<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unknown traffic from VPN blade in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74026#M11495</link>
    <description>&lt;P&gt;Based on the screenshot, your Check Point firewall is not the one initiating.&amp;nbsp; Your firewall is sending a response to 164.52.x.x who attempted to start an IKE Phase 1 negotiation with you; the full content of the sent notification is not shown in your screenshot but it is probably "Invalid ID".&amp;nbsp; This response is sent by a Check Point firewall when an unknown peer/IP address attempts to start a VPN negotiation; in a site to site setup VPN peer IP addresses must normally be known ahead of time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2020 13:23:05 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-02-03T13:23:05Z</dc:date>
    <item>
      <title>unknown traffic from VPN blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/73985#M11493</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;could you please explain why VPN is initiating traffic to an unknown destination.(SC attached)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 06:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/73985#M11493</guid>
      <dc:creator>Renjith_M_P</dc:creator>
      <dc:date>2020-02-03T06:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: unknown traffic from VPN blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/73993#M11494</link>
      <description>&lt;P&gt;This is a rather nice wish - but only you do know what is configured here ! The peer GW must be included in a VPN Community, otherwise, no key install will be sent. At least, this VPN is not coming up, so if you do not want it, you could even leave it this way&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 08:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/73993#M11494</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-03T08:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: unknown traffic from VPN blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74026#M11495</link>
      <description>&lt;P&gt;Based on the screenshot, your Check Point firewall is not the one initiating.&amp;nbsp; Your firewall is sending a response to 164.52.x.x who attempted to start an IKE Phase 1 negotiation with you; the full content of the sent notification is not shown in your screenshot but it is probably "Invalid ID".&amp;nbsp; This response is sent by a Check Point firewall when an unknown peer/IP address attempts to start a VPN negotiation; in a site to site setup VPN peer IP addresses must normally be known ahead of time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 13:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74026#M11495</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-03T13:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: unknown traffic from VPN blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74114#M11496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, that is my doubt. a VPN traffic is initiated to check point from an unknown IP which is not configured in my device, traffic got rejected by the device but after that a response is sending as key install. details are in attached screen shot. what kind of behavior is this.&lt;/P&gt;&lt;P&gt;we are getting lot of request from this unknown IP to some of the internal IP's. service is IKE ( Screen shot attached). we don't have any DAIP for this setup. as a precautionary&amp;nbsp; measure i have created an object and blocked this source IP in the policy.&lt;/P&gt;&lt;P&gt;is it a kind of attack. if yes how do i identity which device is originating this traffic and any helping hand from inside object.&lt;/P&gt;&lt;P&gt;Thank you for response.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 13:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74114#M11496</guid>
      <dc:creator>Renjith_M_P</dc:creator>
      <dc:date>2020-02-04T13:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: unknown traffic from VPN blade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74546#M11497</link>
      <description>&lt;P&gt;Your firewall is properly blocking it, there is nothing to be concerned about.&amp;nbsp; The attacker isn't going to get anywhere.&lt;/P&gt;
&lt;P&gt;You can see the owner of the netblock sending these IKE requests here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://wq.apnic.net/static/search.html?query=164.52.36.247" target="_blank"&gt;https://wq.apnic.net/static/search.html?query=164.52.36.247&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I suppose you could try contacting the abuse email for that netblock, but in my experience with the specific country involved here you are just wasting your time.&amp;nbsp; It could also just be some kind of misconfiguration on their end but I highly doubt it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 15:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/unknown-traffic-from-VPN-blade/m-p/74546#M11497</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-09T15:05:32Z</dc:date>
    </item>
  </channel>
</rss>

