<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN traffic getting blocked in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155250#M7244</link>
    <description>&lt;P&gt;HI&lt;BR /&gt;Im getting this problem,&lt;/P&gt;&lt;P&gt;Source: Print Server(172.20.15.52)&lt;/P&gt;&lt;P&gt;Dest: Printer(192.168.15.210)&lt;/P&gt;&lt;P&gt;Src and Dst are under a Site to site VPN.&lt;/P&gt;&lt;P&gt;I have checked the logs. I have attached the logs. What might be the issue ?&lt;/P&gt;&lt;P&gt;there are other log which seeems to be allowed check 4.log image&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Firewall: Checkpoint SMB Appliance 910&lt;/DIV&gt;&lt;DIV class=""&gt;Firemware: R77.30&lt;/DIV&gt;</description>
    <pubDate>Fri, 19 Aug 2022 06:05:22 GMT</pubDate>
    <dc:creator>faheb1</dc:creator>
    <dc:date>2022-08-19T06:05:22Z</dc:date>
    <item>
      <title>VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155250#M7244</link>
      <description>&lt;P&gt;HI&lt;BR /&gt;Im getting this problem,&lt;/P&gt;&lt;P&gt;Source: Print Server(172.20.15.52)&lt;/P&gt;&lt;P&gt;Dest: Printer(192.168.15.210)&lt;/P&gt;&lt;P&gt;Src and Dst are under a Site to site VPN.&lt;/P&gt;&lt;P&gt;I have checked the logs. I have attached the logs. What might be the issue ?&lt;/P&gt;&lt;P&gt;there are other log which seeems to be allowed check 4.log image&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Firewall: Checkpoint SMB Appliance 910&lt;/DIV&gt;&lt;DIV class=""&gt;Firemware: R77.30&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Aug 2022 06:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155250#M7244</guid>
      <dc:creator>faheb1</dc:creator>
      <dc:date>2022-08-19T06:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155257#M7245</link>
      <description>&lt;P&gt;2.logs.png shows an IKE failure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is other traffic working trough that VPN tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 07:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155257#M7245</guid>
      <dc:creator>Piet_vd_Maas</dc:creator>
      <dc:date>2022-08-19T07:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155258#M7246</link>
      <description>&lt;P&gt;I have seen one log that icmp/ping is working. but cant find the log now.&lt;/P&gt;&lt;P&gt;Besides, Log4 image shows that some traffic is flowing. however, majority is getting block for that destination. What should i check ? recently the PeerGateway ip was changed. after that we are having this problem.&amp;nbsp; My client tried traceroute from his ip&lt;/P&gt;&lt;P&gt;Source: 172.20.15.76&lt;/P&gt;&lt;P&gt;Fw LAN : 192.168.50.54 (Form Core Switch)&lt;/P&gt;&lt;P&gt;C:\Users\scanpp&amp;gt;tracert 192.168.15.210&lt;/P&gt;&lt;P&gt;Tracing route to 192.168.15.210 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;1 1 ms 2 ms 1 ms 172.20.15.1&lt;BR /&gt;2 &amp;lt;1 ms * * 172.20.15.2 (Core Switch)&lt;BR /&gt;3 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 192.168.50.54 --- FW&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 * * * Request timed out.&lt;BR /&gt;6 * * * Request timed out.&lt;BR /&gt;7 * * * Request timed out.&lt;BR /&gt;8 * * * Request timed out.&lt;BR /&gt;9 * * * Request timed out.&lt;BR /&gt;10 * * * Request timed out.&lt;BR /&gt;11 * * * Request timed out.&lt;BR /&gt;12&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 07:21:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155258#M7246</guid>
      <dc:creator>faheb1</dc:creator>
      <dc:date>2022-08-19T07:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155259#M7247</link>
      <description>&lt;P&gt;[Expert@ScanConnectFW02]# vpn tu&lt;/P&gt;&lt;P&gt;********** Select Option **********&lt;/P&gt;&lt;P&gt;(1) List all IKE SAs&lt;BR /&gt;(2) List all IPsec SAs&lt;BR /&gt;(3) List all IKE SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(4) List all IPsec SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(5) Delete all IPsec SAs for a given peer (GW)&lt;BR /&gt;(6) Delete all IPsec SAs for a given User (Client)&lt;BR /&gt;(7) Delete all IPsec+IKE SAs for a given peer (GW)&lt;BR /&gt;(8) Delete all IPsec+IKE SAs for a given User (Client)&lt;BR /&gt;(9) Delete all IPsec SAs for ALL peers and users&lt;BR /&gt;(0) Delete all IPsec+IKE SAs for ALL peers and users&lt;/P&gt;&lt;P&gt;(Q) Quit&lt;/P&gt;&lt;P&gt;*******************************************&lt;/P&gt;&lt;P&gt;4&lt;/P&gt;&lt;P&gt;Enter IP of peer (format: xxx.xxx.xxx.xxx): A.A.A.A&lt;/P&gt;&lt;P&gt;Peer A.A.A.A SAs:&lt;/P&gt;&lt;P&gt;1. SPI's related to IKE SA &amp;lt;20012e163a402797,684343b0201ad46e&amp;gt;:&lt;/P&gt;&lt;P&gt;2. SPI's related to IKE SA &amp;lt;24e22e54dfdc23ea,74aa4a4a736e535f&amp;gt;:&lt;/P&gt;&lt;P&gt;3. SPI's related to IKE SA &amp;lt;d27a77ee1af9ceda,73239d6b0a6514c3&amp;gt;:&lt;/P&gt;&lt;P&gt;4. SPI's related to IKE SA &amp;lt;72b61a621efe15d6,26f908e01a73194f&amp;gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hit &amp;lt;Enter&amp;gt; key to continue ...&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 07:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155259#M7247</guid>
      <dc:creator>faheb1</dc:creator>
      <dc:date>2022-08-19T07:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155261#M7248</link>
      <description>&lt;P&gt;Phase2 doesn't seem to be completed. Can you check logs between the two public addresses (of the vpn peers) to see the VPN negotiation?&lt;/P&gt;&lt;P&gt;Confirm the P2 configuration on both sides and confirm the networks are also the same on both sides. Also confirm you have security rules on your side for that traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:08:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155261#M7248</guid>
      <dc:creator>AndréTinoco</dc:creator>
      <dc:date>2022-08-19T08:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155380#M7262</link>
      <description>&lt;P&gt;Is your issue solved?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 07:18:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155380#M7262</guid>
      <dc:creator>Piet_vd_Maas</dc:creator>
      <dc:date>2022-08-22T07:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155417#M7268</link>
      <description>&lt;P&gt;I have used Ikeview and found that Phase-1(P1 Main mode) ok but Phase2 QM Packet-1 has errors. I have asked the remote Gateway admin to share the config. Need to cross check if there are any changes in their side config.&lt;/P&gt;&lt;P&gt;Can someone tell me Why Egress traffic are failing but Ingress traffic is getting in ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 12:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155417#M7268</guid>
      <dc:creator>faheb1</dc:creator>
      <dc:date>2022-08-22T12:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155449#M7270</link>
      <description>&lt;P&gt;Phase 2 is in my experience always an issue with vpn domains not being presented properly or supernatting. Make sure that remote gateway interoperable object is set with right encryption domain.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 16:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155449#M7270</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T16:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155456#M7271</link>
      <description>&lt;P&gt;Sounds like a routing issue indeed.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/77776"&gt;@faheb1&lt;/a&gt;&amp;nbsp;you also mentioned the issues started after a IP change of the peer gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:48:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155456#M7271</guid>
      <dc:creator>Piet_vd_Maas</dc:creator>
      <dc:date>2022-08-22T17:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN traffic getting blocked</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155485#M7273</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Checked the routing. Found a problem . It seems like a typo. I have fixed it. Need to check it tomorrow by client. VPN shows up. I will let you know the result.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 07:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-traffic-getting-blocked/m-p/155485#M7273</guid>
      <dc:creator>faheb1</dc:creator>
      <dc:date>2022-08-23T07:40:21Z</dc:date>
    </item>
  </channel>
</rss>

