<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to view &amp;quot;phase 2&amp;quot; SPI details in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17226#M12843</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested the main command of the suggested post on R77.30 and R80.10 and both work as expected (expert mode); however, you can give a try to &lt;A href="https://community.checkpoint.com/migrated-users/64438"&gt;Alexey Bilay&lt;/A&gt;‌'s modification:&lt;/P&gt;&lt;PRE class=""&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;CODE&gt;fw tab &lt;SPAN class=""&gt;-&lt;/SPAN&gt;t vpn_routing &lt;SPAN class=""&gt;-&lt;/SPAN&gt;u &lt;SPAN class=""&gt;|&lt;/SPAN&gt; awk &lt;SPAN class=""&gt;'NR&amp;gt;3 {$0=substr($0,2,28); gsub(", ", ""); gsub("; ", ""); gsub("..", "0x&amp;amp; "); print}'&lt;/SPAN&gt; &lt;SPAN class=""&gt;|&lt;/SPAN&gt; xargs printf &lt;SPAN class=""&gt;"%d.%d.%d.%d\t-\t%d.%d.%d.%d\tPeer: %d.%d.%d.%d\r\n"&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/BLOCKQUOTE&gt;&lt;/PRE&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Dec 2018 15:07:19 GMT</pubDate>
    <dc:creator>KennyManrique</dc:creator>
    <dc:date>2018-12-18T15:07:19Z</dc:date>
    <item>
      <title>How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17223#M12840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to find out the local and remote identities associated with a specific phase 2 SPI for an IPsec encrypted VPN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output from '&lt;EM&gt;vpn tu&lt;/EM&gt;' is rather limited:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;4&lt;/P&gt;&lt;P&gt;Enter IP of peer (format: xxx.xxx.xxx.xxx): 192.0.2.1&lt;/P&gt;&lt;P&gt;Peer &lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;92.0.2.1&lt;/SPAN&gt;&amp;nbsp;SAs:&lt;/P&gt;&lt;P&gt;1. SPI's related to IKE SA &amp;lt;7dc3f321cf09371c,bc0373ef85ca407e&amp;gt;:&lt;BR /&gt; INBOUND:&lt;BR /&gt; 1. 0xe75e94b5&lt;BR /&gt; OUTBOUND:&lt;BR /&gt; 1. 0x2d692cda&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 11:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17223#M12840</guid>
      <dc:creator>Phil_Leinster</dc:creator>
      <dc:date>2018-12-18T11:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17224#M12841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can verify the following: &lt;A href="https://community.checkpoint.com/docs/DOC-3021-show-vpn-routing-on-cli" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-3021-show-vpn-routing-on-cli&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:07:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17224#M12841</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2019-06-21T09:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17225#M12842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kenny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That looks like it should be helpful, but the command on this page doesn't print anything on my firewall instance. However I can go through the "&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;&lt;EM&gt;fw tab -f -t vpn_routing -u&lt;/EM&gt;&lt;/SPAN&gt;" table manually to find my answer, so thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would need to go through this command in&amp;nbsp;detail to find out what the problem is, but at first look the first grep statement is removing all the lines in my output as they all include the '+' sign. There's a deeper problem than that, though...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 14:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17225#M12842</guid>
      <dc:creator>Phil_Leinster</dc:creator>
      <dc:date>2018-12-18T14:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17226#M12843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested the main command of the suggested post on R77.30 and R80.10 and both work as expected (expert mode); however, you can give a try to &lt;A href="https://community.checkpoint.com/migrated-users/64438"&gt;Alexey Bilay&lt;/A&gt;‌'s modification:&lt;/P&gt;&lt;PRE class=""&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;CODE&gt;fw tab &lt;SPAN class=""&gt;-&lt;/SPAN&gt;t vpn_routing &lt;SPAN class=""&gt;-&lt;/SPAN&gt;u &lt;SPAN class=""&gt;|&lt;/SPAN&gt; awk &lt;SPAN class=""&gt;'NR&amp;gt;3 {$0=substr($0,2,28); gsub(", ", ""); gsub("; ", ""); gsub("..", "0x&amp;amp; "); print}'&lt;/SPAN&gt; &lt;SPAN class=""&gt;|&lt;/SPAN&gt; xargs printf &lt;SPAN class=""&gt;"%d.%d.%d.%d\t-\t%d.%d.%d.%d\tPeer: %d.%d.%d.%d\r\n"&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/BLOCKQUOTE&gt;&lt;/PRE&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 15:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17226#M12843</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-12-18T15:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17227#M12844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running R77.10 on the firewall I was testing against, which I know is out of support. Neither the original command nor my modified command worked on R77.30. I had to use separate versions for each as the output format has changed across versions. The original command may not work in future releases as the format output of the vpn_routing table does not seem to be stable:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R77.10&lt;BR /&gt;&lt;STRONG&gt;echo -e "\033[0m####################\n# VPN Routing #\n####################";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |awk '{split($0,a,";"); print a[6]}' |sort -ng |uniq | awk '{split($0,a," "); print a[2]}' | xargs -I % sh -c 'echo -n "External Gateway: ";echo -e "\033[0;31m % \\033[37m";echo -e " Routing: \033[32m";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep % |awk '\''{split($0,b,";"); print b[2] b[3]}'\''| sed 's/,//'| sed 's/From\://'| sed 's/To\:/-/'|sort -u ;echo -e "\033[0m" '&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;R77.30&lt;BR /&gt;&lt;STRONG&gt;echo -e "\033[0m####################\n# VPN Routing #\n####################";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |awk '{split($0,a,";"); print a[6]}' |sort -ng |uniq | awk '{split($0,a,":"); print a[2]}' | xargs -I % sh -c 'echo -n "External Gateway: ";echo -e "\033[0;31m % \\033[37m";echo -e " Routing: \033[32m";fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep % |awk '\''{split($0,b,";"); print b[2] b[3]}'\''| sed 's/,//'| sed 's/From\://'| sed 's/To\:/-/'|sort -u ;echo -e "\033[0m" '&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 15:49:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17227#M12844</guid>
      <dc:creator>Phil_Leinster</dc:creator>
      <dc:date>2018-12-18T15:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to view "phase 2" SPI details</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17228#M12845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For anyone interested I created this script based on the original so I can easily check idents for single VPN peers (tested 0n R7710 &amp;amp; R77.30; mileage may vary on different versions):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;#!/bin/bash&lt;BR /&gt;echo -e "\033[0m####################\n# VPN Routing #\n####################"&lt;BR /&gt;if [ $# -eq 0 ]&lt;BR /&gt; then&lt;BR /&gt; read -p 'Gateway: ' ipaddr&lt;BR /&gt;else&lt;BR /&gt; ipaddr=$1&lt;BR /&gt;fi&lt;BR /&gt;echo -n "For Single Gateway: "&lt;BR /&gt;echo -e "\033[0;31m $ipaddr \\033[37m"&lt;BR /&gt;echo -e " Routing: \033[32m"&lt;BR /&gt;fw tab -f -t vpn_routing -u 2&amp;gt;&amp;amp;1 |grep $ipaddr |awk '{split($0,b,";"); print b[2] b[3]}' | sed 's/,//'| sed 's/From\://'| sed 's/To\:/-/'|sort -u ;echo -e "\033[0m"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 16:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-view-quot-phase-2-quot-SPI-details/m-p/17228#M12845</guid>
      <dc:creator>Phil_Leinster</dc:creator>
      <dc:date>2018-12-18T16:17:10Z</dc:date>
    </item>
  </channel>
</rss>

