<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: site to site VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28946#M5914</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;will I see "e" also ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2018 22:01:08 GMT</pubDate>
    <dc:creator>Brianpiraty_Ale</dc:creator>
    <dc:date>2018-06-14T22:01:08Z</dc:date>
    <item>
      <title>site to site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28944#M5912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For IPsec tunnel troubleshooting, after disabling the secureXL, when I run fwmonitor&amp;nbsp; with src and dest IP address,what should I expect to see?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will I see both (i, I) and Both (o,O) for the&amp;nbsp; traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28944#M5912</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-06-07T15:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28945#M5913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I always like to get packet captures without any filtering and I will filter later on in wireshark.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For R77.30 and lower versions, if you are filtering for the interesting traffic src and destination you suppose to see the clear packet in the following positions i I o and O you suppose to see the ESP packet which will have the public IPs of the endpoint of the vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For R80.10 since Corexl Is enabled for VPN in fw monitor checkpoint introduced 2 other positions e and E. because the traffic will be sent to a core that handles the connecion after that it will be forwarded to another core to do the encryption&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you suppose to see the clear packet in position i I o O e and you will see the esp packet at E position.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28945#M5913</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-06-07T15:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28946#M5914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;will I see "e" also ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 22:01:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28946#M5914</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-06-14T22:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: site to site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28947#M5915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you take a look on whole chain in your actual system, then you can se it is possible to run fw monitor on much more places then just default state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is chain example (note - Acceleration enabled):&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier, monospace;"&gt;[Expert@FWHOST:0]# fw ctl chain&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;in chain (15):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 0: -7f800000 (f5b395b0) (ffffffff) IP Options Strip (in) (ipopt_strip)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 1: - 2000000 (f544bb00) (00000003) vpn decrypt (vpn)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 2: - 1fffffa (f5466460) (00000001) l2tp inbound (l2tp)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 3: - 1fffff8 (f5b3aca0) (00000001) Stateless verifications (in) (asm)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 4: - 1fffff2 (f54888f0) (00000003) vpn tagging inbound (tagging)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 5: - 1fffff0 (f544a4a0) (00000003) vpn decrypt verify (vpn_ver)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 6: - 1000000 (f5c0d820) (00000003) SecureXL conn sync (secxl_sync)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 7: 0 (f5ad9390) (00000001) fw VM inbound (fw)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 8: 2000000 (f5449a60) (00000003) vpn policy inbound (vpn_pol)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 9: 10000000 (f5c18070) (00000003) SecureXL inbound (secxl)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 10: 7f600000 (f5b2d990) (00000001) fw SCV inbound (scv)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 11: 7f730000 (f5d40760) (00000001) passive streaming (in) (pass_str)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 12: 7f750000 (f5f53920) (00000001) TCP streaming (in) (cpas)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 13: 7f800000 (f5b392c0) (ffffffff) IP Options Restore (in) (ipopt_res)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 14: 7fb00000 (f633d240) (00000001) HA Forwarding (ha_for)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;out chain (13):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 0: -7f800000 (f5b395b0) (ffffffff) IP Options Strip (out) (ipopt_strip)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 1: - 1ffffff (f5449260) (00000003) vpn nat outbound (vpn_nat)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 2: - 1fffff0 (f5f53bb0) (00000001) TCP streaming (out) (cpas)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 3: - 1ffff50 (f5d40760) (00000001) passive streaming (out) (pass_str)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 4: - 1ff0000 (f54888f0) (00000003) vpn tagging outbound (tagging)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 5: - 1f00000 (f5b3aca0) (00000001) Stateless verifications (out) (asm)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 6: 0 (f5ad9390) (00000001) fw VM outbound (fw)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 7: 2000000 (f5449270) (00000003) vpn policy outbound (vpn_pol)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 8: 10000000 (f5c18070) (00000003) SecureXL outbound (secxl)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 9: 1ffffff0 (f54670d0) (00000001) l2tp outbound (l2tp)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 10: 20000000 (f544c600) (00000003) vpn encrypt (vpn)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 11: 7f700000 (f5f53df0) (00000001) TCP streaming post VM (cpas)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 12: 7f800000 (f5b392c0) (ffffffff) IP Options Restore (out) (ipopt_res)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SK for FW monitor is&amp;nbsp;much more fine than in the past. So try to look there for examples and syntax -&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30583&amp;amp;partition=General&amp;amp;product=Security"&gt;sk30583&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 06:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/site-to-site-VPN/m-p/28947#M5915</guid>
      <dc:creator>Petr_Hantak</dc:creator>
      <dc:date>2018-06-15T06:56:22Z</dc:date>
    </item>
  </channel>
</rss>

