<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure route based VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57291#M12184</link>
    <description>What debugging have you done?&lt;BR /&gt;Usually, there's error messages that might give you a clue.&lt;BR /&gt;You may also need to do some detailed debug, start here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&lt;/A&gt;</description>
    <pubDate>Tue, 02 Jul 2019 23:44:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-07-02T23:44:49Z</dc:date>
    <item>
      <title>Azure route based VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57279#M12183</link>
      <description>&lt;P&gt;I'm new to Azure and trying to create a site to site VPN route based between it and my on prem cluster.&amp;nbsp; I've already referenced s&lt;SPAN&gt;k101275 for the encryption parameters so I have that part down.&amp;nbsp; Unfortunately this SK doesn't seem to cover all the pieces of the configuration required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm now working on the VTI interfaces on the firewall.&amp;nbsp; For each firewall I configured a new public external IP as local and specified the Azure VPN IP as the remote IP.&amp;nbsp; Additionally I configured a new public external IP for the cluster interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So the basic network config looks like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Firewall 1 - Local IP = New public IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remote IP = Azure public IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Peer = Azure&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Firewall 2 - Local IP = New Public IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remote IP = Azure public IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Peer = Azure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster IP = New Public IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then I created an interoperable device using the same name as the peer for the VTI and the IP is the Azure Public IP.&amp;nbsp; I've read where that has to match.&amp;nbsp; I also created a VPN Community and followed sk101275 for parameters.&amp;nbsp; Policy rules were created as well as an empty network object to represent the encryption domain.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So what I'm seeing is phase 1 come up and that's it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I opened a ticket and was initially told to check routing.&amp;nbsp; Since the VTI remote IP is pointing to the Azure public IP it's creating that a directly connected route via the VTI.&amp;nbsp; The thought was the traffic isn't going out to the internet properly to establish the tunnel.&amp;nbsp; I've read quite a few links on the site here but nothing has seemed to give me quite enough info on what I could be missing.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 18:30:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57279#M12183</guid>
      <dc:creator>Michael_Hightow</dc:creator>
      <dc:date>2019-07-02T18:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Azure route based VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57291#M12184</link>
      <description>What debugging have you done?&lt;BR /&gt;Usually, there's error messages that might give you a clue.&lt;BR /&gt;You may also need to do some detailed debug, start here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&lt;/A&gt;</description>
      <pubDate>Tue, 02 Jul 2019 23:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57291#M12184</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-02T23:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Azure route based VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57373#M12185</link>
      <description>&lt;P&gt;I have done some debugging and see two-way traffic with both tcpdump and fw monitor.&amp;nbsp; I definitely see phase 1 negotiated in the ikev2.xmll.&lt;/P&gt;&lt;P&gt;Support is pointing out a route on my firewall that points to the azure gateway via the vti interface.&amp;nbsp; Since that route is created by creating the vti interface itself I'm not sure how you get around that.&amp;nbsp; The support engineer was saying the traffic is returning over the vti interface and not taking the external interface path.&lt;/P&gt;&lt;P&gt;I don't think any static route setting would override this directly connected route.&amp;nbsp; As a matter of fact I created one just to do it and it showed up as "i" or inactive in the show route all command.&lt;/P&gt;&lt;P&gt;So still looking around.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 16:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Azure-route-based-VPN/m-p/57373#M12185</guid>
      <dc:creator>Michael_Hightow</dc:creator>
      <dc:date>2019-07-03T16:46:55Z</dc:date>
    </item>
  </channel>
</rss>

