<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint VPN with PaloAlto not working about invalid proxy id in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29447#M6021</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because Check Point handles the external or Main IPs of both VPN gateways as part of the VPN encryption domain. Exclude them via crypt.def or adjust your Palo configuration accordingly and you should be fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Sep 2018 08:40:02 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2018-09-26T08:40:02Z</dc:date>
    <item>
      <title>CheckPoint VPN with PaloAlto not working about invalid proxy id</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29444#M6018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Client(192.168.100.100) ----[CheckPoint](192.168.121.100)----(192.168.121.200)[PaloAlto]----Client(192.168.200.100)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;On CheckPoint Side&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;VPN Domain :&lt;/STRONG&gt; 192.168.100.0/24&lt;BR /&gt;&lt;STRONG&gt;Interoperable Device VPN Domain :&lt;/STRONG&gt; 192.168.200.0/24&lt;BR /&gt;&lt;STRONG&gt;VPN Tunnel Share :&lt;/STRONG&gt; already config both per subnet and per gateway but have the same result.&lt;BR /&gt;&lt;STRONG&gt;user.def.FW1 :&lt;/STRONG&gt; &lt;BR /&gt;subnet_for_range_and_peer = {&lt;BR /&gt;&amp;lt;192.168.121.200, 192.168.100.1, 192.168.100.254; 255.255.255.0&amp;gt;&lt;BR /&gt;};&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;On PaloAlto Side&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Proxy ID :&lt;/STRONG&gt; Local : 192.168.200.0/24 and Remote : 192.168.100.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR message from Palo :&lt;/STRONG&gt; description contains 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 192.168.121.200/32 type IPv4_address protocol 0 port 0, received remote id: 192.168.100.0/24 type IPv4_subnet protocol 0 port 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Result:&lt;/STRONG&gt; Client from PaloAlto side can access to client on Checkpoint side but on CheckPoint side can't access client on palo side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 07:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29444#M6018</guid>
      <dc:creator>Worapong_Janloy</dc:creator>
      <dc:date>2018-09-26T07:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN with PaloAlto not working about invalid proxy id</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29445#M6019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Palo's error message shows a received local id: 192.168.&lt;STRONG&gt;121&lt;/STRONG&gt;.200/32 while the configured local proxy id is 192.168.&lt;STRONG&gt;200&lt;/STRONG&gt;.0/24.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 07:24:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29445#M6019</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-26T07:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN with PaloAlto not working about invalid proxy id</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29446#M6020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;The 192.168.&lt;/SPAN&gt;&lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;121&lt;/STRONG&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;.200/32 is ip address of&amp;nbsp;Interoperable Device (Main IP) I not sure why checkpoint propose this ip to PaloAlto.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 07:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29446#M6020</guid>
      <dc:creator>Worapong_Janloy</dc:creator>
      <dc:date>2018-09-26T07:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN with PaloAlto not working about invalid proxy id</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29447#M6021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because Check Point handles the external or Main IPs of both VPN gateways as part of the VPN encryption domain. Exclude them via crypt.def or adjust your Palo configuration accordingly and you should be fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 08:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29447#M6021</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-26T08:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN with PaloAlto not working about invalid proxy id</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29448#M6022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do they do a NAT on the PaloAlto Side before encapsulating the IP packet in the IPSec Tunnel, so the IP of the Client is actually the 192.168.121.200 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 13:17:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-with-PaloAlto-not-working-about-invalid-proxy-id/m-p/29448#M6022</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2018-09-26T13:17:39Z</dc:date>
    </item>
  </channel>
</rss>

