<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route-based VPN issue with DAIP third party device (Cisco 1921) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63227#M11945</link>
    <description>&lt;P&gt;This is documented in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92845&amp;amp;partition=General&amp;amp;product=Security" target="_blank"&gt;sk92845: Can users create a &lt;STRONG&gt;GRE&lt;/STRONG&gt;tunnel on Gaia OS?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;(but see also&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90060&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank"&gt;sk90060: &lt;STRONG&gt;GRE&lt;/STRONG&gt;tunnel stops working inside a Site-to-Site VPN tunnel established with Check Point cluster&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157893&amp;amp;partition=General&amp;amp;product=CloudGuard" target="_blank"&gt;sk157893: Check Point recommendations for tunneling through IPsec instead of &lt;STRONG&gt;GRE&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The main GRE performance disadvantages can be found in &lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32578&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank"&gt;sk32578: SecureXL Mechanism&lt;/A&gt; and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105119&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk105119: Best Practices - VPN Performance&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2019 07:00:21 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-09-20T07:00:21Z</dc:date>
    <item>
      <title>Route-based VPN issue with DAIP third party device (Cisco 1921)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63041#M11942</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've configure one of my CP cluster to do route-based VPN instead domain-based.&lt;/P&gt;&lt;P&gt;A ticket is open but it seems CP don't really understand the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my configuration is:&lt;/P&gt;&lt;P&gt;- Cluster CP (OpenServer) R80.10 Take 214&lt;/P&gt;&lt;P&gt;- Cisco 1921 IOS 15.5 (4G modem with IPSec support APN/public IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My need is a route-based VPN between my Cluster and this router.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My issue is: all is working fine if i set the public IP for this third party device, GRE over IPsec is working fine. If i set this object in DAIP, with wan interface configured as Dynamic IP in its topology, IPsec tunnel is up but there is no GRE traffic inside.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the CP log tracker, the "VPN peer Gateway" field have the right name (rt-lte-xxx) and public IP when i set public IP on the object, but in DAIP mode, only 0.0.0.19 is visible, nothing else.&lt;/P&gt;&lt;P&gt;I think Checkpoint can't retrieve the object name/dynamic IP address when packet is routing thought VTI interface.&lt;/P&gt;&lt;P&gt;Anyone here is able to route-based VPN trafic with Third party object in DAIP mode?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 12:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63041#M11942</guid>
      <dc:creator>Equipe_Reseau2</dc:creator>
      <dc:date>2019-09-18T12:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN issue with DAIP third party device (Cisco 1921)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63216#M11943</link>
      <description>I assume if you're doing DAIP that you're authenticating with certificates.&lt;BR /&gt;Have you done any debugging or opened a TAC case?</description>
      <pubDate>Fri, 20 Sep 2019 02:43:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63216#M11943</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-20T02:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN issue with DAIP third party device (Cisco 1921)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63223#M11944</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes i use certificate, it works fine. As i explain, if i set the third party device on public fixed IP, it works fine.&lt;/P&gt;&lt;P&gt;I had only one session with Checkpoint support but the technician (couldn't be an engineer), first told me that GRE is not supported by Checkpoint, he don't know the route-based VPN is IPsec over GRE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPsec debug don't give anything as this layer works fine.&lt;/P&gt;&lt;P&gt;If you have some command for debugging GRE in Checkpoint, i take it !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 06:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63223#M11944</guid>
      <dc:creator>Equipe_Reseau2</dc:creator>
      <dc:date>2019-09-20T06:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN issue with DAIP third party device (Cisco 1921)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63227#M11945</link>
      <description>&lt;P&gt;This is documented in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92845&amp;amp;partition=General&amp;amp;product=Security" target="_blank"&gt;sk92845: Can users create a &lt;STRONG&gt;GRE&lt;/STRONG&gt;tunnel on Gaia OS?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;(but see also&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk90060&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank"&gt;sk90060: &lt;STRONG&gt;GRE&lt;/STRONG&gt;tunnel stops working inside a Site-to-Site VPN tunnel established with Check Point cluster&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157893&amp;amp;partition=General&amp;amp;product=CloudGuard" target="_blank"&gt;sk157893: Check Point recommendations for tunneling through IPsec instead of &lt;STRONG&gt;GRE&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The main GRE performance disadvantages can be found in &lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32578&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank"&gt;sk32578: SecureXL Mechanism&lt;/A&gt; and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105119&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk105119: Best Practices - VPN Performance&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 07:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/63227#M11945</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-20T07:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN issue with DAIP third party device (Cisco 1921)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/70684#M11946</link>
      <description>Update: a TAC is open since September, the issue has not been understood by level 1 technicien during more than two month, an escalation was impossible, i was upset...&lt;BR /&gt;Now, after 3 month, i received a 1st fix, doesn't worked. I've done a lot of debug with script provided by CP, i'm waiting some news...</description>
      <pubDate>Tue, 17 Dec 2019 14:39:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-based-VPN-issue-with-DAIP-third-party-device-Cisco-1921/m-p/70684#M11946</guid>
      <dc:creator>Equipe_Reseau2</dc:creator>
      <dc:date>2019-12-17T14:39:06Z</dc:date>
    </item>
  </channel>
</rss>

