<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection failed: Negotation with site failed in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157552#M6304</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;The topology:&lt;/P&gt;&lt;P&gt;internet-----CP 1550 fw------R81.10 virtual fw&lt;/P&gt;&lt;P&gt;cp-1550 is the edge firewall,&amp;nbsp;R81.10 virtual fw is the internal vpn gw and is mapped with cp-1550 firewall&lt;/P&gt;&lt;P&gt;You said that this probably won't work,why?&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2022 16:34:23 GMT</pubDate>
    <dc:creator>Jeffgo</dc:creator>
    <dc:date>2022-09-19T16:34:23Z</dc:date>
    <item>
      <title>Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/156977#M6299</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;&lt;P&gt;My version: R81.10,hotfix is T66&lt;/P&gt;&lt;P&gt;I configure the gateway as a vpn gateway,and the vpnn gateway location internal network,i mapping it by internet firewall.GW VPN port is 10443 on the visitor mode.&lt;/P&gt;&lt;P&gt;I test it,i can successfull connect to vpn on internal network.but i can not connect to vpn on internet.the connected informations as fowwowing:&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11WX20220911-154952@2x.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17740i781E099DEF7AF16B/image-size/large?v=v2&amp;amp;px=999" role="button" title="11WX20220911-154952@2x.png" alt="11WX20220911-154952@2x.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Sep 2022 07:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/156977#M6299</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-11T07:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157116#M6300</link>
      <description>&lt;P&gt;There can be tons of reasons for that, you need to see the logs both from the FW and the client for more details.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 09:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157116#M6300</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-13T09:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157460#M6301</link>
      <description>&lt;P&gt;Internal pc connect to vpn working well,but i map the vpn gw to internet with PAT,client can not working,I think this is checkpoint issue,&lt;/P&gt;&lt;P&gt;if need to see the gw logs,how to see the gw logs,thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 14:51:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157460#M6301</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-17T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157461#M6302</link>
      <description>&lt;P&gt;Is some other device doing the NAT?&lt;BR /&gt;This probably won't work if so...&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 03:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157461#M6302</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-18T03:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157469#M6303</link>
      <description>&lt;P&gt;This is SecureRemote - Have you tried enabling vpn debug and collect logs from client side? That should show the reason. Plus what is the VPN link selection IP address specified?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 05:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157469#M6303</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-09-18T05:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157552#M6304</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;The topology:&lt;/P&gt;&lt;P&gt;internet-----CP 1550 fw------R81.10 virtual fw&lt;/P&gt;&lt;P&gt;cp-1550 is the edge firewall,&amp;nbsp;R81.10 virtual fw is the internal vpn gw and is mapped with cp-1550 firewall&lt;/P&gt;&lt;P&gt;You said that this probably won't work,why?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 16:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157552#M6304</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-19T16:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157554#M6305</link>
      <description>&lt;P&gt;The guys definitely brought up all the good reasons. Enable debugs and also collect client logs. But, before all that, make sure all the office mode settings are correct on the gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 17:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157554#M6305</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-19T17:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157556#M6306</link>
      <description>&lt;P&gt;I guess this might not work since the tunnel_test packet I believe might not be able to route back since its SecureRemote. Since firewall gives a fake IP address and here I believe firewall is behind nat device it would not know where to route the tunnel_test packet.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 18:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157556#M6306</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-09-19T18:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157558#M6307</link>
      <description>&lt;P&gt;Good point actually, I did not realize from that screen if was secureremote...&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 18:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157558#M6307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-19T18:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157571#M6308</link>
      <description>&lt;P&gt;What is the precise NAT configuration on the 1550?&lt;BR /&gt;Or if that device isn't doing the NAT, what is and what is its precise configuration?&lt;/P&gt;
&lt;P&gt;What is the configuration on the R81.10 system with respect to Remote Access?&lt;BR /&gt;Did you configure Link Selection and the Visitor Mode port?&lt;BR /&gt;I'm fairly certain you cannot "PAT" the Visitor Mode port to a different port (e.g from 10443 to 443) because of how the client stores/validates this information.&lt;BR /&gt;If you set the Link Selection on the R81.10 gateway and the Visitor Mode port used to match what your clients actually connects to initially (which means Link Selection IP of 58.33109.55 and Visitor Mode port of 10443), it might work.&lt;BR /&gt;Without doing that, I would not expect it to work.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 23:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157571#M6308</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-19T23:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157576#M6309</link>
      <description>&lt;P&gt;R81.10 vpn gw visitor mode port is 2443(I have modify the port from 10443 to 2443) and the 1550 map from 2443 to 2443.&lt;/P&gt;&lt;P&gt;Link selection ,i set the value "statically NATed IP:&lt;SPAN&gt;58.33109.55&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 01:25:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157576#M6309</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-20T01:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157627#M6310</link>
      <description>&lt;P&gt;Would you mind attach screenshots of how this is configured? I think it would help us help you solve this. By the way, did it ever work or its brand new config?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 11:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157627#M6310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-20T11:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157791#M6311</link>
      <description>&lt;P&gt;This is new config&amp;nbsp; and the configure as following:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL class="lia-list-style-type-disc"&gt;&lt;LI&gt;&lt;STRONG&gt;Enable IPsec VPN&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17853i1E29CD890A993E7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Enabled NATt by default&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17855i474FEB297B774425/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;The visitor mode port is tcp2443&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17857i8B06C3749CAF552B/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The belowing is the RemoteAccess community configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17858iFF9A30A9E004F499/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="6.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17859i7F2CCD5ABDD2E0E4/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:20:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157791#M6311</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-22T09:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157799#M6312</link>
      <description>&lt;P&gt;The attachment file is the&amp;nbsp; endpoint trac.log,i can not found any available error or alerts&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157799#M6312</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-22T09:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157858#M6313</link>
      <description>&lt;P&gt;Are you also port forwarding the NAT-T port (4500)?&lt;BR /&gt;Because that's where it looks like it is failing, if I'm understanding these debug logs correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:04:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157858#M6313</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-22T16:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157864#M6314</link>
      <description>&lt;P&gt;Yes,i also map the NAT-T port,but still can not connect successfull.&lt;/P&gt;&lt;P&gt;we can connect successfull when i disable the securexl both cp-1550 and R81.10.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 17:29:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157864#M6314</guid>
      <dc:creator>Jeffgo</dc:creator>
      <dc:date>2022-09-22T17:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157865#M6315</link>
      <description>&lt;P&gt;You may wish to contact TAC and have them give you right flags to debug securexl or refer to below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31404&amp;amp;partition=Expert&amp;amp;product=SecureXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31404&amp;amp;partition=Expert&amp;amp;product=SecureXL&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 17:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157865#M6315</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-22T17:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Connection failed: Negotation with site failed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157867#M6316</link>
      <description>&lt;P&gt;If disabling SecureXL "solves" a problem, contact TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 17:48:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-failed-Negotation-with-site-failed/m-p/157867#M6316</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-22T17:48:20Z</dc:date>
    </item>
  </channel>
</rss>

