<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tunnel_test drops and iked disable when connecting to Endpoint Security in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Tunnel-test-drops-and-iked-disable-when-connecting-to-Endpoint/m-p/239051#M2502</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;We encountered a problem when connecting Endpoint clients via Remote Access.&lt;/P&gt;&lt;P&gt;Successfully connected clients disconnect after some time and in SmartConsole we see tunnel_test drop logs. The problem occurs only with some VPN clients when working with files. After the drop, a reconnection occurs, which lasts for several minutes, several attempts of automatic reconnection may be required to successfully connect again.&lt;/P&gt;&lt;P&gt;The environment in which the problem occurs is VSX and R81.10. Nat-t is enabled.&lt;/P&gt;&lt;P&gt;We tried to debug VPN-related processes and found that iked debug did not start with the message: 'iked' is currently disabled.&lt;BR /&gt;The vpn iked status command also shows the result:&lt;BR /&gt;vpn: 'iked' is disabled.&lt;BR /&gt;vpn: The 'iked' process is currently not running.&lt;/P&gt;&lt;P&gt;The documentation related to iked debugging says that iked can be disabled when using legacy mode. But we did not disable iked manually. The upgrade to R81.10 was over a year ago, but tunnel_test issues appeared later.&lt;/P&gt;&lt;P&gt;Does anyone know a solution to this problem? Can we simply enable iked with vpn iked enable?&lt;/P&gt;&lt;P&gt;The documentation says that this modifies the $FWDIR/boot/modules/fwkern.conf file and may break the SSH session. Will enabling iked in this way have a negative impact on the system and current VPN connections?&lt;/P&gt;&lt;P&gt;I would appreciate any help!&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 11:28:46 GMT</pubDate>
    <dc:creator>Dayaana</dc:creator>
    <dc:date>2025-01-20T11:28:46Z</dc:date>
    <item>
      <title>Tunnel_test drops and iked disable when connecting to Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Tunnel-test-drops-and-iked-disable-when-connecting-to-Endpoint/m-p/239051#M2502</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;We encountered a problem when connecting Endpoint clients via Remote Access.&lt;/P&gt;&lt;P&gt;Successfully connected clients disconnect after some time and in SmartConsole we see tunnel_test drop logs. The problem occurs only with some VPN clients when working with files. After the drop, a reconnection occurs, which lasts for several minutes, several attempts of automatic reconnection may be required to successfully connect again.&lt;/P&gt;&lt;P&gt;The environment in which the problem occurs is VSX and R81.10. Nat-t is enabled.&lt;/P&gt;&lt;P&gt;We tried to debug VPN-related processes and found that iked debug did not start with the message: 'iked' is currently disabled.&lt;BR /&gt;The vpn iked status command also shows the result:&lt;BR /&gt;vpn: 'iked' is disabled.&lt;BR /&gt;vpn: The 'iked' process is currently not running.&lt;/P&gt;&lt;P&gt;The documentation related to iked debugging says that iked can be disabled when using legacy mode. But we did not disable iked manually. The upgrade to R81.10 was over a year ago, but tunnel_test issues appeared later.&lt;/P&gt;&lt;P&gt;Does anyone know a solution to this problem? Can we simply enable iked with vpn iked enable?&lt;/P&gt;&lt;P&gt;The documentation says that this modifies the $FWDIR/boot/modules/fwkern.conf file and may break the SSH session. Will enabling iked in this way have a negative impact on the system and current VPN connections?&lt;/P&gt;&lt;P&gt;I would appreciate any help!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 11:28:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Tunnel-test-drops-and-iked-disable-when-connecting-to-Endpoint/m-p/239051#M2502</guid>
      <dc:creator>Dayaana</dc:creator>
      <dc:date>2025-01-20T11:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel_test drops and iked disable when connecting to Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Tunnel-test-drops-and-iked-disable-when-connecting-to-Endpoint/m-p/239096#M2503</link>
      <description>&lt;P&gt;It looks like you can enable it with vpn iked enable.&lt;BR /&gt;The reason your SSH connection may get disconnected is because of the policy installation required to (de)activate iked, which can sometimes terminate existing connections (depends on settings).&lt;/P&gt;
&lt;P&gt;In general, iked should improve VPN performance for certain operations as iked is multicore.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 22:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Tunnel-test-drops-and-iked-disable-when-connecting-to-Endpoint/m-p/239096#M2503</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-20T22:33:17Z</dc:date>
    </item>
  </channel>
</rss>

