<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn warning: VPN-1 has reached its tunnel capacity in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/vpn-warning-VPN-1-has-reached-its-tunnel-capacity/m-p/13698#M328</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your VPN Tunnel Sharing setting under Advanced Properties in the VPN Community is probably set to "pair of hosts", which creates a unique Phase 2 IPSEC tunnel for every possible combination of hosts that try to use the VPN.&amp;nbsp; "Pair of subnets" is more appropriate; if that is already selected consider the "one tunnel per gateway pair" setting.&amp;nbsp; Be careful changing this setting though as it can have a wide impact on VPN connectivity, best to do it during a maintenance window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Nov 2017 15:51:46 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2017-11-22T15:51:46Z</dc:date>
    <item>
      <title>vpn warning: VPN-1 has reached its tunnel capacity</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/vpn-warning-VPN-1-has-reached-its-tunnel-capacity/m-p/13697#M327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our decentralize Firewall Cluster (type 1180) gives the following information info:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vpn warning: VPN-1 has reached its tunnel capacity&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's part of a VPN Star Community with our central gateways (12000) R77.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Increasing the Optimizations on the Cluster Object for:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Maximum concurrent IKE negotiations&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;doesn't solve the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have other decentralize Firewall Clusters (also type 1180) who do not have this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone knows what it means, and how to solve this? How can i debug it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/vpn-warning-VPN-1-has-reached-its-tunnel-capacity/m-p/13697#M327</guid>
      <dc:creator>Raymond_Poede</dc:creator>
      <dc:date>2017-11-22T10:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: vpn warning: VPN-1 has reached its tunnel capacity</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/vpn-warning-VPN-1-has-reached-its-tunnel-capacity/m-p/13698#M328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your VPN Tunnel Sharing setting under Advanced Properties in the VPN Community is probably set to "pair of hosts", which creates a unique Phase 2 IPSEC tunnel for every possible combination of hosts that try to use the VPN.&amp;nbsp; "Pair of subnets" is more appropriate; if that is already selected consider the "one tunnel per gateway pair" setting.&amp;nbsp; Be careful changing this setting though as it can have a wide impact on VPN connectivity, best to do it during a maintenance window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2017 15:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/vpn-warning-VPN-1-has-reached-its-tunnel-capacity/m-p/13698#M328</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-22T15:51:46Z</dc:date>
    </item>
  </channel>
</rss>

