<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN site to site fwconn_key_init_links (OUTBOUND) failed in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262609#M13410</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Have you check this sk?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk106682" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk106682&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Because of the local &amp;gt; central migration, the Global Properties differ. But before you change anything in the Global Properties,&amp;nbsp;consider the impact of the change.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Wed, 12 Nov 2025 10:39:40 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-11-12T10:39:40Z</dc:date>
    <item>
      <title>VPN site to site fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262608#M13409</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We are currently migrating a Site-to-Site VPN between two Check Point 1555 gateways from locally managed mode to centrally managed mode via SmartConsole (SMS).&lt;/P&gt;&lt;P&gt;Site details:&lt;/P&gt;&lt;P&gt;Branch Gateway (CP-1555)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Public IP: 192.168.168.201 (connected to SMS via public IP)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Encryption Domain: 10.17.36.0/24&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Head Office Gateway (CP-1555)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Public IP: 192.168.168.156&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Interface connected to SMS: 10.17.30.6&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Encryption Domain: 10.17.31.0/24, 10.17.34.0/24, 10.17.38.0/24, 10.17.4.0/24, ...&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;After configuring the VPN Community and Encryption Domains, we are unable to establish the VPN tunnel. The following log appears in fw ctl zdebug drop:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;@;&lt;SPAN class=""&gt;510065576&lt;/SPAN&gt;;&lt;SPAN class=""&gt;[cpu_0]&lt;/SPAN&gt;;&lt;SPAN class=""&gt;[fw4_0]&lt;/SPAN&gt;;fw_log_drop_ex: Packet proto=&lt;SPAN class=""&gt;17&lt;/SPAN&gt; &lt;SPAN class=""&gt;192.168&lt;/SPAN&gt;.&lt;SPAN class=""&gt;168.156&lt;/SPAN&gt;:&lt;SPAN class=""&gt;500&lt;/SPAN&gt; -&amp;gt; &lt;SPAN class=""&gt;192.168&lt;/SPAN&gt;.&lt;SPAN class=""&gt;168.201&lt;/SPAN&gt;:&lt;SPAN class=""&gt;500&lt;/SPAN&gt; dropped by fw_conn_post_inspect Reason: fwconn_key_init_links (OUTBOUND) failed;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;In SmartView Monitor, the VPN tunnel mostly shows as Down, though occasionally it briefly appears as &lt;STRONG&gt;Up&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We noticed that the Branch Gateway is attempting to connect to the Head Office gateway via the &lt;STRONG&gt;private interface (10.17.30.6)&lt;/STRONG&gt; instead of the public IP (192.168.168.156).&lt;/P&gt;&lt;P&gt;Since this is a migration, I suspect there might be a conflict between the previous locally managed VPN configuration and the new centrally managed setup. I have collected advanced VPN debug logs, but I am not sure how to interpret them.&lt;/P&gt;&lt;P&gt;Has anyone faced a similar issue or can share experience with analyzing these debug logs?&lt;BR /&gt;Any guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tin Tran&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 10:12:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262608#M13409</guid>
      <dc:creator>rozkie20</dc:creator>
      <dc:date>2025-11-12T10:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN site to site fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262609#M13410</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Have you check this sk?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk106682" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk106682&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Because of the local &amp;gt; central migration, the Global Properties differ. But before you change anything in the Global Properties,&amp;nbsp;consider the impact of the change.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 10:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262609#M13410</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-11-12T10:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN site to site fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262614#M13411</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;This feature already enable on R82&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 885px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32074iD9CAEBBF0D48BD33/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 11:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262614#M13411</guid>
      <dc:creator>rozkie20</dc:creator>
      <dc:date>2025-11-12T11:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN site to site fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262674#M13414</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;
&lt;P&gt;Are you able to check if it fails on phase 1 or 2? Because on phase 1, it would be more related to most likely enc settings/PSK, but if its phase 2, then usually its something with VPN enc. domains. Just run vpn tu and check there or one of below:&lt;/P&gt;
&lt;P&gt;vpn tu list ike&lt;BR /&gt;vpn tu list ipsec&lt;BR /&gt;vpn tu list peer_ike ip-addr&lt;BR /&gt;vpn tu list peer_ipsec ip-addr&lt;BR /&gt;vpn tu list tunnels&lt;BR /&gt;vpn tu tlist&lt;BR /&gt;vpn tu mstats&lt;BR /&gt;vpn tu del ipsec all&lt;BR /&gt;vpn tu del ipsec ip-addr&lt;BR /&gt;vpn tu del ipsec ip-addr username&lt;BR /&gt;vpn tu del ipsec ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu del all&lt;BR /&gt;vpn tu del ip-addr&lt;BR /&gt;vpn tu del ip-addr username&lt;BR /&gt;vpn tu del ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu conn&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 17:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/262674#M13414</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T17:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN site to site fwconn_key_init_links (OUTBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/263185#M13448</link>
      <description>&lt;P&gt;Opened case with TAC. Because we use one Public IP for management and VPN so it conflict when remote gateway try to negotia VPN with SMS so we have try to use another Public IP so this issue was fixed&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 07:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-site-to-site-fwconn-key-init-links-OUTBOUND-failed/m-p/263185#M13448</guid>
      <dc:creator>rozkie20</dc:creator>
      <dc:date>2025-11-19T07:37:16Z</dc:date>
    </item>
  </channel>
</rss>

