<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN between Checkpoint and Cisco ASA in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20322#M12792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would helpful if you pasted the exact output from tcpdump that you're seeing.&lt;/P&gt;&lt;P&gt;The only thing you should be seeing there is IKE and IPsec traffic from the peer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Jan 2019 18:25:30 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-01-02T18:25:30Z</dc:date>
    <item>
      <title>IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20317#M12787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;im having really tought time establishing inbound connectivity from a third party Cisco ASA to my perimeter Checkpoint firewall. I am using R.76 and not R.80&lt;/P&gt;&lt;P&gt;I have an existing VPN created that permits outbound access from my internal servers to a 3rd party server.&lt;/P&gt;&lt;P&gt;The source of the Outbound traffic (FROM internal server to 3rd Party server) is hidden behind a single static NAT IP address. This access works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issue is&amp;nbsp;establishing traffic&amp;nbsp;Inbound (FROM 3rd party server to local internal server).&lt;/P&gt;&lt;P&gt;Traffic from the 3rd party is destined for a hide address that i translate to the real IP address of my internal server.&lt;/P&gt;&lt;P&gt;I can see the VPN attempt to establish and then get an&amp;nbsp;error : "encryption Fail Reason: Received a cleartext packet within an encrypted connection".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done the usual troubleshooting and this error usually means that the encryption domains on either side do not match, however from what i can see they do.&lt;/P&gt;&lt;P&gt;Under the topology section of the gateway i have the VPN domains manually defined and include all the subnets that will be permitted to go through the VPN from my side, including the NAT addresses.&lt;/P&gt;&lt;P&gt;And under the VPN settings for the destination i have the subnet of the destination 3rd party servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something i am missing, below are the things i've tried:-&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;checked encryption domains on both sides, they appear to match&lt;/LI&gt;&lt;LI&gt;checked VPN tunnel sharing to "one vpn tunnel per subnet pair"&lt;/LI&gt;&lt;LI&gt;checked VPN type to meshed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After each time i went on to the CLI of the gateway and cleared both IPSec and IKEs for the IPSec gateway and no change: outbound from us to them works, but they cannot initiate an inbound&amp;nbsp;connection to a server i have control of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help is greatly&amp;nbsp;appreciated, and i can provide additional detail if required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2019 17:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20317#M12787</guid>
      <dc:creator>taib_charkaoui</dc:creator>
      <dc:date>2019-01-01T17:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20318#M12788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would use a tcpdump or fw monitor to validate whether you are, in fact, receiving packets from the remote site in plaintext.&lt;/P&gt;&lt;P&gt;If you are, the misconfiguration is on the other side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&amp;amp;partition=Advanced&amp;amp;product=IPSec" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;Debugging Site-to-Site VPN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While I'm not aware of any specific issues in R76 related to this, keep in mind R76 (unless it's R76SP) is no longer supported.&lt;/P&gt;&lt;P&gt;You should look at upgrading to a supported version.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2019 18:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20318#M12788</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-01T18:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20319#M12789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;if i do a TCP dump i can check that there is traffic coming from the source subnet (the 3rd party).&lt;/P&gt;&lt;P&gt;But there shouldnt be anything particularly complicated in configuring an IPSec VPN to allow Inbound as opposed to outbound only traffic right?&lt;/P&gt;&lt;P&gt;The issue is if i am going to go back to the 3rd party to tell them their config needs amending i need, to be sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2019 18:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20319#M12789</guid>
      <dc:creator>taib_charkaoui</dc:creator>
      <dc:date>2019-01-01T18:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20320#M12790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you see anything in the tcpdump that looks like it comes from hosts behind the VPN Endpoint (e.g. SSH as shown in your log entry) that means the remote end is not encrypting the traffic.&lt;/P&gt;&lt;P&gt;That can only be fixed on the remote end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2019 01:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20320#M12790</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-02T01:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20321#M12791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon - so i did the TCPDump and could see traffic coming in from the 3rd party peer, as per the existing encryption domain on my side, so that is what is confusing me:-&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;traffic is coming from 10.199.3.96/28 as per the encryption domain configured on under the VPN gateway on my checkpoint firewall.&lt;/LI&gt;&lt;LI&gt;the local VPN encryption domain includes both the NAT hide address the 3rd party is trying to get to and the real address of the server that the NAT hide address is being translated to.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below is the detail shown in the packet when the vpn is setting up.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="VPN Encryption packet detail" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/76660_VPN Capture.JPG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And finally i've attached&amp;nbsp;a picture of the order of packets taken from smartview tracker, with the packets marked with a padlock showing the setup of the VPN, and then the drop notification, and the repeat of this after each attempt&lt;/P&gt;&lt;P&gt;&lt;IMG alt="smartview tracker output" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/76658_smartview tracker output.JPG" /&gt;&lt;/P&gt;&lt;P&gt;so it looks like the encryption domains are correct,&amp;nbsp;&lt;/P&gt;&lt;P&gt;appreciate the assistance Dameon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2019 17:32:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20321#M12791</guid>
      <dc:creator>taib_charkaoui</dc:creator>
      <dc:date>2019-01-02T17:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20322#M12792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would helpful if you pasted the exact output from tcpdump that you're seeing.&lt;/P&gt;&lt;P&gt;The only thing you should be seeing there is IKE and IPsec traffic from the peer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2019 18:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20322#M12792</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-02T18:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20323#M12793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So below is the TCPdump capture, i see when i ask the 3rd party to initiate traffic.&lt;/P&gt;&lt;P&gt;The 10.199.3.97 address is the source address that the 3rd party is coming from (FYI this is also a nat'd address as we cannot see their real ip addresses)&lt;/P&gt;&lt;P&gt;The 10.199.2.11 address is the NAT address on my side that i have hidden the real ip address of my server behind.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="TCPDump Capture" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/76674_TCP Dump Capture_LI.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 11:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20323#M12793</guid>
      <dc:creator>taib_charkaoui</dc:creator>
      <dc:date>2019-01-03T11:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20324#M12794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is unencrypted traffic, as the error messages were suggesting.&lt;/P&gt;&lt;P&gt;(Well, ok, SSH is technically encrypted but it's not IPsec)&lt;/P&gt;&lt;P&gt;This means the problem is on the remote end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 14:15:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20324#M12794</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-03T14:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between Checkpoint and Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20325#M12795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon, this is what i thought.&lt;/P&gt;&lt;P&gt;Potentially their end had different encryption domains and i was trying to match them by changing config on my side, but if they are not encrypting the traffic in the first place then there shouldnt be anything i can do.&lt;/P&gt;&lt;P&gt;I will get back to them and press for them to re-look at things. in the meantime i will mark your last answer as correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for your assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 15:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-between-Checkpoint-and-Cisco-ASA/m-p/20325#M12795</guid>
      <dc:creator>taib_charkaoui</dc:creator>
      <dc:date>2019-01-03T15:09:33Z</dc:date>
    </item>
  </channel>
</rss>

