<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic site to site vpn in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/site-to-site-vpn/m-p/179425#M5102</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We're trying to implement a site-to-site VPN, and i get the error&amp;nbsp; "&lt;/SPAN&gt;&lt;SPAN&gt;Encryption Failure: according to the policy the packet should not have been decrypted&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We tried the url:&lt;/P&gt;&lt;P&gt;URL 1 : &lt;A href="https://support.checkpoint.com/results/sk/sk64060" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64060&lt;/A&gt;&lt;/P&gt;&lt;P&gt;URL 2 : &lt;A href="https://support.checkpoint.com/results/sk/sk97612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk97612&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We tried the solution of url 1 and 2 it doesn't work despite having vpn enabled on both sides.&lt;/P&gt;&lt;P&gt;We have tried using and inbound NAT, but error message persists.&lt;/P&gt;&lt;P&gt;Client A has shophs gateway and client B has checkpoint r80.40 gateway.&lt;/P&gt;&lt;P&gt;Have you encountered this problem before? And how did you solve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 14:11:10 GMT</pubDate>
    <dc:creator>Oussa</dc:creator>
    <dc:date>2023-04-28T14:11:10Z</dc:date>
    <item>
      <title>site to site vpn</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/site-to-site-vpn/m-p/179425#M5102</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We're trying to implement a site-to-site VPN, and i get the error&amp;nbsp; "&lt;/SPAN&gt;&lt;SPAN&gt;Encryption Failure: according to the policy the packet should not have been decrypted&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We tried the url:&lt;/P&gt;&lt;P&gt;URL 1 : &lt;A href="https://support.checkpoint.com/results/sk/sk64060" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64060&lt;/A&gt;&lt;/P&gt;&lt;P&gt;URL 2 : &lt;A href="https://support.checkpoint.com/results/sk/sk97612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk97612&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We tried the solution of url 1 and 2 it doesn't work despite having vpn enabled on both sides.&lt;/P&gt;&lt;P&gt;We have tried using and inbound NAT, but error message persists.&lt;/P&gt;&lt;P&gt;Client A has shophs gateway and client B has checkpoint r80.40 gateway.&lt;/P&gt;&lt;P&gt;Have you encountered this problem before? And how did you solve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 14:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/site-to-site-vpn/m-p/179425#M5102</guid>
      <dc:creator>Oussa</dc:creator>
      <dc:date>2023-04-28T14:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: site to site vpn</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/site-to-site-vpn/m-p/179429#M5103</link>
      <description>&lt;P&gt;Check out below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Now, here is what I can tell you. Error you get, 99% of the time is related to phase 2, so something with enc. domains. Firewall is simply "telliong" you that packet SHOULD have been encrypted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I gave below to few people here in the community and it always helped. If you check these valus in guidbedit, should be set to false. It simplty implies that CP would stop presenting largest possible subnet, even though its not supposed to. Not saying it would solve your issue, but it always helps.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;ike_enable_supernet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;By the way, if you get confused, we can always do remote session.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Cheers,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 14:34:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/site-to-site-vpn/m-p/179429#M5103</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-28T14:34:16Z</dc:date>
    </item>
  </channel>
</rss>

