<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure Site to Site VPN issue. Connection seems to be ok but ping/telnet is not working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30863#M6452</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up a S2S VPN between azure and a Checkpoint cluster 5400 R77.30 and it seems to be working, since on the azure side as well on the checkpoint side it appears connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66338_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the image, even that it is connected, Azure only show Data out, which is weird since it seems that Checkpoint is not routing the traffic property.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is confirmed when we try to ping on both sides (ping and telnet are enabled). On the customer side, a traceroute shows that the traffic is not routing properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66339_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The checkpoint cluster is conformed by the 200.75.50.131 (which is the ip that is routing the traffic) and the 200.75.50.132 (which is the IP that we match on the local network gateway to peer with azure).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The weirdest thing is that on the checkpoint side, traffic seems to be passing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66340_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66341_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;Is there anything that we are missing on the set up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jun 2018 14:51:16 GMT</pubDate>
    <dc:creator>Andres_Romero</dc:creator>
    <dc:date>2018-06-12T14:51:16Z</dc:date>
    <item>
      <title>Azure Site to Site VPN issue. Connection seems to be ok but ping/telnet is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30863#M6452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up a S2S VPN between azure and a Checkpoint cluster 5400 R77.30 and it seems to be working, since on the azure side as well on the checkpoint side it appears connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66338_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the image, even that it is connected, Azure only show Data out, which is weird since it seems that Checkpoint is not routing the traffic property.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is confirmed when we try to ping on both sides (ping and telnet are enabled). On the customer side, a traceroute shows that the traffic is not routing properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66339_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The checkpoint cluster is conformed by the 200.75.50.131 (which is the ip that is routing the traffic) and the 200.75.50.132 (which is the IP that we match on the local network gateway to peer with azure).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The weirdest thing is that on the checkpoint side, traffic seems to be passing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66340_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66341_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;Is there anything that we are missing on the set up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 14:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30863#M6452</guid>
      <dc:creator>Andres_Romero</dc:creator>
      <dc:date>2018-06-12T14:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Site to Site VPN issue. Connection seems to be ok but ping/telnet is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30864#M6453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Checkpoint side seems to be ok to me. you need to do traffic captures to makes sure ESP traffic leaving the checkpoint on the correct interface and capture on azure and logs on azure to see if it is receiving traffic or not or the traffic is being dropped by policy on azure side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 15:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30864#M6453</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-06-12T15:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Site to Site VPN issue. Connection seems to be ok but ping/telnet is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30865#M6454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply. I'm afraid that the customer is not an expert on Checkpoint, so I wonder if you can guide us in how they can do that traffic captures on the checkpoint side.&lt;/P&gt;&lt;P&gt;I'm also wonder if you know if maybe they need to set up some routing information on checkpoint, for me the traffic is stuck on the 200.75.50.131 device and it is not routing it to the gateway (200.75.50.132).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 19:41:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30865#M6454</guid>
      <dc:creator>Andres_Romero</dc:creator>
      <dc:date>2018-06-12T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Site to Site VPN issue. Connection seems to be ok but ping/telnet is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30866#M6455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For traffic capture you can use tcpdumps and fw monitor please check the following links and you can find great examples on youtube&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30583&amp;amp;partition=General&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30583&amp;amp;partition=General&amp;amp;product=Security"&gt;What is FW Monitor?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://danielmiessler.com/study/tcpdump/" title="https://danielmiessler.com/study/tcpdump/"&gt;A tcpdump Tutorial and Primer with Examples - Daniel Miessler&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.youtube.com/watch?v=2a9UCXGs87E" title="https://www.youtube.com/watch?v=2a9UCXGs87E"&gt;How to use TCPDUMP Command while troubleshooting CheckPoint Gateways? - YouTube&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the routing we need to understand the topology first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 20:28:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Azure-Site-to-Site-VPN-issue-Connection-seems-to-be-ok-but-ping/m-p/30866#M6455</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-06-12T20:28:46Z</dc:date>
    </item>
  </channel>
</rss>

