<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phase -2 not working in the Ipsec tunnel in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23777#M13611</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you exclude IPSEC group under vpn community?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 May 2018 19:38:45 GMT</pubDate>
    <dc:creator>Kim_Moberg</dc:creator>
    <dc:date>2018-05-15T19:38:45Z</dc:date>
    <item>
      <title>Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23772#M13606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have multiple sub nets in the local encryption domain(checkpoint firewall ) . and only one subnet for the remote peer encryption domain. Remote peer is a non checkpoint device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we have initiated the ping from central gateway to remote gateway , I see that Phase 1 is up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase2 not. Ike .elg file shows that&amp;nbsp; P1 - main mode - all 6 packets good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P2- quick mode , the first packet itself ( QM packet 1) itself failed. is the QM packet I see that IP address of central gateway and remote peer.&lt;/P&gt;&lt;P&gt;when I initiate a ping from the device behind the firewall , though the IP is listed in the subnet , it is not encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what could be wrong in configuration?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 16:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23772#M13606</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-05-14T16:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23773#M13607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would start by looking at the logs in SmartLog/SmartConsole and seeing if there are any errors noted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 17:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23773#M13607</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-14T17:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23774#M13608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no errors. should I see the central gateway IP and peer gateway IP of P2- message 1 or the IPs of both side encryption domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 19:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23774#M13608</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-05-14T19:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23775#M13609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on the log message in question.&lt;/P&gt;&lt;P&gt;You should certainly see the VPN establish itself in the logs between the two gateways.&lt;/P&gt;&lt;P&gt;If you're not seeing errors in SmartLog, then the traffic is probably being accepted by a rule that doesn't involve encryption.&lt;/P&gt;&lt;P&gt;Do you see what log the traffic from the original (unencrypted) traffic is accepted on?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 20:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23775#M13609</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-14T20:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23776#M13610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that it is accepted by an explicit rule. only the thing is it is not encrypted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 14:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23776#M13610</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-05-15T14:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23777#M13611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you exclude IPSEC group under vpn community?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 19:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23777#M13611</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-05-15T19:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23778#M13612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes. that was one of the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 19:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23778#M13612</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-05-30T19:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Phase -2 not working in the Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23779#M13613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whenever you setup vpn tunnels and you test with icmp make sure to change the global properties for icmp traffic to be accepted before last, because any traffic matches implied rules will never get encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For phase 2 negotiation issue, your best friend is sk108600 scenario 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPsec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66289_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 21:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Phase-2-not-working-in-the-Ipsec-tunnel/m-p/23779#M13613</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-06-08T21:14:14Z</dc:date>
    </item>
  </channel>
</rss>

