<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point with Cisco ASA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33879#M7115</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've trying create a VPN tunnel with ASA using CP R77.30, but think something is wrong because the other side cannot connect the internal network, they told me that has the same internal network. We could simulate the traffic , like CISCO ASA has Packtet Tracer. I used tcpdump and looked the logs in SmartView Tracker&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Tracker:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Record Details&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 396px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="width: 389px;"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 6px 6px 0px 0px;"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR style="height: 71px;"&gt;&lt;TD class="" style="height: 71px;"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" height="70" width="379"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="" style="width: 371px;"&gt;&lt;STRONG&gt;IKE:&lt;/STRONG&gt; Quick Mode completion [UDP (IPv4)].&lt;BR /&gt;&lt;STRONG&gt;IKE IDs:&lt;/STRONG&gt; host: 200.xxx.xxx.60( peer CP) and host: 10.xxx.1x.29&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;STRONG&gt;tcpdump:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;tcpdump -ni eth1 src&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;(PEER-ASA)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Peer CP.500 &amp;gt; PEER ASA.500 isakmp: phase 1 I ident&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;IP Peer CP.500 &amp;gt; PEER ASA.500 isakmp: phase2/others I oakley-quick[E]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Jun 2018 12:02:02 GMT</pubDate>
    <dc:creator>Luisnego</dc:creator>
    <dc:date>2018-06-25T12:02:02Z</dc:date>
    <item>
      <title>Check Point with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33879#M7115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've trying create a VPN tunnel with ASA using CP R77.30, but think something is wrong because the other side cannot connect the internal network, they told me that has the same internal network. We could simulate the traffic , like CISCO ASA has Packtet Tracer. I used tcpdump and looked the logs in SmartView Tracker&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Tracker:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Record Details&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 396px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="width: 389px;"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 6px 6px 0px 0px;"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR style="height: 71px;"&gt;&lt;TD class="" style="height: 71px;"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" height="70" width="379"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="" style="width: 371px;"&gt;&lt;STRONG&gt;IKE:&lt;/STRONG&gt; Quick Mode completion [UDP (IPv4)].&lt;BR /&gt;&lt;STRONG&gt;IKE IDs:&lt;/STRONG&gt; host: 200.xxx.xxx.60( peer CP) and host: 10.xxx.1x.29&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;STRONG&gt;tcpdump:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;tcpdump -ni eth1 src&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;(PEER-ASA)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Peer CP.500 &amp;gt; PEER ASA.500 isakmp: phase 1 I ident&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;IP Peer CP.500 &amp;gt; PEER ASA.500 isakmp: phase2/others I oakley-quick[E]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2018 12:02:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33879#M7115</guid>
      <dc:creator>Luisnego</dc:creator>
      <dc:date>2018-06-25T12:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33880#M7116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You say: "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;they told me that has the same internal network."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;It does not matter what hardware the other end is, but you cannot have communication over a normal VPN when you have the same network on both sides.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;First point is to make sure you have a different network defined on each side of the VPN, either by changing the IP range on one side or by using source NAT on both ends.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;When it is a different network, but just a chunk out of the range used at one end, ie local network is a 10.200/16 network and the other side is 10.200.200/24 you could use a exclusion group on the Check Point side.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;So there are a lot of possible answers here.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2018 21:09:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33880#M7116</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-25T21:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33881#M7117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;‌ Thanks, I can fix, I had overlap in my network. Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-with-Cisco-ASA/m-p/33881#M7117</guid>
      <dc:creator>Luisnego</dc:creator>
      <dc:date>2018-06-26T12:37:26Z</dc:date>
    </item>
  </channel>
</rss>

