<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Phase 2 issues / Tunnel Per Subnet (invalid ID info) in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132435#M5956</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having difficulty working out how to proceed with this particular VPN set up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is between an 1800 device running R80.20.30 and a 3rd party non-Check Point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 1 has no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 2 fails on 'invalid ID information'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the 3rd party offers me 1 subnet only, and I change the remote encryption domain to that 1 subnet, the tunnel comes up instantly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When he offers more than 1 subnet, and equally I put these subnets in the enc domain, the tunnel fails with the error above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe if this was centrally managed/full Gaia, the solution would be to tick 'one vpn tunnel per subnet pair'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant find such an option on Gaia Embedded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also tried to create multiple VPN sites with a single subnet in each site, but you cant have multiple vpn sites with the same remote peer IP!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 14:24:00 GMT</pubDate>
    <dc:creator>JackPrendergast</dc:creator>
    <dc:date>2021-10-22T14:24:00Z</dc:date>
    <item>
      <title>VPN Phase 2 issues / Tunnel Per Subnet (invalid ID info)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132435#M5956</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having difficulty working out how to proceed with this particular VPN set up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is between an 1800 device running R80.20.30 and a 3rd party non-Check Point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 1 has no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 2 fails on 'invalid ID information'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the 3rd party offers me 1 subnet only, and I change the remote encryption domain to that 1 subnet, the tunnel comes up instantly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When he offers more than 1 subnet, and equally I put these subnets in the enc domain, the tunnel fails with the error above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe if this was centrally managed/full Gaia, the solution would be to tick 'one vpn tunnel per subnet pair'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant find such an option on Gaia Embedded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also tried to create multiple VPN sites with a single subnet in each site, but you cant have multiple vpn sites with the same remote peer IP!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 14:24:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132435#M5956</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-10-22T14:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Phase 2 issues / Tunnel Per Subnet (invalid ID info)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132515#M5957</link>
      <description>&lt;P&gt;Did you try:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14065i0918B99D32A53CBA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 01:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132515#M5957</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-25T01:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Phase 2 issues / Tunnel Per Subnet (invalid ID info)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132543#M5959</link>
      <description>&lt;P&gt;Well played PhoneBoy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great spot. Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 12:02:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Phase-2-issues-Tunnel-Per-Subnet-invalid-ID-info/m-p/132543#M5959</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-10-25T12:02:58Z</dc:date>
    </item>
  </channel>
</rss>

