<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN IPSec Tunnel with Sophos IKEv2 Issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259829#M43909</link>
    <description>&lt;P&gt;I would debug both sides and see what gives.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 14 Oct 2025 12:28:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-10-14T12:28:40Z</dc:date>
    <item>
      <title>VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257265#M43323</link>
      <description>&lt;P&gt;Dear all,&lt;BR /&gt;&lt;BR /&gt;we have an IPSec Tunnel with a customer that has Sophos GW. If we use Ikev1 the tunnel work without a problem, but if we change to IKEv2 then it doesn't work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Error on our side:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;invalid Syntax&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error on the other side:&lt;/P&gt;&lt;P&gt;invalid SPI&lt;BR /&gt;&lt;BR /&gt;I'd be glad if someone can share their experience with the so called "free Firewall software". No mater which "Software" based Firewall it is, we always have problems with it.&lt;BR /&gt;&lt;BR /&gt;Thank you and kind regards!&lt;BR /&gt;Rok&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 09:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257265#M43323</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-09-15T09:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257268#M43324</link>
      <description>&lt;P&gt;IKEv2 between VPN gateways of different vendors has been an issue for many years.&lt;BR /&gt;I've created a &lt;A href="https://community.checkpoint.com/t5/General-Topics/Check-Point-Site-to-Site-VPN-Compatibility-Matrix/m-p/39089/highlight/true#M8390" target="_self"&gt;VPN compatibility matrix for Check Point&lt;/A&gt;&amp;nbsp;to document our community experience of IKEv2 with other vendors.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257268#M43324</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-15T10:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257270#M43325</link>
      <description>&lt;P&gt;I actually had this issue with large hospital using CP to PAN and it turned out they were using wrong peer ID, since for a long time they used IP from general properties of the CP smart console object, but one day when we did debug and worked with TAC, Tier 3 guy told us that it changed, so they had to use link selection setting.&lt;/P&gt;
&lt;P&gt;Just something to verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257270#M43325</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-15T10:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257272#M43326</link>
      <description>&lt;P&gt;Nice one&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;. Btw, does that still apply?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257272#M43326</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-15T10:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257388#M43355</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62608"&gt;@Mlinko&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any luck with this?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 15:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/257388#M43355</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-16T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258424#M43636</link>
      <description>&lt;P&gt;Dear Andy and Danny,&lt;BR /&gt;&lt;BR /&gt;Thank you for your help, I'll let you know how it turned out after a debugging session with a client.&lt;BR /&gt;&lt;BR /&gt;KR&lt;BR /&gt;Rok&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 05:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258424#M43636</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-09-29T05:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258426#M43637</link>
      <description>&lt;P&gt;The NIS2 directive will hit us any time now, that is why we want to "prepare" and reconfigure the VPN Tunnels with our clients to IKEv2.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 05:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258426#M43637</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-09-29T05:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258433#M43638</link>
      <description>&lt;P&gt;Sounds good!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 09:18:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258433#M43638</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T09:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258436#M43640</link>
      <description>&lt;P&gt;I would say its more less the norm these days to use ikev2.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 09:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258436#M43640</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T09:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258692#M43704</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Any luck yet with this?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 13:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/258692#M43704</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T13:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259759#M43873</link>
      <description>&lt;P&gt;No luck at all, the only thing that we need to test ist - One vpn tunnel per GW Pair. Then it's debuging time, but the last time we didn't see anything - actually only that the Encryption Domain is not correct... I don't know what kind of settings are possible on the other side...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 07:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259759#M43873</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-10-13T07:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259760#M43874</link>
      <description>&lt;P&gt;What are the settings currently?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 08:05:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259760#M43874</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-13T08:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259828#M43908</link>
      <description>&lt;P&gt;IKE 1&lt;BR /&gt;1440&amp;nbsp; min&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;IKE 2&amp;nbsp;&lt;/P&gt;&lt;P&gt;3600s&lt;BR /&gt;&lt;BR /&gt;VPN Tunnel Sharing:&lt;BR /&gt;One VPN Tunnel per subnet pair&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 12:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259828#M43908</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-10-14T12:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259829#M43909</link>
      <description>&lt;P&gt;I would debug both sides and see what gives.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 12:28:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259829#M43909</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-14T12:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259877#M43927</link>
      <description>&lt;P&gt;Btw, any relevant logs from Sophis side?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 04:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259877#M43927</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-15T04:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259878#M43928</link>
      <description>&lt;P&gt;No, that is the problem! I didn't see any logs from the Sophos side... I don't know how your experience is with the customers/partners but they are usually not willing to give their logs or configurations...&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 04:54:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259878#M43928</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2025-10-15T04:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec Tunnel with Sophos IKEv2 Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259879#M43929</link>
      <description>&lt;P&gt;Personally, I never have that issue. Any customer I work with is more than willing to send anything needed for troubleshooting. Anyway, that aside, lets see what we can do to try solve this for you.&lt;/P&gt;
&lt;P&gt;If there is nothing we can rely on from Sophos side as far as logs, I saw in your description that error showed invalid SPI, which is always 100%, phase 2 issue. Can you double check phase 2 settings? Ensure vpn domains are fine as well.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 07:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-Tunnel-with-Sophos-IKEv2-Issue/m-p/259879#M43929</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-15T07:21:02Z</dc:date>
    </item>
  </channel>
</rss>

