<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to site VPN issue -  Packet is dropped because there is no valid SA in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114014#M9016</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; and &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I have checked and there is no other error message. The enryption is working again and nothing has been changed to make it work. I will check further tomorrow and see if there is anything unsual.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;The option "Keep IKE SAs" is already enabled.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 19:51:59 GMT</pubDate>
    <dc:creator>MichaelBurnham</dc:creator>
    <dc:date>2021-03-18T19:51:59Z</dc:date>
    <item>
      <title>Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113919#M9013</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have a site to site VPN ( Checkpoint to checkpoint, IKEv2 only). A few days ago, everything was working fine. but since yesterday, traffic is ok in one way, and it's dropped by the firewall for the other way, with the error message below:&lt;/P&gt;&lt;P&gt;Enryption Fail Reason: "Packet is dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge Database for more information"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've checked the configuration, everything looks fine. The fact that is work one day and stopped working the next can't be a config issue..I think..&lt;/P&gt;&lt;P&gt;Does anyone have any idea what might be the root cause ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113919#M9013</guid>
      <dc:creator>MichaelBurnham</dc:creator>
      <dc:date>2021-03-18T11:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113973#M9014</link>
      <description>&lt;P&gt;Insufficient information.&amp;nbsp; That error message is a symptom of your problem (interesting traffic could not be encrypted and forwarded because no VPN tunnel is present), not the actual cause.&amp;nbsp; You should have some other error messages that will be more helpful such as "no proposal chosen", "no response from peer", "Invalid ID", "Received a Cleartext Packet within an Encrypted Connection", "Packet was Decrypted, but Policy Says Packet Should not have been decrypted", etc.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113973#M9014</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-03-18T16:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113975#M9015</link>
      <description>&lt;P&gt;Tim is right, very generic error...did you try run ike debug? Also, there is a setting in global properties to "keep ike SAs", check that and push policy. Is under menu -&amp;gt; global properties -&amp;gt; advanced -&amp;gt; configuration -&amp;gt; VPN I believe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/113975#M9015</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T16:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114014#M9016</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; and &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I have checked and there is no other error message. The enryption is working again and nothing has been changed to make it work. I will check further tomorrow and see if there is anything unsual.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;The option "Keep IKE SAs" is already enabled.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 19:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114014#M9016</guid>
      <dc:creator>MichaelBurnham</dc:creator>
      <dc:date>2021-03-18T19:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114020#M9017</link>
      <description>&lt;P&gt;Ok, sounds good...maybe also make sure to check "keep all connections" under connection persistence under gateway properties (somewhere on the left menu at the bottom). Honestly, dont ask me why this is relevant, but I had seen it help with VPN tunnels many times.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 20:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114020#M9017</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T20:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue -  Packet is dropped because there is no valid SA</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114027#M9018</link>
      <description>&lt;P&gt;As Andy advised, you should definitely enable IKE debugging. You can do so with this command on the firewall:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;vpn debug ikeon&lt;/LI-CODE&gt;
&lt;P&gt;If you are using a cluster, you should enable it on both members. If you control both sides of the VPN, you should enable it on both sides. You then need to wait until you get a successful negotiation&amp;nbsp;&lt;STRONG&gt;and&lt;/STRONG&gt; start seeing the problem again. "&lt;SPAN&gt;Packet is dropped because there is no valid SA" always means the traffic was flagged as interesting for a particular VPN community and was held while the keys were negotiated, but the key negotiation failed. To figure out what's wrong from an IKE debug, you want a successful negotiation and a failing negotiation. The difference between them is the most certain way to figure out what's wrong.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 22:00:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Site-to-site-VPN-issue-Packet-is-dropped-because-there-is-no/m-p/114027#M9018</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-03-18T22:00:52Z</dc:date>
    </item>
  </channel>
</rss>

