<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223751#M4101</link>
    <description>&lt;P&gt;Ironically enough, I currently have a case with AWESOME TAC guy from Dallas that I worked with many times and he actually asked me to send cpinfos from gw and mgmt, so can try replicate in their lab. I find it a bit strange what happens is that now first connection works, but then if you disconnect and try reconnect, it NEVER works.&lt;/P&gt;
&lt;P&gt;For what its worth&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8677"&gt;@Joe_Torrentes_A&lt;/a&gt;&amp;nbsp;, we made changes from sk32229 and it did help, but still same behavior.&lt;/P&gt;
&lt;P&gt;Once I have more details and do more testing, will update. All I can tell you at this time is that site resolves to right IP, IDP shows connected, first time connection works, but when you do route print on the client, correct subnet is NOT listed there, so thats also another issue. We both found that part odd, since we all know when it comes to RA vpn, whatever you put in RA vpn domain, clients should see that when you run route print, but that part is failing.&lt;/P&gt;
&lt;P&gt;Anywho, since we all share solution once we have it (in the spirit) of the community, I will certainly do so as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This was document we followed btw:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial" target="_blank"&gt;Tutorial: Microsoft Entra single sign-on (SSO) integration with Check Point Remote Secure Access VPN - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Also went through this too, but did not help.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk44075" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk44075&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Last, but not least, this sk was not really relevant, since client is on R81.20 jumbo 65&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk172909" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk172909&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 12:44:34 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-15T12:44:34Z</dc:date>
    <item>
      <title>Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/204576#M4098</link>
      <description>&lt;P&gt;Hello all!&lt;/P&gt;&lt;P&gt;my first post I've ever made here, with an error that's driving me crazy!&lt;/P&gt;&lt;P&gt;Endpoint Security Client: E87.60 Build 986105018&lt;BR /&gt;Checkpoint 6200P Cluster: R81.10 take 335&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I've been trying to secure our VPN connection with MFA for a year with Endpoint Security Client and Entra ID .&amp;nbsp;However, I cannot switch authentication for all users, because there is an onnoying problem with the new identity provider (Microsoft Entra ID).&lt;/P&gt;&lt;P&gt;I already had tickets open regarding that topic, that had been passed on to the escalation engineer. Unfortunately, no solution was provided after gathering a lot of logs over months. The engineer was very rude and kept asking for new logs without providing a solution.&lt;/P&gt;&lt;P&gt;I would like to hear your opinion and at the same time ask if you know the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Explanation:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;- Microsoft Entra ID is used as an identity provider.&amp;nbsp;&lt;BR /&gt;See link:&amp;nbsp;&lt;A href="https://learn.microsoft.com/de-de/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial" target="_blank"&gt;https://learn.microsoft.com/de-de/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial&lt;/A&gt;&lt;BR /&gt;- Multifactor authentication is required when establishing a connection. -&amp;gt; Everything fine.&lt;/P&gt;&lt;P&gt;&lt;U&gt;But after a few hours the VPN connection no longer works&lt;/U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Helpdesk.log&lt;/STRONG&gt;&amp;nbsp;from Endpoint Security Client (Advanced Logging)&lt;/P&gt;&lt;P&gt;[21 Feb 17:04:03] No reply from the gw ip=X.X.X.X for tunnel test packet. Office Mode IP=A.A.A.A, source port=18009.&lt;BR /&gt;[21 Feb 17:04:05] No reply from the gw ip=X.X.X.X for tunnel test packet. Office Mode IP=A.A.A.A, source port=18010.&lt;BR /&gt;[21 Feb 17:04:08] IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.&lt;BR /&gt;[21 Feb 17:04:08] Client state is connected&lt;BR /&gt;[21 Feb 17:04:08] Tunnel (2) disconnected. State is connected. Trying to reconnect.&lt;BR /&gt;[21 Feb 17:04:18] IKE connection failed, error code=-1000. Reason: Site is not responding.&lt;BR /&gt;[21 Feb 17:04:18] Client state is reconnecting&lt;BR /&gt;[21 Feb 17:04:18] Reconnect failed. trying again (2)&lt;/P&gt;&lt;P&gt;......&lt;BR /&gt;[21 Feb 17:06:17] Client state is reconnecting&lt;BR /&gt;[21 Feb 17:06:17] State reconnecting. Roaming timeout is reached, cancelling connection (2)&lt;/P&gt;&lt;P&gt;Site is not responding --&amp;gt;&amp;nbsp;There is no vpn error with user/password authentication at the same time for hundreds of users.&lt;/P&gt;&lt;P&gt;It looks like there is an error with vpn phase 1 or 2, by using Entra ID.&lt;/P&gt;&lt;P&gt;The problem can be solved for a few hours by reestablishing the VPN connection.&lt;/P&gt;&lt;P&gt;The time, in which the connection works fine without problems can be influenced by changing the DHCP lease time.&lt;/P&gt;&lt;P&gt;- If the DHCP Lease Time is 60 minutes, the problem occurs several times a day. (4-5 times in 8 hours with vpn connection)&lt;BR /&gt;-&amp;nbsp;If the DHCP Lease Time is 960 minutes, the error only occurs once every 2-3 days.&lt;/P&gt;&lt;P&gt;Automatic DHCP lease: the DHCP Lease time is configured to the same value on our DHCP Server. -&amp;gt; Same error&lt;/P&gt;&lt;P&gt;Manual (using IP pool): Using CP as DHCP Server--&amp;gt; Same error with manual IP Pool.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Global properties -&amp;gt; Remote Access --&amp;gt; Endpoint Connect&lt;/P&gt;&lt;P&gt;Re-authenticate user every is set to 720 minutes according Checkpoint recommendation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Does anyone have the same problem or any advice?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 15:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/204576#M4098</guid>
      <dc:creator>Homer</dc:creator>
      <dc:date>2024-01-30T15:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223698#M4099</link>
      <description>&lt;P&gt;HI Homer&lt;/P&gt;&lt;P&gt;Did you ever got a root cause and solution for this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 23:47:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223698#M4099</guid>
      <dc:creator>Joe_Torrentes_A</dc:creator>
      <dc:date>2024-08-14T23:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223735#M4100</link>
      <description>&lt;P&gt;Hello Joe!&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Unfortunately, since July of this year, the problem has resolved itself without any verifiable changes being made.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;So I cannot provide a solution and at the same time I still have the bad feeling of putting the authentication method into production.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Together with Checkpoint R&amp;amp;D, we have made many changes and collected hundreds of logs without finding the error.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Have you got the same issue?&lt;/P&gt;&lt;P&gt;Which configuration settings have you already checked?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Greetings&lt;BR /&gt;Julian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 10:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223735#M4100</guid>
      <dc:creator>Homer</dc:creator>
      <dc:date>2024-08-15T10:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223751#M4101</link>
      <description>&lt;P&gt;Ironically enough, I currently have a case with AWESOME TAC guy from Dallas that I worked with many times and he actually asked me to send cpinfos from gw and mgmt, so can try replicate in their lab. I find it a bit strange what happens is that now first connection works, but then if you disconnect and try reconnect, it NEVER works.&lt;/P&gt;
&lt;P&gt;For what its worth&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8677"&gt;@Joe_Torrentes_A&lt;/a&gt;&amp;nbsp;, we made changes from sk32229 and it did help, but still same behavior.&lt;/P&gt;
&lt;P&gt;Once I have more details and do more testing, will update. All I can tell you at this time is that site resolves to right IP, IDP shows connected, first time connection works, but when you do route print on the client, correct subnet is NOT listed there, so thats also another issue. We both found that part odd, since we all know when it comes to RA vpn, whatever you put in RA vpn domain, clients should see that when you run route print, but that part is failing.&lt;/P&gt;
&lt;P&gt;Anywho, since we all share solution once we have it (in the spirit) of the community, I will certainly do so as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This was document we followed btw:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial" target="_blank"&gt;Tutorial: Microsoft Entra single sign-on (SSO) integration with Check Point Remote Secure Access VPN - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Also went through this too, but did not help.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk44075" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk44075&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Last, but not least, this sk was not really relevant, since client is on R81.20 jumbo 65&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk172909" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk172909&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 12:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223751#M4101</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-15T12:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security - Entra ID Auth - No reply from the gw / Site is not responding</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223834#M4102</link>
      <description>&lt;P&gt;Hey Andy,&lt;/P&gt;&lt;P&gt;it looks like you have als an annoying issue...&lt;/P&gt;&lt;P&gt;Thank you for your advice! Entra SSO Integration Tutorial is well known to me, I have checked the settings several times...&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I noticed is that the configuration instructions have changed frequently in the last few months and each update results in different configuration settings on CP GW and Entra ID&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Using-Azure-AD-for-Authorization.htm" target="_blank"&gt;Using Azure AD for Authorization (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does the client's helpdesk.log from trlogsXXX.cab say?&lt;BR /&gt;Is all traffic forwarded to CP GW or only RA VPN Domain?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 08:36:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-Entra-ID-Auth-No-reply-from-the-gw-Site-is-not/m-p/223834#M4102</guid>
      <dc:creator>Homer</dc:creator>
      <dc:date>2024-08-16T08:36:31Z</dc:date>
    </item>
  </channel>
</rss>

