<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quantum Spark Remote Access VPN Drops or Asks for Reauthentication Every Hour in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/279139#M14044</link>
    <description>&lt;P&gt;Hi, I've similar problem after upgrading to R82 with CVE fix on my Spark 2000 centrally managed.&lt;/P&gt;&lt;P&gt;The only solution was reverting VPN Remote Access IKE support to IKEv1 (Use IKEv2 and support IKEv1 do not work).&lt;/P&gt;&lt;P&gt;I'll open a ticket...&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2026 18:24:22 GMT</pubDate>
    <dc:creator>perfect4situa</dc:creator>
    <dc:date>2026-06-30T18:24:22Z</dc:date>
    <item>
      <title>Quantum Spark Remote Access VPN Drops or Asks for Reauthentication Every Hour</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/278270#M13992</link>
      <description>&lt;P&gt;After upgrading to the latest builds for R81.10.17 (4901) and R82.00.10 (2216) we now have all clients complaining that VPNs are dropping or asking for reauthentication every hour. This affect Entra SSO, AD Auth, etc.&lt;/P&gt;&lt;P&gt;If someone from Checkpoint sees this, please escalate this with R&amp;amp;D.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 19:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/278270#M13992</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-10T19:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark Remote Access VPN Drops or Asks for Reauthentication Every Hour</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/278285#M13995</link>
      <description>&lt;P&gt;Updating this post with logs. We have a TAC case open but want other people to know this is a problem. This is with IKEv2 turned on R82. IKEv2 doesn't work on R81 for Remote Access even though it is in the advanced settings (brilliant!). Apparently IKEv2 is completely broken on R82 as well (brilliant!).&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW CTL ZDEBUG output:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;fw_log_drop_ex: Packet proto=17&lt;SPAN&gt;&amp;nbsp;[redacted]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dropped by vpn_ipsec_decrypt Reason: decryption failure: Could not get SAs from packet;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Client Helpdesk.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;No reply from the gw ip= for tunnel test packet. Office Mode IP=, source port=18232.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;No reply from the gw ip= for tunnel test packet. Office Mode IP=, source port=18233.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;No reply from the gw ip= for tunnel test packet. Office Mode IP=, source port=18234.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Client state is connected&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Tunnel (0x1) disconnected. State is connected. Trying to reconnect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;IKE connection failed, error code=-1000. Reason: Site is not responding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Client state is reconnecting&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Reconnect failed. trying again (0x1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;State reconnecting. Roaming timeout is reached, cancelling connection (0x1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Checkpoint GUI:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;IKE failure: Child SA exchange: Exchange failed: timeout reached.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;IKE failure: Informational exchange: Sending notification to peer: Invalid IKE SPI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;IKE SPIs: 4b5c&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Drop UDP/4500&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 13:10:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/278285#M13995</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-11T13:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark Remote Access VPN Drops or Asks for Reauthentication Every Hour</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/279139#M14044</link>
      <description>&lt;P&gt;Hi, I've similar problem after upgrading to R82 with CVE fix on my Spark 2000 centrally managed.&lt;/P&gt;&lt;P&gt;The only solution was reverting VPN Remote Access IKE support to IKEv1 (Use IKEv2 and support IKEv1 do not work).&lt;/P&gt;&lt;P&gt;I'll open a ticket...&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 18:24:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/279139#M14044</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-06-30T18:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark Remote Access VPN Drops or Asks for Reauthentication Every Hour</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/279368#M14049</link>
      <description>&lt;P&gt;I've had a ticket open for weeks. I have a good engineer that I have worked with in the past but he said he was not able to replicate the issue so I am just providing him access to our firewall to see if he can monitor it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2026 21:11:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-Remote-Access-VPN-Drops-or-Asks-for/m-p/279368#M14049</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-07-07T21:11:20Z</dc:date>
    </item>
  </channel>
</rss>

