<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN problems - Invalid ID in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161433#M7708</link>
    <description>&lt;P&gt;First, which version of the GW software and hardware are you using?&lt;BR /&gt;&lt;BR /&gt;IKE VPN ID is a combination of peer IP and its VPN domain. It has to be identical for both parties. If there is a mismatch, you will not be able to open a tunnel.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 13:08:30 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-11-07T13:08:30Z</dc:date>
    <item>
      <title>VPN problems - Invalid ID</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161362#M7691</link>
      <description>&lt;P&gt;Hello every one&lt;BR /&gt;&lt;BR /&gt;I can't get up the vpn between two gateways, checking the logs it says "Notification to Peer: invalid id information". I don't understand what it mean by id. Also, the IKE Responder Cookie and Initiator are different. Could it be because of that?&lt;/P&gt;&lt;P&gt;Does anyone know what Invalid id information refers to? and what causes it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2022 16:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161362#M7691</guid>
      <dc:creator>Engii</dc:creator>
      <dc:date>2022-11-06T16:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN problems - Invalid ID</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161433#M7708</link>
      <description>&lt;P&gt;First, which version of the GW software and hardware are you using?&lt;BR /&gt;&lt;BR /&gt;IKE VPN ID is a combination of peer IP and its VPN domain. It has to be identical for both parties. If there is a mismatch, you will not be able to open a tunnel.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161433#M7708</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-07T13:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN problems - Invalid ID</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161434#M7709</link>
      <description>&lt;P&gt;Most likely phase 2 mismatch somewhere. I would follow below sk:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115455" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115455&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also, on top of that, make sure below 3 settings are set to FALSE in Guidbedit:&lt;/P&gt;
&lt;P&gt;ike_enable_supernet&lt;BR /&gt;ike_p2_enable_supernet_from_R80.20&lt;BR /&gt;ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P&gt;I recall even if really old versions of CP, this was an issue where CP always tried to present larger subnet than intended, so say if Cisco is expecting, for example, /28 subnet, CP would have tried to send something bigger, for example/24.&lt;/P&gt;
&lt;P&gt;Anyway, had not seen much of that since R80 came out initially, but I would still verify those values.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-problems-Invalid-ID/m-p/161434#M7709</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-07T13:19:19Z</dc:date>
    </item>
  </channel>
</rss>

