<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173020#M8345</link>
    <description>&lt;P&gt;We are trying with keeping the IKE SAs and observing the tunnel for the next several hours. Finger crossed.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 14:58:06 GMT</pubDate>
    <dc:creator>Hsanity</dc:creator>
    <dc:date>2023-02-28T14:58:06Z</dc:date>
    <item>
      <title>Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172819#M8331</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We have been experiencing an unstable VPN connection at one of our sites. VPN tunnels randomly go down. Looking at the log in the web portal shows "Peer closed connection" and "The peer is no longer responding" between the gateways. We can also see logs like "Informational Exchange Received Delete IPSEC-SA from Peer" coming from the remote gateway. Following is an example of one of the events:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Eventlog_VPN_tunnel_drop_and_restablishment.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19807i952F3DF88F7B29B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Eventlog_VPN_tunnel_drop_and_restablishment.png" alt="Eventlog_VPN_tunnel_drop_and_restablishment.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looking at ike.elg log file indicates towards lots of INVALID-COOKIE before and after phase 1 and phase 2 ike negotiation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="INVALID-COOKIE.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19808iEB2D4506DF842A38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="INVALID-COOKIE.png" alt="INVALID-COOKIE.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting steps taken:&lt;BR /&gt;1. Cross-checked VPN site settings on both ends&lt;BR /&gt;2. Delete and recreate VPN sites on both ends&lt;BR /&gt;3. Increased WAN bandwidth from ISP&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SMB gateway: 1450 Appliance | Version: R77.20.75 (990172321)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 12:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172819#M8331</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-02-27T12:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172913#M8332</link>
      <description>&lt;P&gt;Before spending too much time troubleshooting this, I recommend upgrading to the latest firmware.&lt;BR /&gt;The most recent can be obtained from here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk153433" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk153433&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 23:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172913#M8332</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-27T23:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172916#M8334</link>
      <description>&lt;P&gt;Make sure "keep ike SAs" in global properties is enabled.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 23:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172916#M8334</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-27T23:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172982#M8338</link>
      <description>&lt;P&gt;We are running our gateways with local management. Is it possible to check and enable "keep ike SAs" without a management server?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 11:04:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172982#M8338</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-02-28T11:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172989#M8339</link>
      <description>&lt;P&gt;Why ? See explanation in sk142355: Enabling this parameter changes the behavior so that the Security Gateway keeps all Phase 1 and Phase 2 keys after a policy installation to work around interoperability issues with 3rd party VPN peers.&lt;/P&gt;
&lt;P&gt;I do not see any issue after policy installation mentioned here...&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:42:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172989#M8339</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-28T12:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172991#M8340</link>
      <description>&lt;P&gt;Best next steps:&lt;/P&gt;
&lt;P&gt;- upgrade to latest firmware&lt;/P&gt;
&lt;P&gt;- if the issue persists contact TAC&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 12:48:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172991#M8340</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-28T12:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172993#M8341</link>
      <description>&lt;P&gt;Not that I know of...I believe that option is only available as per below (from smart console):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19831i13C374A491EFE288/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:20:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/172993#M8341</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-28T14:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173017#M8342</link>
      <description>&lt;P&gt;Thank you. For local management, I found it under Device &amp;gt; Advanced Settings &amp;gt; VPN Site to Site global settings - Keep IKE SA Keys.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173017#M8342</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-02-28T14:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173018#M8343</link>
      <description>&lt;P&gt;Good stuff, learned something new today. So any way to tell if it helps or it may take some time?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173018#M8343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-28T14:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173019#M8344</link>
      <description>&lt;P&gt;Are you planning to upgrade to R77.20.87 JHF ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173019#M8344</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-28T14:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173020#M8345</link>
      <description>&lt;P&gt;We are trying with keeping the IKE SAs and observing the tunnel for the next several hours. Finger crossed.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:58:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173020#M8345</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-02-28T14:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173022#M8346</link>
      <description>&lt;P&gt;Honestly, even if that works, I would still upgrade to latest version available. It never hurts to do that with these SMB appliances, it can only help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173022#M8346</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-28T14:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173023#M8347</link>
      <description>&lt;P&gt;Unfortunately, my user account does not have enough privileges to download the hotfix that &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; suggested. Logged a separate support on this. Awaiting response.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 15:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173023#M8347</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-02-28T15:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173053#M8352</link>
      <description>&lt;P&gt;Yes, because your account must be associated with a support agreement.&lt;BR /&gt;This is required to download most things from UserCenter.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 17:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173053#M8352</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-28T17:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173054#M8353</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70716"&gt;@Hsanity&lt;/a&gt;&amp;nbsp;...any luck with changes made?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 18:01:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173054#M8353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-28T18:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173105#M8356</link>
      <description>&lt;P&gt;There were still tunnel drops after switching to keep ike SAs. But After upgrading to the latest JHF | fw1_sx_dep_R77_990173120_20.img, haven't had a single tunnel drop in the last 12 hours. This looks promising! But I must say, We have about fifteen other 1450 firewalls that have VPN tunnels to the same central site and this is the only gateway causing issues without the JHF. Thanks so much for the file &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 07:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173105#M8356</guid>
      <dc:creator>Hsanity</dc:creator>
      <dc:date>2023-03-01T07:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173116#M8357</link>
      <description>&lt;P&gt;As i wrote above: Afaik and refering to sk142355, your issue has nothing to do with Keep IKE SAs...&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173116#M8357</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-01T08:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173141#M8358</link>
      <description>&lt;P&gt;They all need upgrading in that case as R77.20.75 has been End-of-support for almost 3-years already.&lt;/P&gt;
&lt;P&gt;Refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/" target="_blank"&gt;https://www.checkpoint.com/support-services/support-life-cycle-policy/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 09:59:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173141#M8358</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-01T09:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable VPN tunnel between two checkpoint firewalls; ike log indicates INVALID-COOKIE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173145#M8359</link>
      <description>&lt;P&gt;Glad it helped you.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 10:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Unstable-VPN-tunnel-between-two-checkpoint-firewalls-ike-log/m-p/173145#M8359</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T10:46:10Z</dc:date>
    </item>
  </channel>
</rss>

