<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-Site VPN connection issue with CISCO ASA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36867#M7761</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also this KB can be a good start&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk53980"&gt;Site to Site with 3rd party&lt;/A&gt;&lt;/P&gt;&lt;P&gt;then you need to ensure what's the design (routing mecanism, encryption domain, provider implementation of protocols)&lt;/P&gt;&lt;P&gt;then turn on complete debug following &lt;A href="https://community.checkpoint.com/migrated-users/45132"&gt;Aleksei Shelepov&lt;/A&gt;‌ suggestion.&lt;/P&gt;&lt;P&gt;after the log collect, install&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994"&gt;IKE View Tool&lt;/A&gt;&amp;nbsp;and try understanding something. (@checkpoint please hear me crying... rewrite this tool and add it to the diagnosticview tool ! &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2018 11:08:39 GMT</pubDate>
    <dc:creator>Pierre-Aymeric_</dc:creator>
    <dc:date>2018-07-05T11:08:39Z</dc:date>
    <item>
      <title>Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36865#M7759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have troubles with a Site-to-Site VPN between a R77.30 and a CISCO ASA Gateway.&lt;/P&gt;&lt;P&gt;The subnets on my side:&lt;/P&gt;&lt;P&gt;192.168.4.0/22&lt;/P&gt;&lt;P&gt;192.168.30.0/22&lt;/P&gt;&lt;P&gt;192.168.40.0/22&lt;/P&gt;&lt;P&gt;I have 3 subnets on my side which needs to access 12 subnets on the other side.&lt;/P&gt;&lt;P&gt;The 12 subnets are in the Encryption Domain. However only devices only 2 subnets can ping a remote Host.&lt;/P&gt;&lt;P&gt;The hosts 192.168.4.1 and 192.168.40.1 can ping 192.168.2.12 in the remote subnet.&lt;/P&gt;&lt;P&gt;The connection from 192.168.30.0/22 is very unstable and I get timeouts longer then half a day. At some point the connection is working again. On both sides nothing was changed. Can someone help? I don't know how to troubleshoot the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 19:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36865#M7759</guid>
      <dc:creator>bam_oida</dc:creator>
      <dc:date>2018-07-04T19:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36866#M7760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesn't it look like something worth asking tech support of the vendor to deal with your exact networks and setup?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm"&gt;VPN R77 Versions Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32788" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32788"&gt;VPN Troubleshooting Solutions&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk63560" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk63560"&gt;How to run complete VPN debug on Security Gateway to troubleshoot VPN issues?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 07:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36866#M7760</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-07-05T07:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36867#M7761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also this KB can be a good start&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk53980"&gt;Site to Site with 3rd party&lt;/A&gt;&lt;/P&gt;&lt;P&gt;then you need to ensure what's the design (routing mecanism, encryption domain, provider implementation of protocols)&lt;/P&gt;&lt;P&gt;then turn on complete debug following &lt;A href="https://community.checkpoint.com/migrated-users/45132"&gt;Aleksei Shelepov&lt;/A&gt;‌ suggestion.&lt;/P&gt;&lt;P&gt;after the log collect, install&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30994"&gt;IKE View Tool&lt;/A&gt;&amp;nbsp;and try understanding something. (@checkpoint please hear me crying... rewrite this tool and add it to the diagnosticview tool ! &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 11:08:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36867#M7761</guid>
      <dc:creator>Pierre-Aymeric_</dc:creator>
      <dc:date>2018-07-05T11:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36868#M7762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to go thru &lt;SPAN style="color: #0066cc; text-decoration: underline;"&gt;sk108600: VPN Site-to-Site with 3rd Party.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 11:13:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36868#M7762</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-07-05T11:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36869#M7763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class=""&gt;&lt;P&gt;Hello I tried debug with IKEView. I saw that Lifetime and Encryption of Phase 1 was different. I corrected this but now Iam unable to establish Phase 1.&lt;/P&gt;&lt;P&gt;Iam stuck in MM MM packet 3 (20:56:18)-&amp;nbsp; Thu Jul 5 2018&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Transport:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;UDP (IPv4)&lt;BR /&gt;PeerIP:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; xxxxxxx&lt;BR /&gt;PeerPort:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;500&lt;BR /&gt;Peer Name:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;gw_CHINA&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==&amp;gt; Sent to peer x.x.x.x&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The parameters of Transform Payload - KEY_IKE like Encryption Algorithm, Key Length, Hash Algorithm, Authentication Method, Life Type,Group Description and Life Duration are equal on both sides.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 19:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36869#M7763</guid>
      <dc:creator>bam_oida</dc:creator>
      <dc:date>2018-07-05T19:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36870#M7764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked the PSK again? MM3 should be part of the key exchange.&lt;/P&gt;&lt;P&gt;Otherwise, what type of VPN Tunnel Sharing is configured in the community?&lt;/P&gt;&lt;P&gt;If your phase 1 comes up again, you see the information in P2, if if needed you can try between the 3 options. I had some problems with 3rd party gateways in the past, when using "One tunnel per subnet pair" or "One tunnel per gateway pair" depending what the partner had configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 17:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36870#M7764</guid>
      <dc:creator>Georg_Reichau</dc:creator>
      <dc:date>2018-07-09T17:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN connection issue with CISCO ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36871#M7765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have access to the ASA to view the configuration / logs there...?&lt;/P&gt;&lt;P&gt;Most common issue is the "One tunnel per subnet pair" setting not set. Also I had some issues with pfs group set to higher than group5, for any reason, it only worked with group 5 or less.&lt;/P&gt;&lt;P&gt;Next one would be to have a look at the IPSEC and IKE session details on ASA side, to see, if your packets arive there but are not routed back correctly or other issues...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 19:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-connection-issue-with-CISCO-ASA/m-p/36871#M7765</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2018-07-09T19:24:44Z</dc:date>
    </item>
  </channel>
</rss>

