<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN TU HASH OR HEX in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36858#M7758</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Oct 2018 15:09:19 GMT</pubDate>
    <dc:creator>jessica_smith</dc:creator>
    <dc:date>2018-10-19T15:09:19Z</dc:date>
    <item>
      <title>VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36852#M7752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you do VPN TU and select , say option 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer 11.27.106.218 SAs:&lt;/P&gt;&lt;P&gt;1. IKE SA &amp;lt;b4ce6d95oc62e935,3f7248d932f017d3&amp;gt;:&lt;/P&gt;&lt;P&gt;2. IKE SA &amp;lt;f12ca4613c564c2b,09001dcf0ca41373&amp;gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer 15.74.27.48 SAs:&lt;/P&gt;&lt;P&gt;1. IKE SA &amp;lt;&lt;STRONG&gt;11282929er737d23&lt;/STRONG&gt;,35a68bw4431fa043&amp;gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 1: What are these alpha numeric numbers for and how can I decode them? whats the pupose of these? why are they alpha numeric? is it due to security?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2: Why first peer has 2 IKE SA entries and the other one has only one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 07:22:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36852#M7752</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-10-19T07:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36853#M7753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you explain what is the final goal here? What you would like to check?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;SPI: the 32-bit value used to distinguish among different SAs terminating at the same destination and using the same IPsec protocol.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px;"&gt;2.&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #000000; font-size: 12px;"&gt;Each IPSec peer agrees to set up SAs consisting of policy parameters to be used during the IPSec session. The SAs are unidirectional for IPSec, so that peer 1 will offer peer 2 a policy. If peer 2 accepts this policy, it will send that policy back to peer 1. This establishes two one-way SAs between the peers. Two-way communication consists of two SAs, one for each direction.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 07:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36853#M7753</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-10-19T07:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36854#M7754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Aleksei for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your question, I would like to know the phase 2 encryption domains from the cli that are being configured (local and remote encryption domain).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 11:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36854#M7754</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-10-19T11:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36855#M7755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That can be checked by enabling vpn debug and looking into ke.elg during key exchange. You cannot check that once SA is formed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, answer to your original question is "neither", but Alexey has covered that already&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 12:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36855#M7755</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-10-19T12:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36856#M7756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In another thread you asked for this command and there was an answer about different options of CLI commands. Do they all not work on your firewalls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) &lt;A href="https://community.checkpoint.com/docs/DOC-2214-common-check-point-commands-ccc" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2214-common-check-point-commands-ccc&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 | grep Peer: | cut -d ';' -f8 | cut -c 8- | sort -ng | uniq | xargs -I % sh -c 'echo; tput sgr0; echo -n VPN Gateway: ; tput setaf 1; echo -e %; tput sgr0; echo -e&amp;nbsp; Routing: ; tput setaf 2; fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 | grep % | grep -o 'From.*Peer' | cut -c 6- | rev | cut -c 7- | rev' | sed 's/; To:/ -/g'; tput sgr0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-3021" target="_blank"&gt;Show VPN Routing on CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11px; font-family: 'courier new', courier, monospace;"&gt;echo -e "\033[0m####################\n# VPN Routing&amp;nbsp; &amp;nbsp; &amp;nbsp; #\n####################";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep -v "+"| awk '{split($0,a,";"); print a[8]}' |sort -ng |uniq | awk '{split($0,a," "); print a[2]}' | xargs -I % sh -c&amp;nbsp; 'echo -n "External Gateway: ";echo -e "\033[0;31m % \033[37m";echo -e "&amp;nbsp; Routing: \033[32m";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep % |awk '\''{split($0,b,";"); print b[6] b[7]}'\''| sed 's/From\://'| sed 's/To\:/-/'|sort -u ;echo -e "\033[0m" '&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)&amp;nbsp;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/thread/5560-command-bto-check-particular-segment-is-already-part-of-any-encryption-domain#comment-8134" title="https://community.checkpoint.com/thread/5560-command-bto-check-particular-segment-is-already-part-of-any-encryption-domain#comment-8134" target="_blank"&gt;Tim Hall's comment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;fw tab -t vpn_routing -u -f | awk '{ print $18 "&amp;nbsp; " $19 "&amp;nbsp; " $20 "&amp;nbsp; " $21 "&amp;nbsp; " $22 "&amp;nbsp; " $23 }'&amp;nbsp; | awk NF | sort -n&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36856#M7756</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2019-06-21T09:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36857#M7757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aleksei,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried few of them already but they dont seem to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@FW1-USA-A:0]# echo -e "\033[0m####################\n# VPN Routing #\n####################";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep -v "+"| awk '{split($0,a,";"); print a[8]}' |sort -ng |uniq | awk '{split($0,a," "); print a[2]}' | xargs -I % sh -c 'echo -n "External Gateway: ";echo -e "\033[0;31m % \\033[37m";echo -e " Routing: \033[32m";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep % |awk '\''{split($0,b,";"); print b[6] b[7]}'\''| sed 's/From\://'| sed 's/To\:/-/'|sort -u ;echo -e "\033[0m" '&lt;BR /&gt;####################&lt;BR /&gt;# VPN Routing #&lt;BR /&gt;####################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;[Expert@FW1-&lt;SPAN&gt;USA&lt;/SPAN&gt;-A:0]# fw tab -t vpn_routing -u -f | awk '{ print $18 " " $19 " " $20 " " $21 " " $22 " " $23 }' | awk NF | sort -n&lt;BR /&gt;fw: Warning: Can't find ::CPSB-CTNT in cp.macro. License version might be not compatible&lt;BR /&gt; Warning: Can't find ::CPSB-CTNT in cp.macro. License version might be not compatible&lt;BR /&gt; Using cptfmt&lt;BR /&gt;Formatting table's data - this might take a while...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 15:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36857#M7757</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-10-19T15:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN TU HASH OR HEX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36858#M7758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 15:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-TU-HASH-OR-HEX/m-p/36858#M7758</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-10-19T15:09:19Z</dc:date>
    </item>
  </channel>
</rss>

