<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN LAN to LAN to 1490 is up but not working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46776#M9051</link>
    <description>also check this out:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/VPN-Routing-Route-all-except-for-Internet-traffic/td-p/22913" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/VPN-Routing-Route-all-except-for-Internet-traffic/td-p/22913&lt;/A&gt;</description>
    <pubDate>Wed, 13 Mar 2019 16:01:02 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2019-03-13T16:01:02Z</dc:date>
    <item>
      <title>VPN LAN to LAN to 1490 is up but not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46749#M9038</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp; I am configuring a L2L between a CP 1490 and a 5000 box. I am pretty sure the problem lies on the 1490, because we have quite a few tunnels on the 5000 that work just fine -and this is my first time with a 1490 so I might be missing something there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; When I check on the 1490, it says the tunnel is up -I can see the same in the 5000. The logs in the 5000 shows the packets get encrypted and sent on its way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking the logs on the 1490 I see the key gets installed, but I also see this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;IKE failure: Child SA exchange: Received notification from peer: Traffic selectors unacceptable&lt;/EM&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Are any routes needed in the 1490 for the subnets on the other side? Since this is a Policy-based L2L I guess they are not but I am trying to make sure I am not missing anything.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp; //Anibal&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 13:22:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46749#M9038</guid>
      <dc:creator>Anibal_Onnis</dc:creator>
      <dc:date>2019-03-13T13:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN LAN to LAN to 1490 is up but not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46775#M9050</link>
      <description>EncDom mismatch - check Encryption Domain membership on both ends and make sure you've got a proper cross-routing in place, otherwise you may need to look into this --sk86582--</description>
      <pubDate>Wed, 13 Mar 2019 15:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46775#M9050</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-13T15:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN LAN to LAN to 1490 is up but not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46776#M9051</link>
      <description>also check this out:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/VPN-Routing-Route-all-except-for-Internet-traffic/td-p/22913" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/VPN-Routing-Route-all-except-for-Internet-traffic/td-p/22913&lt;/A&gt;</description>
      <pubDate>Wed, 13 Mar 2019 16:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46776#M9051</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-13T16:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN LAN to LAN to 1490 is up but not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46808#M9066</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp; the encryption domain in the hub CP is system-wide, and all I've got for this community is the only subnet on the remote side (1490).&lt;/P&gt;&lt;P&gt;On the remote side, I am defining the remote subnets manually, matching two of the subnets in the hub. The local encryption domain includes the only LAN subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read the SK you posted about VPN routing -in the hub, I am only routing through the center. Is there such an option in the 1490?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Anibal&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 18:43:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-LAN-to-LAN-to-1490-is-up-but-not-working/m-p/46808#M9066</guid>
      <dc:creator>Anibal_Onnis</dc:creator>
      <dc:date>2019-03-13T18:43:04Z</dc:date>
    </item>
  </channel>
</rss>

