<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic connection Issue running a Quantum SASE client (Perimeter81) behind a Spark appliance in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/200042#M933</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;using the Perimeter81 client behind a spark appliance the network connection to the P81 private or public network didn't work. The connection went down after some seconds. Concerning the logs of the Spark appliance nothing had been blocked but running a zdebug drop you can see "&lt;EM&gt;dropped by fwmultik_process_f2p_cookie_inner Reason: PSL Drop: ADVP" &lt;/EM&gt;messages for port 51821.&amp;nbsp; To get it running I had&amp;nbsp; added a dedicate Service for the&amp;nbsp;WireGuard&amp;nbsp; UDP ports 51821, 8000 and&amp;nbsp; 8055 with the &lt;EM&gt;Protocol Type&lt;/EM&gt; None and put them in a allow rule.&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Dec 2023 09:51:50 GMT</pubDate>
    <dc:creator>Thomas_Hesse</dc:creator>
    <dc:date>2023-12-08T09:51:50Z</dc:date>
    <item>
      <title>connection Issue running a Quantum SASE client (Perimeter81) behind a Spark appliance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/200042#M933</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;using the Perimeter81 client behind a spark appliance the network connection to the P81 private or public network didn't work. The connection went down after some seconds. Concerning the logs of the Spark appliance nothing had been blocked but running a zdebug drop you can see "&lt;EM&gt;dropped by fwmultik_process_f2p_cookie_inner Reason: PSL Drop: ADVP" &lt;/EM&gt;messages for port 51821.&amp;nbsp; To get it running I had&amp;nbsp; added a dedicate Service for the&amp;nbsp;WireGuard&amp;nbsp; UDP ports 51821, 8000 and&amp;nbsp; 8055 with the &lt;EM&gt;Protocol Type&lt;/EM&gt; None and put them in a allow rule.&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 09:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/200042#M933</guid>
      <dc:creator>Thomas_Hesse</dc:creator>
      <dc:date>2023-12-08T09:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: connection Issue running a Quantum SASE client (Perimeter81) behind a Spark appliance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/200161#M934</link>
      <description>&lt;P&gt;Hi, connection with the agent requires several ports to be reachable and not blocked over the network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The list of required ports and destinations are listed at:&amp;nbsp;&lt;A href="https://support.perimeter81.com/docs/can-t-connect-perimeter-s-internet-connection-troubleshooting-guide" target="_blank"&gt;https://support.perimeter81.com/docs/can-t-connect-perimeter-s-internet-connection-troubleshooting-guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 08:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/200161#M934</guid>
      <dc:creator>GuyA</dc:creator>
      <dc:date>2023-12-11T08:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: connection Issue running a Quantum SASE client (Perimeter81) behind a Spark appliance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/205312#M935</link>
      <description>&lt;P&gt;I also had issues. Traffic on port 51821 was being dropped with the following error: "Violated Unidirectional Connection".&lt;/P&gt;
&lt;P&gt;I was able to make it work after creating services for ports&amp;nbsp;51821, 8000, 8055 and creating a rule explicitly allowing the service group instead of using a rule with service=any.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/connection-Issue-running-a-Quantum-SASE-client-Perimeter81/m-p/205312#M935</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2024-02-07T13:40:54Z</dc:date>
    </item>
  </channel>
</rss>

