<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN on DAIP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275886#M46055</link>
    <description>&lt;P&gt;See if below helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-site-to-site-with-Remote-Peer-Dynamic-IP/m-p/180681#M33028" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-site-to-site-with-Remote-Peer-Dynamic-IP/m-p/180681#M33028&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2026 13:33:46 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-04-21T13:33:46Z</dc:date>
    <item>
      <title>VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275873#M46047</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im currently helping a customer with a site to site vpn, between to quantum spark gateways, where one is DAIP.&lt;/P&gt;&lt;P&gt;After registereing a ddns address, i can easily log on and manage it, and it has&amp;nbsp; a rulebase.&lt;/P&gt;&lt;P&gt;But we are struggling to get the vpn up and running, with only a generic "ike failure, error occured" message when we initiate traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I havent been able to find much documentation on how to properly set this up, and best practices, so i hope i might get some good feedback on here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the gateways are both centrally managed from the same mgmt server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 11:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275873#M46047</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2026-04-21T11:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275874#M46048</link>
      <description>&lt;P&gt;Did you set permanent tunnels on the gateway? Do you have the link selection configured all good on both ends? Which end are you sending traffic from to test?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 11:19:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275874#M46048</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-21T11:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275875#M46049</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set permanent tunnels, yes.&lt;/P&gt;&lt;P&gt;Link selection on DAIP is set to dns resolving, with the ddns.net address put in. Havent changed link selection on center gateway, as that is not a DAIP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are initiation traffic from the DAIP gateway, as that is the way the traffic is meant to flow, and also the only supported way, if i remember correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 11:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275875#M46049</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2026-04-21T11:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275878#M46050</link>
      <description>&lt;P&gt;Link selection is still relevant to the non DAIP gateway - is the main IP on the general page of the gateway properties the internet IP? If not, you will need to set the correct external IP in link selection on that gateway and install policy to both of them. Or set the main IP to the internet IP and push policy to both.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 12:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275878#M46050</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-21T12:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275884#M46053</link>
      <description>&lt;P&gt;yes, the link selection is correct for the non daip. this vpn community is already in production with other satelite gateways, and working..its just this DAIP gateway we are struggling with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275884#M46053</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2026-04-21T13:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275886#M46055</link>
      <description>&lt;P&gt;See if below helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-site-to-site-with-Remote-Peer-Dynamic-IP/m-p/180681#M33028" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-site-to-site-with-Remote-Peer-Dynamic-IP/m-p/180681#M33028&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:33:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275886#M46055</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-04-21T13:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on DAIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275910#M46059</link>
      <description>&lt;P&gt;OK, if there's no useful information in the VPN logs for the key exchange failure specifically, it's time to get some VPN debug logs and open a TAC case so they can help figure it out.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 02:50:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-DAIP/m-p/275910#M46059</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-22T02:50:42Z</dc:date>
    </item>
  </channel>
</rss>

