<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No data on receiving end in site-to-site  VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-data-on-receiving-end-in-site-to-site-VPN/m-p/160622#M6072</link>
    <description>&lt;P&gt;Few questions...&lt;/P&gt;
&lt;P&gt;How did you configure other side of the tunnel (the 4800) object? As interoperable or externally managed CP object?&lt;/P&gt;
&lt;P&gt;Does phase 1 show as up or no via vpn tu or sv monitor?&lt;/P&gt;
&lt;P&gt;Any change if you reset VPn tunnel?&lt;/P&gt;
&lt;P&gt;Do you see anything if running tcpdump -nni any host 1.2.3.4 (or whatever other side external IP is) and proto 50&lt;/P&gt;
&lt;P&gt;so say other side is 20.30.40.50, run tcpdump -nni any host 20.30.40.50 and proto 50&lt;/P&gt;
&lt;P&gt;Have you tried running simple vpn debug and reviewing vpnd.elg and ike.elg files&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;try generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;get ike.elg and vpnd.elg files from $fWDIR/log&lt;/P&gt;
&lt;P&gt;Ping me privately, happy to do remote and help you.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 19:19:09 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-10-27T19:19:09Z</dc:date>
    <item>
      <title>No data on receiving end in site-to-site  VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-data-on-receiving-end-in-site-to-site-VPN/m-p/160601#M6071</link>
      <description>&lt;P&gt;I’m migrating the firewall in one of my networks from an ASA to a Checkpoint 6400 running R81.10 (HFA 78 is installed) and used SmartMove to migrate the config.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Internally, everything works great, but I’m running into an issue with the VPN connection to one of my other sites.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have a star community configured and the other site is a 4800 running R77.30 that I do not control. I’m seeing an SA establish and then a number of child SAs form, but the other site does not see any traffic coming out of the tunnel. I also do not see any data traffic coming from them.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I see the expected traffic in the logs showing up as action:encrypt, so I feel pretty certain that I’m sending the right traffic into the tunnel. In monitoring outbound traffic at my border router, I only see UDP 500 traffic headed to the other gateway’s address, so that also looks to my like traffic is correctly entering the tunnel.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The only change the other site made was changing the gateway object to a Checkpoint device. I’m out of ideas here for possible problems or troubleshooting tools. Any thoughts on what else could cause this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 16:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-data-on-receiving-end-in-site-to-site-VPN/m-p/160601#M6071</guid>
      <dc:creator>JohnW1</dc:creator>
      <dc:date>2022-10-27T16:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: No data on receiving end in site-to-site  VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-data-on-receiving-end-in-site-to-site-VPN/m-p/160622#M6072</link>
      <description>&lt;P&gt;Few questions...&lt;/P&gt;
&lt;P&gt;How did you configure other side of the tunnel (the 4800) object? As interoperable or externally managed CP object?&lt;/P&gt;
&lt;P&gt;Does phase 1 show as up or no via vpn tu or sv monitor?&lt;/P&gt;
&lt;P&gt;Any change if you reset VPn tunnel?&lt;/P&gt;
&lt;P&gt;Do you see anything if running tcpdump -nni any host 1.2.3.4 (or whatever other side external IP is) and proto 50&lt;/P&gt;
&lt;P&gt;so say other side is 20.30.40.50, run tcpdump -nni any host 20.30.40.50 and proto 50&lt;/P&gt;
&lt;P&gt;Have you tried running simple vpn debug and reviewing vpnd.elg and ike.elg files&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;try generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;get ike.elg and vpnd.elg files from $fWDIR/log&lt;/P&gt;
&lt;P&gt;Ping me privately, happy to do remote and help you.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 19:19:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-data-on-receiving-end-in-site-to-site-VPN/m-p/160622#M6072</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-27T19:19:09Z</dc:date>
    </item>
  </channel>
</rss>

