<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint to Cisco VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34387#M7221</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a&amp;nbsp;Star VPN&amp;nbsp;with 3rd Party Cisco ASA firewall (interoperable device).&amp;nbsp; The VPN is up and stable and able to pass traffic between encryption domains.&amp;nbsp; We are experiencing an&amp;nbsp;intermittent issue when traffic is initiated from the Cisco side to a resource on our Checkpoint side, when it needs to traverse our Mesh VPN&amp;nbsp;network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Source&amp;nbsp;connects to resource that goes over 2 VPN connections, it fails on the first and sometimes second attempt&amp;nbsp;but successfully connects the third attempt.&amp;nbsp; It never connects the first time.&amp;nbsp; There are no drops on FW-A or FW-B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Working&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Cisco ASA&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Star VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checkpoint FW-A&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Resource&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Not Working&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Cisco ASA&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Star VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checkpoint FW-A&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Mesh VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt; Checkpoint FW-B&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt; Resource&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone run into this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2018 18:11:17 GMT</pubDate>
    <dc:creator>Raj_Khatri</dc:creator>
    <dc:date>2018-06-27T18:11:17Z</dc:date>
    <item>
      <title>Checkpoint to Cisco VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34387#M7221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a&amp;nbsp;Star VPN&amp;nbsp;with 3rd Party Cisco ASA firewall (interoperable device).&amp;nbsp; The VPN is up and stable and able to pass traffic between encryption domains.&amp;nbsp; We are experiencing an&amp;nbsp;intermittent issue when traffic is initiated from the Cisco side to a resource on our Checkpoint side, when it needs to traverse our Mesh VPN&amp;nbsp;network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Source&amp;nbsp;connects to resource that goes over 2 VPN connections, it fails on the first and sometimes second attempt&amp;nbsp;but successfully connects the third attempt.&amp;nbsp; It never connects the first time.&amp;nbsp; There are no drops on FW-A or FW-B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Working&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Cisco ASA&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Star VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checkpoint FW-A&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Resource&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Not Working&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Source&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Cisco ASA&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Star VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checkpoint FW-A&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Mesh VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt; Checkpoint FW-B&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;gt; Resource&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone run into this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 18:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34387#M7221</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-06-27T18:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint to Cisco VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34388#M7222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to setup Dead Peer Detection on the ASA, follow the SK to set the CP to work with DPD and set permanent tunnels on and set your tunnels to pair on per subnet not per host pair.&lt;/P&gt;&lt;P&gt;Do you happen to use&amp;nbsp; an exclusion group for the center gateway's VPN Topology? If so you could run into an issue that the CP will use per host tunneling.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 20:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34388#M7222</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-27T20:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint to Cisco VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34389#M7223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The VPN tunnel is already configured for per subnet pair and&amp;nbsp;we are using a Group with Exclusions for the center gateway VPN topology.&amp;nbsp; It appears this is the SK describing this - sk39679&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:31:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-to-Cisco-VPN/m-p/34389#M7223</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-06-28T11:31:18Z</dc:date>
    </item>
  </channel>
</rss>

