<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about VPN S2S Permanent Tunnel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273875#M45859</link>
    <description>&lt;P&gt;Reading the admin guide here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?tocpath=Tunnel%20Management%7C_____0#Tunnel_Management" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?tocpath=Tunnel%20Management%7C_____0#Tunnel_Management&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;It appears that a &lt;STRONG&gt;Permanent Tunnel&lt;/STRONG&gt; can only be established when both peers in the site-to-site VPN are &lt;STRONG&gt;Check Point gateways&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;In cases where the peer is a &lt;STRONG&gt;non–Check Point gateway&lt;/STRONG&gt;, it is necessary to enable &lt;STRONG&gt;PDP (Permanent Tunnel via DPD)&lt;/STRONG&gt;. From what I understand, this configuration seems to require enabling it through &lt;STRONG&gt;GuiDBEdit&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Insight from the guide:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Permanent Tunnels can only be established between Check Point Security Gateways.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Dead Peer Detection (DPD) is a different method to test if VPN tunnels are active. Dead Peer Detection does support third-party Security Gateways and supports permanent tunnels with interoperable devices based on IKEv1/IKEv2 DPD (IKEv1 DPD is based on RFC 3706).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;To enable DPD monitoring:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On each VPN gateway in the VPN community, configure the tunnel_keepalive_method property, in Database Tool (GuiDBEdit Tool) or dbedit (see skI3301). This includes third-party gateways. (You cannot configure different monitor mechanisms for the same gateway).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In Database Tool (GuiDBEdit Tool), go to Network Objects &amp;gt; network_objects &amp;gt; &amp;lt;Name of Security Gateways object&amp;gt; &amp;gt; VPN.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;For the Value, select a permanent tunnel mode.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Save all the changes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Install the Access Control Policy.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2026 09:26:32 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2026-03-20T09:26:32Z</dc:date>
    <item>
      <title>Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273801#M45850</link>
      <description>&lt;P&gt;Hi Mates,&lt;BR /&gt;Simple question here:&lt;BR /&gt;Is the permanent tunnel feature for a site-to-site VPN is enabled via GuiDBEdit, or am I missing something?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:28:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273801#M45850</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-19T13:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273802#M45851</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;No need, just enable it via tunnel management in community settings in smart console.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273802#M45851</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-19T13:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273803#M45852</link>
      <description>&lt;P&gt;And you can obviously also use the relevant Management API commands:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-vpn-community-meshed~v2.1%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/add-vpn-community-meshed~v2.1%20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-vpn-community-star~v2.1%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-vpn-community-star~v2.1%20&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273803#M45852</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2026-03-19T13:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273804#M45853</link>
      <description>&lt;P&gt;But I remembered that sometimes I saw it done in &lt;SPAN&gt;GuiDBEdit&amp;nbsp;&lt;/SPAN&gt;as well. Under what circumstances should this be done?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273804#M45853</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-19T13:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273805#M45854</link>
      <description>&lt;P&gt;I believe ever since R80.30 or R80.40, its enabled automatically in guidbedit once you set it as permanent tunnel.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273805#M45854</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-19T13:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273807#M45855</link>
      <description>&lt;P&gt;ok thank you brother, i'll double check also with TAC&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:48:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273807#M45855</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-19T13:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273808#M45856</link>
      <description>&lt;P&gt;Sure thing, though Im fairly positive thats the case.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 13:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273808#M45856</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-19T13:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273821#M45857</link>
      <description>&lt;P&gt;In R81, DPD became the default (i.e. not something you have to enable with guidbedit), as mentioned in Scenario 5 here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Not sure if this applies if the management was upgraded from a pre-R81 release or not.&lt;/P&gt;
&lt;P&gt;In any case, you still have to enable "Permanent Tunnels" in the relevant VPN community.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 15:50:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273821#M45857</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-19T15:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273875#M45859</link>
      <description>&lt;P&gt;Reading the admin guide here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?tocpath=Tunnel%20Management%7C_____0#Tunnel_Management" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Tunnel-Management.htm?tocpath=Tunnel%20Management%7C_____0#Tunnel_Management&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;It appears that a &lt;STRONG&gt;Permanent Tunnel&lt;/STRONG&gt; can only be established when both peers in the site-to-site VPN are &lt;STRONG&gt;Check Point gateways&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;In cases where the peer is a &lt;STRONG&gt;non–Check Point gateway&lt;/STRONG&gt;, it is necessary to enable &lt;STRONG&gt;PDP (Permanent Tunnel via DPD)&lt;/STRONG&gt;. From what I understand, this configuration seems to require enabling it through &lt;STRONG&gt;GuiDBEdit&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Insight from the guide:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Permanent Tunnels can only be established between Check Point Security Gateways.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Dead Peer Detection (DPD) is a different method to test if VPN tunnels are active. Dead Peer Detection does support third-party Security Gateways and supports permanent tunnels with interoperable devices based on IKEv1/IKEv2 DPD (IKEv1 DPD is based on RFC 3706).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;To enable DPD monitoring:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On each VPN gateway in the VPN community, configure the tunnel_keepalive_method property, in Database Tool (GuiDBEdit Tool) or dbedit (see skI3301). This includes third-party gateways. (You cannot configure different monitor mechanisms for the same gateway).&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In Database Tool (GuiDBEdit Tool), go to Network Objects &amp;gt; network_objects &amp;gt; &amp;lt;Name of Security Gateways object&amp;gt; &amp;gt; VPN.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;For the Value, select a permanent tunnel mode.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Save all the changes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Install the Access Control Policy.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 09:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273875#M45859</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-20T09:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273881#M45860</link>
      <description>&lt;P&gt;Its true thats what it says, but in reality, it works fine with any other vendor and no need to change anything in guidbedit once you enable permanent tunnel setting.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 11:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273881#M45860</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-20T11:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273991#M45866</link>
      <description>&lt;P&gt;Sounds like an area where the documentation might need to be updated.&lt;BR /&gt;Tagging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2208"&gt;@Sergei_Shir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 16:39:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273991#M45866</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-23T16:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273993#M45867</link>
      <description>&lt;P&gt;Hey, bro,&lt;BR /&gt;So why does the administrative guide mention it? I don't get it.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 16:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/273993#M45867</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-23T16:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/275598#M46008</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have updated the Site-to-Site VPN Admin Guide, removed the GuiDBedit instructions and added a note:&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Starting in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Versions.r_ivory variable"&gt;R81.20&lt;/SPAN&gt;, when you create the interoperable device object for the 3rd Party VPN&amp;nbsp;gateway, DPD&amp;nbsp;is automatically set as the permanent tunnel method.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;DIV id="tinyMceEditor_1a84ddebc4ccf2Gil_Frantsus_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Thank you for your feedback.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 09:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/275598#M46008</guid>
      <dc:creator>Gil_Frantsus</dc:creator>
      <dc:date>2026-04-16T09:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question about VPN S2S Permanent Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/276040#M46079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19672"&gt;@Gil_Frantsus&lt;/a&gt;&amp;nbsp;thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 08:38:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-VPN-S2S-Permanent-Tunnel/m-p/276040#M46079</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-04-24T08:38:41Z</dc:date>
    </item>
  </channel>
</rss>

