<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-site VPN tunnel logs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265211#M44672</link>
    <description>&lt;P&gt;I normally do "blade:VPN AND &amp;lt;public IP of peer&amp;gt;", then filter out accepted / encrypted traffic or filter on reject / key install or something like that, and I generally can fix any VPN issues doing that based on what the logs tell me.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Dec 2025 19:23:49 GMT</pubDate>
    <dc:creator>CaseyB</dc:creator>
    <dc:date>2025-12-12T19:23:49Z</dc:date>
    <item>
      <title>Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174715#M29160</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I would like to know how to check the log history in the console for a given VPN site to site.&lt;/P&gt;&lt;P&gt;We have a VPN site to site set up with another company, and there was a case that the VPN tunnel was broken for an hour, you can't see anything in the SMS logs, there is only an hour hole, the question is whether it is possible in the console to download logs from a given tunnel at a given time deeper hour.&lt;BR /&gt;Thank you very much for help&lt;/P&gt;&lt;P&gt;The sms version is R81.10&lt;BR /&gt;Firewall - r81.10&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 09:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174715#M29160</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-14T09:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174719#M29161</link>
      <description>&lt;P&gt;Logs at least should show why the tunnel went down and later up again ! If VPN is down it will not log.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 09:50:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174719#M29161</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-14T09:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174721#M29162</link>
      <description>&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 10:03:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/174721#M29162</guid>
      <dc:creator>Gacki</dc:creator>
      <dc:date>2023-03-14T10:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265202#M44669</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Is there a way to see the “possible root cause” of why a VPN tunnel went down and then came back up, from one moment to the next?&lt;/P&gt;
&lt;P&gt;We are having a problem with a VPN, which suddenly “crashes” and then starts working again after a while without any intervention.&lt;BR /&gt;Is there a file we can check that might help us with this?&lt;/P&gt;
&lt;P&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 17:25:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265202#M44669</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-12-12T17:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265206#M44670</link>
      <description>&lt;P&gt;These kinds of "fails and comes back" issues with VPNs are usually caused by mismatches in the configuration on both ends (namely timers related to key renegotiation).&lt;BR /&gt;You might have a look at scenario 4 here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 17:59:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265206#M44670</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-12T17:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265207#M44671</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Is there a relevant log in SmartConsole that could give us an “idea” of the possible root cause?&lt;BR /&gt;Is there any way to help find logs relevant to intermittent issues in the SmartConsole search engine?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 18:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265207#M44671</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-12-12T18:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265211#M44672</link>
      <description>&lt;P&gt;I normally do "blade:VPN AND &amp;lt;public IP of peer&amp;gt;", then filter out accepted / encrypted traffic or filter on reject / key install or something like that, and I generally can fix any VPN issues doing that based on what the logs tell me.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 19:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265211#M44672</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-12T19:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265213#M44673</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;Regarding the “Key Install” log type, does it always represent a “problem” with an S2S VPN?&lt;BR /&gt;Is it something that needs to be “checked” in detail?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 20:13:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265213#M44673</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-12-12T20:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265216#M44674</link>
      <description>&lt;P&gt;No, generally the "Key Install" is always a good thing and is an expected log, but I use it to confirm the tunnel is building how I expect it to, as the tunnel could be breaking because of the networks / hosts sent in Phase 2.&lt;/P&gt;
&lt;P&gt;For this example, this is the exact IKE ID I expect to see, so I know the encryption domain is not the problem in this direction. This can work properly when 1 firewall initiates traffic and could break if the other side is to initiate as their configuration could be off slightly sending a /29 instead of a /28 or something.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IKE_ids.png" style="width: 422px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32414iA73337C373AF3D27/image-size/large?v=v2&amp;amp;px=999" role="button" title="IKE_ids.png" alt="IKE_ids.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will see key installs line-up with the timers you have set here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike_timers.png" style="width: 459px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32415i84F456D611C5FD97/image-size/large?v=v2&amp;amp;px=999" role="button" title="ike_timers.png" alt="ike_timers.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;An example of an issue could be you are seeing "Key Installs" every 15 minutes when they should be around an hour, something is probably off.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 20:25:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265216#M44674</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-12T20:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265218#M44675</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Your last comment is precisely part of my problem.&lt;BR /&gt;I am seeing too many recurring Key Install logs for a specific VPN.&lt;/P&gt;
&lt;P&gt;And the other problem is that every Friday morning, the VPN goes down and then comes back up without any intervention.&lt;/P&gt;
&lt;P&gt;That is why I am trying to find a way to know if the logs show us a reason why this is happening.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 20:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265218#M44675</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-12-12T20:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-site VPN tunnel logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265221#M44676</link>
      <description>&lt;P&gt;You are going to see a "Key Install" for every IKE SA you are building on the tunnel. So, you do need to examine them to see if they are expected.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Example 1 - I am building at least 5 IKE SAs with this vendor on a tunnel, so I will see multiple "Key Installs" per hour, but that is expected because each IKE SA will probably re-key at a different time. See:&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike_sas1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32416i67E5DF1A7BD5B7EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="ike_sas1.png" alt="ike_sas1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Example 2 - I am building 1 IKE SA on this tunnel, and I should only see one key install per hour.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike_sas2.png" style="width: 781px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32417i47392AB4B89AB1E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="ike_sas2.png" alt="ike_sas2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 21:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-site-VPN-tunnel-logs/m-p/265221#M44676</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-12T21:11:55Z</dc:date>
    </item>
  </channel>
</rss>

