<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Establisth VPN between 1555 and 1575 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254508#M13025</link>
    <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
    <pubDate>Mon, 04 Aug 2025 15:46:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-08-04T15:46:11Z</dc:date>
    <item>
      <title>Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254442#M13012</link>
      <description>&lt;P&gt;We have two new 1555 and 1575 Quantum Spark gateways. Both are the latest version R81.10.17. When we setup a VPN tunnel the 1575 create a tunnel and can ping the LAN interface on the 1555. The 1555 creates the tunnel ( VPN TU shows there are tunnels) but we cannot ping the interface on the 1575. When we first set it up, it worked perfectly. It eventually went down in the middle of the night and we cannot get it back up no matter what. We contacted support and they were clueless and told me I have to wait until Sunday night (this is a critical matter, company relies on this tunnel to be up 24/7). I deleted the tunnels, re-recreated, cleared SAs in VPU TU, rebooted both firewalls, nothing works. The company I installed these for isn't very pleased. They are telling me they want to go back to their 10+ year old Barracuda's and want their money back because I can't get a simple site to site VPN setup. BTW I manage 50+ Quantum spark and it seems like VPN tunnels get worse and worse through the years. I still have 700 series tunnels that haven't dropped in 8 years, but these new 1500s can't hold a tunnel for a couple hours.&lt;/P&gt;&lt;P&gt;Also, btw, all of the traffic selectors are fine. I am just doing what I always do and let the checkpoint handle the local encryption domains automatically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also both are locally managed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the errors I am getting,&lt;/P&gt;&lt;P&gt;Child SA exchange: Sending notification to peer: Traffic selectors unacceptable MyTSi: &amp;lt;redacted&amp;gt; &amp;lt;255.255.255.254&amp;gt; &amp;lt;224.0.0.0 - 224.0.0.255&amp;gt; MyTSr: &amp;lt;redacted&amp;gt; &amp;lt;192.168.90.0 - 192.168.90.255&amp;gt; &amp;lt;224.0.0.0 - 224.0.0.255&amp;gt; Peer TSi: &amp;lt;192.168.90.0 - 192.168.90.255&amp;gt;&lt;/P&gt;&lt;P&gt;Child SA exchange: Exchange failed: timeout reached.&lt;/P&gt;&lt;P&gt;IKE failure: Informational exchange: Sending notification to peer: Invalid IKE SPI IKE SPIs: 9eabb7e44f833352:50570df6387b0035&lt;/P&gt;&lt;P&gt;dropped by vpn_drop_and_log Reason: According to the policy the packet should not have been decrypted;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Aug 2025 21:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254442#M13012</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2025-08-02T21:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254444#M13014</link>
      <description>&lt;P&gt;Which specific build of R81.10.17 is used?&lt;/P&gt;
&lt;P&gt;Are you trying to do multicast traffic across the VPN (e.g. OSPF over VTI) or have you just chosen that line at random?&lt;/P&gt;
&lt;P&gt;Are either of the gateways DAIP, what else can you tell us about the setup?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 06:38:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254444#M13014</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-08-03T06:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254446#M13015</link>
      <description>&lt;P&gt;FWIW, I've much less experience with Spark than GAIA when I compare it to yours, but I always use manually defined domains rather than "match topology" as I tend to find them more reliable. Also, if you use certificates and exchanged CA, ensure CRL check is off or it is reachable. There are other considerations depending of your setup.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 15:25:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254446#M13015</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-08-03T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254447#M13016</link>
      <description>&lt;P&gt;I would do exactly what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp; suggested, makes total sense to me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 15:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254447#M13016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-03T15:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254506#M13024</link>
      <description>&lt;P&gt;I factory reset the device and everything is fine now. I'm lucky this wasn't one of my devices out of state or else I'd be hopping on a plane to reset a firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 15:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254506#M13024</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2025-08-04T15:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Establisth VPN between 1555 and 1575</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254508#M13025</link>
      <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 15:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cannot-Establisth-VPN-between-1555-and-1575/m-p/254508#M13025</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-04T15:46:11Z</dc:date>
    </item>
  </channel>
</rss>

