<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS to Checkpoint VPN with BGP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/127009#M8177</link>
    <description>&lt;P&gt;Two things -&lt;/P&gt;&lt;P&gt;Is this Policy based VPN or Route based VPN?&lt;/P&gt;&lt;P&gt;Have you tried debugging with vpn debug ikeon? have you analyzed the output? Plus if this is a route based enable match directional traffic.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 03:20:48 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2021-08-16T03:20:48Z</dc:date>
    <item>
      <title>AWS to Checkpoint VPN with BGP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/126747#M8175</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running a Checkpoint cluster on R80.40 and I am trying to connect a VPN to AWS with BGP.&amp;nbsp; The AWS side was built by a third party and I am working on getting it verified. I have downloaded the config file from AWS for my version of checkpoint. I have configured it to the letter except for Dead Peer Detection DPD. I do not think I need this to get the tunnel going? I have been&amp;nbsp;&lt;SPAN&gt;using&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tcpdump -nni any port 500 or esp and host &amp;lt;enter_peer_ip_here&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;to watch the tunnel. I can see phase 1 gets setup and then it fails at phase 2. I say fails loosely as the logs just keep referencing phase 2. It feels a lot like I'm just shooting in the dark as I didn't setup the AWS side and I am not clear on any log locations that might help with this on my firewalls. Are there any techniques that I should be using to troubleshoot this or logs I can look at that might give me some more information? Here are some of the log data that I am seeing now from the command above. I'm not 100% sure what I should be looking for here as I do not have a reference for the log syntax. Really looking for a life line here anything would probably help at this pont.&lt;/P&gt;&lt;P&gt;10:36:32.850496 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident&lt;BR /&gt;10:36:32.850499 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident&lt;BR /&gt;10:36:32.903517 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident&lt;BR /&gt;10:36:32.903517 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident&lt;BR /&gt;10:36:32.904001 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident&lt;BR /&gt;10:36:32.904003 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident&lt;BR /&gt;10:36:32.957669 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident&lt;BR /&gt;10:36:32.957669 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident&lt;BR /&gt;10:36:32.958607 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident[E]&lt;BR /&gt;10:36:32.958609 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 1 I ident[E]&lt;BR /&gt;10:36:33.011620 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident[E]&lt;BR /&gt;10:36:33.011620 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 1 R ident[E]&lt;BR /&gt;10:36:33.012570 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.012573 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.016337 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R inf[E]&lt;BR /&gt;10:36:33.016337 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R inf[E]&lt;BR /&gt;10:36:33.066342 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R oakley-quick[E]&lt;BR /&gt;10:36:33.066342 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R oakley-quick[E]&lt;BR /&gt;10:36:33.067669 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.067671 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.167589 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.167592 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.267595 IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.267598 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt;.500 &amp;gt; &amp;lt;AWSIP&amp;gt;.500: isakmp: phase 2/others I oakley-quick[E]&lt;BR /&gt;10:36:33.367784 IP &amp;lt;CheckpointIP&amp;gt; &amp;gt; &amp;lt;AWSIP&amp;gt;: ESP(spi=0xc71c9dc5,seq=0x1), length 84&lt;BR /&gt;10:36:33.367787 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt; &amp;gt; &amp;lt;AWSIP&amp;gt;: ESP(spi=0xc71c9dc5,seq=0x1), length 84&lt;BR /&gt;10:36:42.654894 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt; &amp;gt; &amp;lt;CheckpointIP&amp;gt;: ESP(spi=0x3e28f919,seq=0x1), length 100&lt;BR /&gt;10:36:42.654894 IP &amp;lt;AWSIP&amp;gt; &amp;gt; &amp;lt;CheckpointIP&amp;gt;: ESP(spi=0x3e28f919,seq=0x1), length 100&lt;BR /&gt;10:36:42.850114 IP &amp;lt;CheckpointIP&amp;gt; &amp;gt; &amp;lt;AWSIP&amp;gt;: ESP(spi=0xc71c9dc5,seq=0x2), length 84&lt;BR /&gt;10:36:42.850117 ethertype IPv4, IP &amp;lt;CheckpointIP&amp;gt; &amp;gt; &amp;lt;AWSIP&amp;gt;: ESP(spi=0xc71c9dc5,seq=0x2), length 84&lt;BR /&gt;10:36:43.012425 ethertype IPv4, IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R inf[E]&lt;BR /&gt;10:36:43.012425 IP &amp;lt;AWSIP&amp;gt;.500 &amp;gt; &amp;lt;CheckpointIP&amp;gt;.500: isakmp: phase 2/others R inf[E]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 13:57:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/126747#M8175</guid>
      <dc:creator>ScottG67</dc:creator>
      <dc:date>2021-08-12T13:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: AWS to Checkpoint VPN with BGP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/127007#M8176</link>
      <description>&lt;P&gt;Start here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 02:47:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/127007#M8176</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-16T02:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: AWS to Checkpoint VPN with BGP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/127009#M8177</link>
      <description>&lt;P&gt;Two things -&lt;/P&gt;&lt;P&gt;Is this Policy based VPN or Route based VPN?&lt;/P&gt;&lt;P&gt;Have you tried debugging with vpn debug ikeon? have you analyzed the output? Plus if this is a route based enable match directional traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 03:20:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AWS-to-Checkpoint-VPN-with-BGP/m-p/127009#M8177</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-16T03:20:48Z</dc:date>
    </item>
  </channel>
</rss>

