<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE failure: Child SA exchange Issue in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207604#M10327</link>
    <description>&lt;P&gt;L-71 is a 1400 Series for those playing along at home.&lt;/P&gt;
&lt;P&gt;This message means the remote site doesn’t accept the proposed encryption domain (Traffic selectors) by current gateway.&lt;BR /&gt;This can indicate a configuration problem, such as:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Missing subnets on either of the peers&lt;/LI&gt;
&lt;LI&gt;Unaligned tunnel sharing configurations (tunnel per gateway \ subnet \ address)&lt;/LI&gt;
&lt;LI&gt;Route all traffic configured on a site where other peer is oblivious.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Verify the following :&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Encryption domains are configured correctly on both peers.&lt;/LI&gt;
&lt;LI&gt;Tunnel sharing is aligned on both peers&lt;/LI&gt;
&lt;LI&gt;If route all traffic is configured on the site, confirm that "Allow traffic to the internet from remote site through this Security Gateway" is enabled under "advanced" tab on peer WebUI site configuration.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 01 Mar 2024 21:29:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-03-01T21:29:58Z</dc:date>
    <item>
      <title>IKE failure: Child SA exchange Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/206909#M10301</link>
      <description>&lt;P&gt;I have a L-71 unit that we are trying to connect to our other office. We managed to get connection after many hours of testing but we keep getting this error on both ends despite a good connection. So much as a single ping causes this error to fire. What is this and how do we fix it?&lt;/P&gt;&lt;P&gt;Description&lt;BR /&gt;IKE failure: Child SA exchange: Received notification from peer: Traffic selectors unacceptable&lt;/P&gt;&lt;P&gt;IKE Phase2 Message ID: 00000001&lt;BR /&gt;Reject Category: IKE failure&lt;BR /&gt;Encryption Scheme: IKEv2&lt;BR /&gt;VPN Feature: IKE&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 19:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/206909#M10301</guid>
      <dc:creator>bsbesit</dc:creator>
      <dc:date>2024-02-22T19:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: IKE failure: Child SA exchange Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207173#M10302</link>
      <description>&lt;P&gt;Versions used on both ends, details about your VPN config? What do you call "a good connection" in this context?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 14:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207173#M10302</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-02-26T14:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: IKE failure: Child SA exchange Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207180#M10303</link>
      <description>&lt;P&gt;Traffic selectors are generally when one side proposes a host/subnet that is not defined on the other side. The log file should tell you which traffic selectors is providing the error, otherwise you'll have to do a debug to get that information.&lt;/P&gt;&lt;P&gt;If you send 10.20.30.0/24, that's how it needs to be defined on both sides. You would get an error if one side was 10.20.30.0/23 for example.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 15:23:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207180#M10303</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-02-26T15:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: IKE failure: Child SA exchange Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207604#M10327</link>
      <description>&lt;P&gt;L-71 is a 1400 Series for those playing along at home.&lt;/P&gt;
&lt;P&gt;This message means the remote site doesn’t accept the proposed encryption domain (Traffic selectors) by current gateway.&lt;BR /&gt;This can indicate a configuration problem, such as:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Missing subnets on either of the peers&lt;/LI&gt;
&lt;LI&gt;Unaligned tunnel sharing configurations (tunnel per gateway \ subnet \ address)&lt;/LI&gt;
&lt;LI&gt;Route all traffic configured on a site where other peer is oblivious.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Verify the following :&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Encryption domains are configured correctly on both peers.&lt;/LI&gt;
&lt;LI&gt;Tunnel sharing is aligned on both peers&lt;/LI&gt;
&lt;LI&gt;If route all traffic is configured on the site, confirm that "Allow traffic to the internet from remote site through this Security Gateway" is enabled under "advanced" tab on peer WebUI site configuration.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 01 Mar 2024 21:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IKE-failure-Child-SA-exchange-Issue/m-p/207604#M10327</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-01T21:29:58Z</dc:date>
    </item>
  </channel>
</rss>

