<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Issue - Wrong IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31404#M6536</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe what you are seeing is that your gateway is sending it's Main IP as the Ike ID for the VPN tunnel and the peer not completing the process and essentially the tunnel not forming.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know what the far end of the tunnel gateway is? I know on cisco ASA they can either turn off some strict checking of the Ike Id against the peer IP,&amp;nbsp; or they can set the IKE to your main IP but have the peer IP as the IP that you desire.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For reference.&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36425&amp;amp;t=1549565616533" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36425&amp;amp;t=1549565616533"&gt;IKE Main Mode negotiation fails with error "invalid id" when Check Point Security Gateway has ISP redundancy configured,…&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2019 18:58:05 GMT</pubDate>
    <dc:creator>Mark_Mitchell</dc:creator>
    <dc:date>2019-02-07T18:58:05Z</dc:date>
    <item>
      <title>VPN Issue - Wrong IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31403#M6535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a gateway with several VPN's on.&amp;nbsp; Some via the Internet, and some routed internally via MPLS lines.&amp;nbsp; These all work fine.&amp;nbsp; Now I'm trying to set up a new site-to-site VPN and&amp;nbsp;it isn't working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I'm trying to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78254_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;So my peer IP is a DMZ interface - 12.12.12.178.&lt;/P&gt;&lt;P&gt;I'm VPNing to remote peer IP 192.168.145.10.&lt;/P&gt;&lt;P&gt;On the firewall I'm routing 192.168.145.0/24 via 12.12.12.224.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall-A&amp;gt; show route destination 192.168.145.10&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt; O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt; A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt; U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;S 192.168.145.0/24 via 12.12.12.224, eth2.105, cost 0, age 279519&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;an existing VPN set up in the same way via a different DMZ interface and that works fine - although I'm reminded that we had exactly the same problem when setting that up, and I fixed it on my side.&amp;nbsp; I just can't remember what I did to fix it, hence asking for help!&amp;nbsp; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that the remote side is seeing me coming from the gateway's public "main IP" - shown as A.A.A.A on the diagram.&amp;nbsp; In Ikeview I see IP's 192.168.145.10 and 12.12.12.178 in packets 1 to 5, then in packet 6 I'm sending my public A.A.A.A IP to the remote peer.&amp;nbsp; I don't understand why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78244_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my gateway I've got VPN link selection set&amp;nbsp;as follows, using the routing table, which is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78251_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78252_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78253_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't really alter this otherwise existing VPN's will stop working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know what else I need to do to stop P1 Packet 6 sending my A.A.A.A IP instead of the correct 12.12.12.178 IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 16:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31403#M6535</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-02-07T16:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue - Wrong IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31404#M6536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe what you are seeing is that your gateway is sending it's Main IP as the Ike ID for the VPN tunnel and the peer not completing the process and essentially the tunnel not forming.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know what the far end of the tunnel gateway is? I know on cisco ASA they can either turn off some strict checking of the Ike Id against the peer IP,&amp;nbsp; or they can set the IKE to your main IP but have the peer IP as the IP that you desire.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For reference.&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36425&amp;amp;t=1549565616533" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36425&amp;amp;t=1549565616533"&gt;IKE Main Mode negotiation fails with error "invalid id" when Check Point Security Gateway has ISP redundancy configured,…&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 18:58:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31404#M6536</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-07T18:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue - Wrong IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31405#M6537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A _jive_internal="true" data-userid="55298" data-username="a4b94975-4348-49b0-b734-83659bd9e567" href="https://community.checkpoint.com/people/a4b94975-4348-49b0-b734-83659bd9e567"&gt;Mark Mitchell&lt;/A&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found a similar solution at the same time...&amp;nbsp; the last paragraph of Pg. 10 of&amp;nbsp;&lt;A class="link-titled" href="http://dl3.checkpoint.com/paid/e8/How-To-Setup-a-site-to-site-VPN-tunnel-using-external-and-internal-NIC.pdf?HashKey=1549568572_48c88db4808bb9fb1e694d69d5c4d3a7&amp;amp;xtn=.pdf" title="http://dl3.checkpoint.com/paid/e8/How-To-Setup-a-site-to-site-VPN-tunnel-using-external-and-internal-NIC.pdf?HashKey=1549568572_48c88db4808bb9fb1e694d69d5c4d3a7&amp;amp;xtn=.pdf"&gt;http://dl3.checkpoint.com/paid/e8/How-To-Setup-a-site-to-site-VPN-tunnel-using-external-and-internal-NIC.pdf?HashKey=154…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The remote side allowed IKE from our public IP too, and the tunnel came straight up &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 19:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31405#M6537</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-02-07T19:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue - Wrong IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31406#M6538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No worries Matt. Glad you got it sorted.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 19:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/31406#M6538</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-07T19:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue - Wrong IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/63087#M12791</link>
      <description>&lt;P&gt;We are about to configure something very similar -- we currently have many VPNs via the external interface of the gateway, and we are adding one which will go over an internal interface. The .pdf linked is rather old and only lists R65 - R75 as supported versions and SecurePlatform and IPSO as supported OS's.&amp;nbsp; I have looked and have not found an updated version of this document, so throwing these questions out to the group:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Can I use "Calculate IP based on network topology" in my scenario, instead of probing (we currently used "Selected address from topology table")?&lt;/P&gt;&lt;P&gt;2. Do I need to create a separate VPN community?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 18:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Issue-Wrong-IP/m-p/63087#M12791</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2019-09-18T18:17:59Z</dc:date>
    </item>
  </channel>
</rss>

