<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S-IPSEC-Tunnel not comming up without public DNS server configured - why? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7573#M134</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;thanks for your response! I think&amp;nbsp;that's it. The log page not beeing responsive is another&amp;nbsp;&lt;A href="https://dict.leo.org/german-english/phenomenon" style="color: inherit; background-color: #ffffff; border: 0px; text-decoration: none; font-size: 13.92px;"&gt;phenomenon&lt;/A&gt;&amp;nbsp;I noticed when no public DNS was defined.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Oct 2017 11:19:01 GMT</pubDate>
    <dc:creator>Julius_Kaiser</dc:creator>
    <dc:date>2017-10-17T11:19:01Z</dc:date>
    <item>
      <title>S2S-IPSEC-Tunnel not comming up without public DNS server configured - why?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7571#M132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an IPSEC tunnel configured on the given platform (see below). The tunnel peer is defined by IP address, not hostname. Tunnel config is default, Check Point as remote gateway (same platform, firmware etc), p&lt;SPAN style="color: #2a3a55; background-color: #ffffff;"&gt;erfect forward secrecy with DH Group 2, no NAT.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a3a55; background-color: #ffffff;"&gt;My problem is: The Tunnel won't come up without a public reachable DNS server configured as the primary DNS server under Device/ DNS/ "Configured DNS Servers".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know this kind of behaviour and can provide an explanation, or is this a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="color: #2a3a55; background-color: #f7f9ff;"&gt;&lt;SPAN class=""&gt;Appliance:&lt;/SPAN&gt;Check Point 1430 Appliance (gro-aue-fw01)&lt;/DIV&gt;&lt;DIV style="color: #2a3a55; background-color: #f7f9ff;"&gt;&lt;SPAN class=""&gt;Security Management:&lt;/SPAN&gt;Locally managed&lt;/DIV&gt;&lt;DIV style="color: #2a3a55; background-color: #f7f9ff;"&gt;&lt;SPAN class=""&gt;Version (Firmware):&lt;/SPAN&gt;R77.20.40 (990171107)&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 12:17:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7571#M132</guid>
      <dc:creator>Julius_Kaiser</dc:creator>
      <dc:date>2017-10-16T12:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: S2S-IPSEC-Tunnel not comming up without public DNS server configured - why?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7572#M133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's possible this is covered by a known limitation listed here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105380" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105380"&gt;Check Point R77.20 for 600 / 700 / 1100 / 1200R / 1400 Appliance Known Limitations&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Specifically:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;TABLE border="1" cellpadding="4" cellspacing="2" style="color: #000000; background-color: #ffffff; font-size: 14px;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;01668937&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Configuring appliances with a DNS server that does not resolve publich domain names, may cause issues in various features, including timeouts during SIC establishment, log page not being responsive, and more. Make sure to configure DNS servers that can be reached from the appliance.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 18:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7572#M133</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-16T18:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: S2S-IPSEC-Tunnel not comming up without public DNS server configured - why?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7573#M134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;thanks for your response! I think&amp;nbsp;that's it. The log page not beeing responsive is another&amp;nbsp;&lt;A href="https://dict.leo.org/german-english/phenomenon" style="color: inherit; background-color: #ffffff; border: 0px; text-decoration: none; font-size: 13.92px;"&gt;phenomenon&lt;/A&gt;&amp;nbsp;I noticed when no public DNS was defined.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/S2S-IPSEC-Tunnel-not-comming-up-without-public-DNS-server/m-p/7573#M134</guid>
      <dc:creator>Julius_Kaiser</dc:creator>
      <dc:date>2017-10-17T11:19:01Z</dc:date>
    </item>
  </channel>
</rss>

