<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 Checkpoint gateways, 1 SMS, site to site VPN ike failure in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Checkpoint-gateways-1-SMS-site-to-site-VPN-ike-failure/m-p/60442#M12077</link>
    <description>&lt;P&gt;First look for rejects in your log file saying "no valid SA found"&lt;/P&gt;&lt;P&gt;Then on your active 12400 member do at bash level:&lt;/P&gt;&lt;P&gt;cd $FWDIR/log&lt;/P&gt;&lt;P&gt;vpn debug on&lt;/P&gt;&lt;P&gt;vpn debug ikeon&lt;/P&gt;&lt;P&gt;try to connect through the vpn from a device in your encryption domain&lt;/P&gt;&lt;P&gt;vpn debug ikeoff&lt;/P&gt;&lt;P&gt;vpn debug off&lt;/P&gt;&lt;P&gt;Now get the file $FWDIR/log/ike.elg to your PC&lt;/P&gt;&lt;P&gt;Open it using the IKEVIEW utility&lt;/P&gt;&lt;P&gt;Look for the entries for your VPN Gateway&lt;/P&gt;&lt;P&gt;I'm pretty sure you'll see the cause for your problems&lt;/P&gt;&lt;P&gt;Common causes for missing SAs are:&lt;/P&gt;&lt;P&gt;wrong (internal) IP used in general tab of gateway object&lt;/P&gt;&lt;P&gt;Rulebase not allowing IPsec communication between gateways&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 06:13:18 GMT</pubDate>
    <dc:creator>peter_schumache</dc:creator>
    <dc:date>2019-08-16T06:13:18Z</dc:date>
    <item>
      <title>2 Checkpoint gateways, 1 SMS, site to site VPN ike failure</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Checkpoint-gateways-1-SMS-site-to-site-VPN-ike-failure/m-p/60436#M12076</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to connect a new (remote location) 3200 to an existing Checkpoint infrastructure consisting of 1 SMS and 2-12400 gateways in a cluster.&amp;nbsp; All devices are 80.20.&amp;nbsp; We have setup an site to site vpn.&amp;nbsp; SIC connects, and when we push policies to the new 3200, it is successful.&amp;nbsp; But we only get Up Phase 1 IKE from the 12400 to the 3200.&amp;nbsp; I have looked through assorted documentation, but have not found a solution.&amp;nbsp; Where do I start or what could the problem be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN tu on the remote 3200 for List all IKE SAs says, "No data to display".&lt;/P&gt;&lt;P&gt;VPN tu on the 12400 for List all IKE SAs has 4 different SAs for the 3200 peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 22:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Checkpoint-gateways-1-SMS-site-to-site-VPN-ike-failure/m-p/60436#M12076</guid>
      <dc:creator>KWD</dc:creator>
      <dc:date>2019-08-15T22:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Checkpoint gateways, 1 SMS, site to site VPN ike failure</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Checkpoint-gateways-1-SMS-site-to-site-VPN-ike-failure/m-p/60442#M12077</link>
      <description>&lt;P&gt;First look for rejects in your log file saying "no valid SA found"&lt;/P&gt;&lt;P&gt;Then on your active 12400 member do at bash level:&lt;/P&gt;&lt;P&gt;cd $FWDIR/log&lt;/P&gt;&lt;P&gt;vpn debug on&lt;/P&gt;&lt;P&gt;vpn debug ikeon&lt;/P&gt;&lt;P&gt;try to connect through the vpn from a device in your encryption domain&lt;/P&gt;&lt;P&gt;vpn debug ikeoff&lt;/P&gt;&lt;P&gt;vpn debug off&lt;/P&gt;&lt;P&gt;Now get the file $FWDIR/log/ike.elg to your PC&lt;/P&gt;&lt;P&gt;Open it using the IKEVIEW utility&lt;/P&gt;&lt;P&gt;Look for the entries for your VPN Gateway&lt;/P&gt;&lt;P&gt;I'm pretty sure you'll see the cause for your problems&lt;/P&gt;&lt;P&gt;Common causes for missing SAs are:&lt;/P&gt;&lt;P&gt;wrong (internal) IP used in general tab of gateway object&lt;/P&gt;&lt;P&gt;Rulebase not allowing IPsec communication between gateways&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 06:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Checkpoint-gateways-1-SMS-site-to-site-VPN-ike-failure/m-p/60442#M12077</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-08-16T06:13:18Z</dc:date>
    </item>
  </channel>
</rss>

