<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection to external AD broken after changing external gw IP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174708#M5366</link>
    <description>&lt;P&gt;Hi _Val_,&lt;/P&gt;&lt;P&gt;unfurtunately no. I have a new site for the new VPN gateway IP, but that was not the problem.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2023 08:51:20 GMT</pubDate>
    <dc:creator>sreingardt</dc:creator>
    <dc:date>2023-03-14T08:51:20Z</dc:date>
    <item>
      <title>Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174508#M5358</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I have a problem with my Security Gateway since I changed the external IP last Friday and all network configuration (default gw, routes, etc) were done. I tried to login with my certificate in Check Point Mobile for Windows client and it got stuck at 47%. The error message reads&lt;/P&gt;&lt;P&gt;OCSP: could not connect to server. Make sure the server is up and running.Email=(my e-mail),CN=(my CN in certificate)&lt;/P&gt;&lt;P&gt;We use a two-step login for VPN, first we check an external certificate with password and then we request the AD password for the user in the certificate.&lt;/P&gt;&lt;P&gt;The information on this error message is very sparse, so I have not been able to continue my search for a solution.&lt;/P&gt;&lt;P&gt;Has anyone had that message in the past or know how to search further?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 07:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174508#M5358</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-13T07:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174516#M5359</link>
      <description>&lt;P&gt;I assume your GW has the object set up with the new IP address, and the policy pushed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like your VPN client is still trying to connect to the old GW IP address. Try setting up a new VPN site with the new IP address and see if you succeed&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 10:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174516#M5359</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-13T10:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174519#M5360</link>
      <description>&lt;P&gt;Hi _Val_,&lt;/P&gt;&lt;P&gt;yes we have changed the object und pushed the policy.&lt;/P&gt;&lt;P&gt;I have set up a new site after the configuration changes and the VPN client pulled the policy/profile from the site. If I forgot to change the client I would get &lt;EM&gt;Site not responding&lt;/EM&gt; or else.&lt;/P&gt;&lt;P&gt;Regards Sascha&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 10:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174519#M5360</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-13T10:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174539#M5361</link>
      <description>&lt;P&gt;Maybe &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178625&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_self"&gt;sk178625 "Unreached OCSP" "OCSP: could not connect to server" reject and detect logs for traffic that is supposed to work&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 11:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174539#M5361</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-13T11:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174544#M5362</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we are not using URL Filtering or HTTPS inspection on the gateway.&lt;/P&gt;&lt;P&gt;The VPN connection worked all fine before we changed the interface IP. It would probably work if we clean-install the gateway, but I hope that the solution could be easier than that.&lt;/P&gt;&lt;P&gt;Regards Sascha&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 12:02:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174544#M5362</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-13T12:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174632#M5363</link>
      <description>&lt;P&gt;The client needs to be able to reach the management server in order to validate the VPN certificate.&lt;BR /&gt;This is done via CRL and/or OCSP.&lt;BR /&gt;Please double check the NAT configuration for your management object, which may need to be different to account for the new external IP of the gateway.&lt;BR /&gt;It's also possible you need to delete and re-add the site on your VPN client.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 17:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174632#M5363</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-13T17:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174699#M5364</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;the VPN gateway connects directly to my external ldap server, so I use a NAT on the gateway. The rule is a very common static source NAT like &lt;EM&gt;VPN gateway object&lt;/EM&gt; to &lt;EM&gt;ldap server&lt;/EM&gt; port &lt;EM&gt;ldap&lt;/EM&gt; - translated source: &lt;EM&gt;other source IP for VPN gateway&lt;/EM&gt;.&lt;BR /&gt;But that NAT only affects the internal interface and not the external.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;It's also possible you need to delete and re-add the site on your VPN client.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What do you mean by that? If I change my NAT configuration do I have to delete the site or if I change the external IP?&lt;/P&gt;&lt;P&gt;Regards Sascha&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 07:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174699#M5364</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-14T07:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174702#M5365</link>
      <description>&lt;P&gt;So, if you define a new site, everything works?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 07:54:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174702#M5365</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-14T07:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174708#M5366</link>
      <description>&lt;P&gt;Hi _Val_,&lt;/P&gt;&lt;P&gt;unfurtunately no. I have a new site for the new VPN gateway IP, but that was not the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 08:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174708#M5366</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-14T08:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174734#M5367</link>
      <description>&lt;P&gt;I see. Please open a service ticket with TAC for this&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 11:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174734#M5367</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-14T11:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174736#M5368</link>
      <description>&lt;P&gt;Ok I will do that, thank you for your support.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 11:59:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174736#M5368</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-14T11:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174770#M5369</link>
      <description>&lt;P&gt;Unless your management server has a public IP address, NAT is required for your clients to access it.&lt;BR /&gt;What is the precise NAT configuration on the management server object?&lt;BR /&gt;If it is tied to the external IP of your gateway, you may need to delete and re-add the site.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 14:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/174770#M5369</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-14T14:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/175541#M5370</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;I finally found the solution and would like to share my experience.&lt;/P&gt;&lt;P&gt;With &lt;EM&gt;vpn debug on ocsp=5&lt;/EM&gt; I found connection entries to an external ocsp provider ocsp.globalsign.com in the &lt;EM&gt;vpnd.elg&lt;/EM&gt;&amp;nbsp; logfile and the gateway tried to connect to the destination via a proxy. This felt strange to me because I have a gateway that points to the internet but wanted to use an additional proxy. The proxy entry came from the &lt;EM&gt;Global Properties&lt;/EM&gt; and was inherited by the gateway by default. Unfurtunately, the gateway was not in the proxy whitelist.&lt;/P&gt;&lt;P&gt;By that OCSP was not reachable and the vpn connection stuck. I set an override for the proxy configuration in the properties of the gateway and everything worked fine after that.&lt;/P&gt;&lt;P&gt;Thank you for your support.&lt;/P&gt;&lt;P&gt;Regards Sascha&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 07:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/175541#M5370</guid>
      <dc:creator>sreingardt</dc:creator>
      <dc:date>2023-03-21T07:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to external AD broken after changing external gw IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/175657#M5371</link>
      <description>&lt;P&gt;Thanks for sharing the solution.&lt;BR /&gt;That would certainly cause an issue.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 02:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-to-external-AD-broken-after-changing-external-gw-IP/m-p/175657#M5371</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-22T02:40:15Z</dc:date>
    </item>
  </channel>
</rss>

