<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN S2S from CP 1550 to FG 30E not PING in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118376#M5191</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a configured and active VPN tunnel between CP 1550 and FG 30E (VPN Site to Site)&lt;/P&gt;&lt;P&gt;The tunnel is active with FG I can ping and access the network on the Checkpoint side. However, I cannot ping from Chackpoint to Fortigate.&lt;/P&gt;&lt;P&gt;I attach entries in the firewall in the post.&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 10:23:21 GMT</pubDate>
    <dc:creator>luk89as</dc:creator>
    <dc:date>2021-05-14T10:23:21Z</dc:date>
    <item>
      <title>VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118376#M5191</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a configured and active VPN tunnel between CP 1550 and FG 30E (VPN Site to Site)&lt;/P&gt;&lt;P&gt;The tunnel is active with FG I can ping and access the network on the Checkpoint side. However, I cannot ping from Chackpoint to Fortigate.&lt;/P&gt;&lt;P&gt;I attach entries in the firewall in the post.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 10:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118376#M5191</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-05-14T10:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118378#M5192</link>
      <description>&lt;P&gt;Why the second Outgoing Rule - Source behind FG target CP ??? And i see no rules defined in incoming &amp;amp;&amp;nbsp;VPN traffic, so i wonder how this should work ?&lt;/P&gt;
&lt;P&gt;I would just follow &lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.25 Locally Managed Administration Guide pp.26ff !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 10:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118378#M5192</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-14T10:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118381#M5193</link>
      <description>&lt;P&gt;I'm sending an additional screen.&lt;/P&gt;&lt;P&gt;I don't know how to set up static routing from CP1550 to VPN.&lt;/P&gt;&lt;P&gt;I don't know VPN in static routing settings - next hop&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 11:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118381#M5193</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-05-14T11:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118383#M5194</link>
      <description>&lt;P&gt;Just follow the admin guide - i think your manual rules are wrong... Usually, no manual routing is needed as we have a VPN community.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 11:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118383#M5194</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-14T11:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118389#M5195</link>
      <description>&lt;P&gt;This is part of my rulebase from 1550, Policy normal, VPN working:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn.png" style="width: 958px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11689iC91BA63DEC3CC521/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn.png" alt="vpn.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 13:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118389#M5195</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-14T13:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118391#M5196</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As you saw on the screen sent by me, I have the same rules.&lt;/P&gt;&lt;P&gt;With time, I added manually the ones that you can see.&lt;/P&gt;&lt;P&gt;Since I can ping from the FG 30E side, the Checkpoint network (I have access to LAN) insists that IKE Phase 1 and Phase 2 are ok on both sides.&lt;/P&gt;&lt;P&gt;It looks like the CP 1550 is not letting traffic into the VPN tunnel from its LAN, although the LOGs show that traffic is entering the tunnel but no response.&lt;/P&gt;&lt;P&gt;I also don't understand that I am getting an error on my VPN test.&lt;/P&gt;&lt;P&gt;If I had an error in IKE Phase 1 or Phase 2 configuration, the connection would not be active and I certainly wouldn't be able to get from the FG 30E LAN to the CP 1550 network.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 13:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118391#M5196</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-05-14T13:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118409#M5199</link>
      <description>&lt;P&gt;When the Check Point attempts to initiate the tunnel to Fortigate the proposed subnets/Proxy-IDs in IKEv1 Phase 2 must PRECISELY match how the Fortigate is configured, whereas if the Fortigate initiates the tunnel the Check Point will accept a subset of the Phase 2 subnets in lieu of a precise match and still allow the VPN tunnel to start.&amp;nbsp; There have been numerous prior CheckMates threads about this, see scenario #1 of&amp;nbsp;&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener noreferrer"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 17:42:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/118409#M5199</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-14T17:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122712#M5363</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So I have to execute the command in the console: disabling the R80.20 "disable supernetting per community&lt;/P&gt;&lt;P&gt;---&lt;BR /&gt;This new feature will still work once ike_enable_supernet is set to "true".&lt;/P&gt;&lt;P&gt;Access the relevant gateway.&lt;BR /&gt;Run fw ctl set int enable_supernet_per_community 0&lt;BR /&gt;Note: It can take some time until user.def tables start to take effect, as current connections can still invoke tunnels using the old ranges.&lt;/P&gt;&lt;P&gt;In order to save this change after reboot of the gateway, set this configuration variable: "enable_supernet_per_community = 0" in the $ FWDIR / boot / modules / fwkern.conf file of the gateway.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;This also applies to my firmware&lt;/P&gt;&lt;P&gt;R80.20.20 (992001869)&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 12:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122712#M5363</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-07-01T12:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122719#M5366</link>
      <description>&lt;P&gt;There is also an Advanced Setting that may help:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="subnets.png" style="width: 804px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12395iE0CA9A749AEF953E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="subnets.png" alt="subnets.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 13:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122719#M5366</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-07-01T13:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122724#M5367</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The setting you suggest is already running. It didn't change anything.&lt;/P&gt;&lt;P&gt;I still have FG to CP traffic but no CP to FG traffic.&lt;/P&gt;&lt;P&gt;Could I only have the option to edit the crypt.def file and change the ike_enable_supernet is set parameter to "true".&lt;/P&gt;&lt;P&gt;Will I do it via the console? However, am I forced to set up a GAIA server?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 13:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122724#M5367</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-07-01T13:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122727#M5368</link>
      <description>&lt;P&gt;No, you have to uncheck the option ! This is the default and makes trouble with some 3rd party GWs...&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 14:22:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122727#M5368</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-07-01T14:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122736#M5369</link>
      <description>&lt;P&gt;I turned off the option according to your recommendation, but still unchanged.&lt;/P&gt;&lt;P&gt;Network traffic from FG to CP - works&lt;/P&gt;&lt;P&gt;Network traffic from CP to FG - not working&lt;/P&gt;&lt;P&gt;When performing the test, I still get the error: Conecction to remote site filed&lt;/P&gt;&lt;P&gt;Do you have any more ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 15:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122736#M5369</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2021-07-01T15:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122737#M5370</link>
      <description>&lt;P&gt;Read my last post again.&amp;nbsp; The IKE Phase 2 subnet proposals from the CP must exactly match those on the Fortigate or it will silently discard your Phase 2 proposal and appear to not be responding.&amp;nbsp; You need to set&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;subnet_for_range_and_peer.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 15:51:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122737#M5370</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-01T15:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S from CP 1550 to FG 30E not PING</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122885#M5371</link>
      <description>&lt;P&gt;The only way forward is to contact TAC to resolve this issue - locally managed SMBs can not set&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;subnet_for_range_and_peer&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;in user.def. You can try crypt.def, but it does not contain these lines:&lt;/P&gt;
&lt;PRE&gt;#ifndef __user_def__
#define __user_def__

//
// User defined INSPECT code
//

#endif /* __user_def__ */&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 16:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-from-CP-1550-to-FG-30E-not-PING/m-p/122885#M5371</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-07-03T16:41:55Z</dc:date>
    </item>
  </channel>
</rss>

