<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: encryption failure: Ike version: ikev2 not supported for peer in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7492#M903</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll give your suggestions a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 15 Oct 2017 21:39:58 GMT</pubDate>
    <dc:creator>Ron_N</dc:creator>
    <dc:date>2017-10-15T21:39:58Z</dc:date>
    <item>
      <title>encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7489#M900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to setup a Site-to-Site connection between Azure VPN and Checkpoint vSec (R77.30) on AWS.&lt;/P&gt;&lt;P&gt;I was able to setup a connection using Azure Basic gateway with IKEv1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm trying to setup between Azure VPN (High Performance) gateway and Checkpoint vSec (R77.30).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;High Performance gateway uses IKEv2 and have applied the following IKE policy on Azure Gateway.&lt;/P&gt;&lt;P&gt;Phase 1: AES256, SHA384, DH14, SA 28800&lt;/P&gt;&lt;P&gt;Phase 2: AES256, SHA256, PFS2048, SA 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm getting the error: encryption failure: Ike version: ikev2 not supported for peer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm new to checkpoint. Would be great if someone could tell me what the error means and if IKEv2 is even supported for the above Phase 1 and 2 parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Oct 2017 14:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7489#M900</guid>
      <dc:creator>Ron_N</dc:creator>
      <dc:date>2017-10-15T14:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7490#M901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd recommend the following VPN configuration within Check Point for initial testing:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="60116" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/60116_pastedImage_2.png" style="width: 620px; height: 343px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Phase 1 SA Lifetime is expressed by Check Point in minutes, while the Phase 2 SA Lifetime is expressed in seconds please make sure to enter 480 min (28800 sec).&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="60112" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/60112_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't help as well, please perform a IKE debug as described in &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk112139"&gt;sk112139&lt;/A&gt; together with &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk33327"&gt;sk33327&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7490#M901</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-10-15T19:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7491#M902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm pretty sure to use IKEv2 with Azure it must be a route-based VPN instead of domain-based.&amp;nbsp; If you have CoreXL enabled on your gateway (which it is by default), you cannot do a route-based VPN on R77.30.&amp;nbsp; Turning off CoreXL will slam all firewall inspection duties (not just VPN-related functions) onto one core no matter how many cores the firewall has.&amp;nbsp; The performance impact of disabling CoreXL will range from minimal to utterly catastrophic depending on the total number of cores on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you upgrade the gateway to R80.10, route-based VPNs and CoreXL can be used together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7491#M902</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-15T19:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7492#M903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll give your suggestions a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Oct 2017 21:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7492#M903</guid>
      <dc:creator>Ron_N</dc:creator>
      <dc:date>2017-10-15T21:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7493#M904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct. I have route based VPN setup on Azure. The new gen VPN Gateways are only route based however applying IKE policy to the Azure connection enables gateway to establish connection to policy based devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also logged a support case with Azure support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Oct 2017 21:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7493#M904</guid>
      <dc:creator>Ron_N</dc:creator>
      <dc:date>2017-10-15T21:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7494#M905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Danny, thanks for your suggestion, that got the VPN working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 01:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7494#M905</guid>
      <dc:creator>Ron_N</dc:creator>
      <dc:date>2017-10-16T01:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7495#M906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great. I updated our &lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2272"&gt;Site-to-Site VPN Compatibility Matrix&lt;/A&gt; accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 07:00:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7495#M906</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-10-16T07:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7496#M907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if you were able to share the configuration you used connecting to the Azure &lt;STRONG&gt;Basic&lt;/STRONG&gt; VPN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 23:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7496#M907</guid>
      <dc:creator>James_Mcintosh</dc:creator>
      <dc:date>2019-01-07T23:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7497#M908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its been over a year, I don't really remember the configuration I had, but let me dig through my notes and see what I find out. I don't have access to checkpoint device at present but happy to spin up a quick trial on AWS to test it out with Azure Basic GW &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 21:32:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7497#M908</guid>
      <dc:creator>Ron_N</dc:creator>
      <dc:date>2019-01-08T21:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: encryption failure: Ike version: ikev2 not supported for peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7498#M909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ron,&lt;/P&gt;&lt;P&gt;That would be amazing if you could help me out!&lt;BR /&gt;Many thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2019 03:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/encryption-failure-Ike-version-ikev2-not-supported-for-peer/m-p/7498#M909</guid>
      <dc:creator>James_Mcintosh</dc:creator>
      <dc:date>2019-01-15T03:31:40Z</dc:date>
    </item>
  </channel>
</rss>

