<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154949#M6392</link>
    <description>&lt;P&gt;That was one of the things our support partner suggesting checking prior to migration, and they found no alterations to the "trac_client_1.ttm" file.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 12:51:24 GMT</pubDate>
    <dc:creator>Howard_Gyton</dc:creator>
    <dc:date>2022-08-12T12:51:24Z</dc:date>
    <item>
      <title>R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154931#M6386</link>
      <description>&lt;P&gt;We are part way through a firewall migration from R80.30 to R81.10.&lt;/P&gt;&lt;P&gt;Both new boxes are built, the passive firewall has been turned off, and the configuration imported to the new R81.10 passive firewall.&lt;/P&gt;&lt;P&gt;Failover of the cluster has worked flawlessly, and we have conducted tests, and everything appears to work with one exception.&lt;/P&gt;&lt;P&gt;Endpoint clients refuse to VPN connect.&amp;nbsp; I have tried an E86.00, E86.30, and E86.60 client, and none of them work, with the eventual error being that it could could not negotiate a connection.&amp;nbsp; SNX, and Capsule VPN, on both Windows 11, and iPhone, work just fine.&amp;nbsp; Even the really old CLI-enabled SNX copy we have works fine.&lt;/P&gt;&lt;P&gt;Restarting services on the primary, failing back to the R80.30 box, and all VPN services are fully restored.&lt;/P&gt;&lt;P&gt;Has anyone else experienced this?&lt;/P&gt;&lt;P&gt;Howard&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 09:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154931#M6386</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T09:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154933#M6387</link>
      <description>&lt;P&gt;Which Jumbo was applied to the R81.10 gateways?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 09:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154933#M6387</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-12T09:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154934#M6388</link>
      <description>&lt;P&gt;66&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 09:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154934#M6388</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T09:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154936#M6389</link>
      <description>&lt;P&gt;Any corresponding drop logs in SmartConsole or symptoms that align to&amp;nbsp;&lt;SPAN&gt;sk175704?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 10:17:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154936#M6389</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-12T10:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154939#M6390</link>
      <description>&lt;P&gt;Sadly nothing like that.&amp;nbsp; You could see our accounts were authenticated via RADIUS, and the connection was successful. Then it would hang for a few minutes, then the response box would come up again.&amp;nbsp; It did that perhaps three times before finally giving up stating that it could not negotiate a connection.&lt;/P&gt;&lt;P&gt;I just had another look over the SK.&amp;nbsp; So while we didn't see any dropped traffic in the logs we do have a mixture of VPN rules.&lt;/P&gt;&lt;P&gt;We have a new VPN layer rule, using Access Roles, and have been gradually migrating services from the Legacy rules above.&lt;/P&gt;&lt;P&gt;The one thing I would add is this was not an in-place upgrade from R80.30, which that SK seems to imply.&amp;nbsp; This was a new R81.10 server, where we have used the process to import the exported configuration on to that new box, so it has never had R80.30 on it.&lt;/P&gt;&lt;P&gt;set clienv on-failure continue&lt;BR /&gt;load configuration fw1_new-hardware&lt;BR /&gt;set clienv on-failure stop&lt;BR /&gt;save config&lt;/P&gt;&lt;P&gt;Similarly, the R81.10 management server was freshly built, using an exported database from the old R80.30 management server.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 10:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154939#M6390</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T10:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154948#M6391</link>
      <description>&lt;P&gt;I had seen customers have this issue before and in my experience, it was ALWAYS caused by some custom file either on mgmt or gateways that had to do with vpn config. So, either trac.config, or trac_client_1.ttm file in most cases. Not sure if you guys have that configured, but throwing it out there. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;mentioned, any other relevant logs you can find? Do you know if anyone generated any logs from the VPN client?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 12:33:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154948#M6391</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-12T12:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154949#M6392</link>
      <description>&lt;P&gt;That was one of the things our support partner suggesting checking prior to migration, and they found no alterations to the "trac_client_1.ttm" file.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 12:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154949#M6392</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154950#M6393</link>
      <description>&lt;P&gt;What you could do is cd $FWDIR/conf on both mgmt and gateways and do ls -lh trac*&lt;/P&gt;
&lt;P&gt;This will show you if there is more than original trac_client_1.ttm file, so it would tell us 100% what is used.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:38:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154950#M6393</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-12T13:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154951#M6394</link>
      <description>&lt;P&gt;Good idea.&amp;nbsp; For good measure I ran this on the management server, and both the R80.30, and R81.10 firewalls.&lt;/P&gt;&lt;P&gt;ls -lh trac*&lt;BR /&gt;-rwxr-xr-x 1 admin bin 7.2K Jun 13 10:47 trac_client_1.ttm&lt;/P&gt;&lt;P&gt;ls -lh trac*&lt;BR /&gt;-rw-r----- 1 admin bin 7.2K Sep 24 2019 trac_client_1.ttm&lt;/P&gt;&lt;P&gt;ls -lh trac*&lt;BR /&gt;-rw-r----- 1 admin bin 7.2K Jun 30 2021 trac_client_1.ttm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154951#M6394</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T13:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154952#M6395</link>
      <description>&lt;P&gt;Check the content of it on mgmt server.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:47:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154952#M6395</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-12T13:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154955#M6396</link>
      <description>&lt;P&gt;I can't see anything that stands out, that might be something we added.&amp;nbsp; I was going to post its contents here, but it's a long file.&lt;/P&gt;&lt;P&gt;I copied the file from both the management server, and the R81.10 server, and then used Notepad++ to compare them&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trac_compare.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17427i358518A08423652F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="trac_compare.jpg" alt="trac_compare.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I ran a further compare with the file from the R80.30 server, and that was identical too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 13:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154955#M6396</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-12T13:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154985#M6397</link>
      <description>&lt;P&gt;What are your link selection settings?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 08:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154985#M6397</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2022-08-15T08:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154989#M6398</link>
      <description>&lt;P&gt;"Selected address from topology table" VIP selected&lt;/P&gt;&lt;P&gt;"Operating system routing table"&lt;/P&gt;&lt;P&gt;Tracking=None&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 11:30:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/154989#M6398</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-15T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155041#M6399</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11039"&gt;@Howard_Gyton&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you mention access role but did you enable Remote Access check box under identity Awareness configuration?&lt;/P&gt;
&lt;P&gt;if you didn't check this box, can you please enable it and try re-test?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ida_vpn.JPG" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17434iCBA979DF8B858382/image-size/large?v=v2&amp;amp;px=999" role="button" title="ida_vpn.JPG" alt="ida_vpn.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 08:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155041#M6399</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2022-08-16T08:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155047#M6400</link>
      <description>&lt;P&gt;Yes, we have that set.&amp;nbsp; If we didn't it wouldn't work on our R80.30 firewall, where normal functionality is seen for all features.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IA_RA.jpg" style="width: 606px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17437iC12A345063E974B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="IA_RA.jpg" alt="IA_RA.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I may have mentioned, we believe the failure is in Phase 2 of the negotiation.&amp;nbsp; Last night we ran some further tests, and played around with the encryption, and data integrity settings.&amp;nbsp; Briefly we turned everything on, including DES/3DES, and even then the Endpoint clients wouldn't connect to the R81.10 firewall, but work quite happily with the R80.30 firewall.&amp;nbsp; We of course changed those settings back.&lt;/P&gt;&lt;P&gt;But again, SNX, and Capsule VPN remain unaffected, and could connect to the R81.10 firewall, even if I set my phone to use IPSec rather than SSL.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 08:41:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155047#M6400</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-16T08:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155048#M6401</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11039"&gt;@Howard_Gyton&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ok, i though you configured access role only in R81.10, miss understood the story &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I will contact you offline via email and we will continue it from there.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ilya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 08:53:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155048#M6401</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2022-08-16T08:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 to R81.10 - Endpoint client fails to negotiate with the R81.10 box</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155403#M6402</link>
      <description>&lt;P&gt;Issue was eventually resolved with a no-NAT rule for the IP address the VPN clients connect to, this information obtained from our support partner.&lt;/P&gt;&lt;P&gt;It seems that our R80.30 firewalls were affected by this to a degree, and two responses were sent to the client.&amp;nbsp; One from the hide-NAT rule, and one from the IP address the responses should come from.&amp;nbsp; The upshot was that all Endpoint clients were using Visitor mode rather than NAT-T.&lt;/P&gt;&lt;P&gt;On the R81.10 firewalls this didn't seem to work correctly, and instead of working in Visitor mode they disconnected after a few seconds.&lt;/P&gt;&lt;P&gt;A no-NAT rule sitting just above the existing hide NAT rule allowed the Endpoint clients to connect, and NAT-T connections could be seen with "vpn tu tlist".&lt;/P&gt;&lt;P&gt;Both firewall have been replaced with new R81.10 boxes, and everything is working fine.&amp;nbsp; I understand a fix for this behaviour should be included in a forthcoming JHF.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 11:30:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-30-to-R81-10-Endpoint-client-fails-to-negotiate-with-the-R81/m-p/155403#M6402</guid>
      <dc:creator>Howard_Gyton</dc:creator>
      <dc:date>2022-08-22T11:30:30Z</dc:date>
    </item>
  </channel>
</rss>

