P&gt;&lt;P&gt;It might be that there is a mismatch between the encryption domains.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 13:34:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254497#M42768</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2025-08-04T13:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254505#M42771</link>
      <description>&lt;P&gt;Hi, The VPN fails and the services are disrupted until tunnel is reset. No changes were done for VPN related configurations but this issue arose and it stucks on phase 1 randomly and just for two peers. I am using same VPN community with headquarter and other peer, it is working fine there. I verified vpn tu and it shows same IKE SA, could not find any mismatch will now.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 15:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254505#M42771</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-04T15:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254521#M42778</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/130466"&gt;@Zee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No worries, we are here to help. Just wondering, how is tunnel management tab configured inside the community object? Did this work and just started recently or was issue always there?&lt;/P&gt;
&lt;P&gt;Any relevant logs you can send? Did you try do simple debug as below:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic (30 seconds or 1 minute)&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;Get ike* and vpnd* files from $FWDIR/log dir&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 01:29:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254521#M42778</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-05T01:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254545#M42780</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;It was working before 15 July and no changes related to VPN was done which could have caused such an issue in my opinion. I have sent the debug files to TAC support but still have not heard anything relevant. I tried to verify the logs myself but could not found something specific to Phase 1 stuck issue. Moreover, I could not open iked0.elg via ikeview tool as I read somewhere that in R81.20, it should be ike.elg or trace file should have some relevant data.&lt;BR /&gt;The issue is very random, sometimes it wont arise for hours. I made a script to reset tunnel after 30 mins for now, but even with that sometimes it gets stuck and have to reset twice. (just a work around). The VPN community is same for HQ fw and all other FWs but the issue is&amp;nbsp; with one office to HQ fw, other vpn tunnels are fine.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 12:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254545#M42780</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-05T12:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254546#M42781</link>
      <description>&lt;P&gt;K, so couple points about that setting. The way you have it is fine, BUT, in such case, I would make sure you use VTIs and set enc. domains as empty group. I find that works 100% of the time.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 12:55:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254546#M42781</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-05T12:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254548#M42782</link>
      <description>&lt;P&gt;FWIW, check out this post I made last year. Thats pretty much how I set up any route based tunnel (regardless if its Azure or not) and works fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 13:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254548#M42782</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-05T13:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254550#M42783</link>
      <description>&lt;P&gt;We are not using VTIs and enc. domains have the same IP pools which were before. The randomness of the issue has confused me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 14:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254550#M42783</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-05T14:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254551#M42784</link>
      <description>&lt;P&gt;Not to sound funny now when I say this, but any time people tell me "O, this used to work yesterday", my answer is always "Well, I was a year younger last year, now Im not"...It would be nice if there was real time machine haha : - )&lt;/P&gt;
&lt;P&gt;Anyway, lets see what we can do to help. Are you allowed to send debug file? I would be happy to check it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 14:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254551#M42784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-05T14:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254590#M42785</link>
      <description>&lt;P&gt;I understand, there is something wrong which is causing this issue somehow. I don't know if this can help but these are some of the logs related to both fw in iked.elg files. Unfortunately, can not send the debug file as it is not allowed and ignore the IP prevention.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 11:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254590#M42785</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-22T11:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254592#M42786</link>
      <description>&lt;P&gt;Here is where I would start, or try to get this info...does it show which packet of phase 1 is it failing? Because you can totally forget about enc. domains, since thats always related to phase 2, but its not even getting there. So, for example, if it was failing on packet 4 phase 1, thats PSK issue, but anything before, most likely its not agreeing on algorithms.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254592#M42786</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-05T16:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254633#M42787</link>
      <description>&lt;P&gt;Thank You for help Andy. I am following the same process to get the logs but somehow I am not getting relevant logs for the fw peer which is having this issue. The above mentioned logs were the only one which I could gather at the time of issue. May be I am doing something wrong. Secondly, after the script which is working after every 30 mins twice after 5 secs, the issue just comes 2-3 times in a day, earlier it was like more than 10 times. Do you think if the issue was with algo or PSK, resetting the tunnel would resolve the issue temporarily?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 08:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254633#M42787</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-06T08:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254638#M42788</link>
      <description>&lt;P&gt;You can try that, does not hurt, but logically, it might not do anything to reset PSK unless there is log showing thats the issue. Plus, if PSK was the problem, tunnel would NEVER work to begin with &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 11:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254638#M42788</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-06T11:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254639#M42789</link>
      <description>&lt;P&gt;True, I will dig down more and see what TAC has to say, but idk why resetting the tunnel resolves the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 11:21:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254639#M42789</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-06T11:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254640#M42790</link>
      <description>&lt;P&gt;Is this CP to CP?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 11:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254640#M42790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-06T11:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254642#M42791</link>
      <description>&lt;P&gt;Yes, from HQ to one branch in another country. Almost all other CP FW which have a tunnel with HQ does not have this issue, except this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 11:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254642#M42791</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-06T11:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254643#M42792</link>
      <description>&lt;P&gt;Is it star or mesh community? If star, I fixed this sort of issue once by "flipping" centre and satellite gateways around, not sure if you can try that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 11:51:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254643#M42792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-06T11:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254644#M42793</link>
      <description>&lt;P&gt;It is working in a mesh community actually&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 12:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254644#M42793</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-06T12:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254645#M42794</link>
      <description>&lt;P&gt;K, got it...I mean, you can try reset PSK, does not hurt and test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 12:18:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254645#M42794</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-06T12:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue stuck in Phase 1 and sometimes disconnects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254650#M42795</link>
      <description>&lt;P&gt;I stopped the script and its been 24 hours I have not seen the issue with the same configurations. I am also thinking of an ISP issue but its a far stretched thought for now.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 14:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-issue-stuck-in-Phase-1-and-sometimes-disconnects/m-p/254650#M42795</guid>
      <dc:creator>Zee</dc:creator>
      <dc:date>2025-08-06T14:45:23Z</dc:date>
    </item>
  </channel>
</rss>

