<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't Ping gateway IP of End VPN IP Address in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Can-t-Ping-gateway-IP-of-End-VPN-IP-Address/m-p/178652#M8776</link>
    <description>&lt;P&gt;Just to be clear, the IP address you're having trouble with is configured as a VPN peer in the Quantum Spark appliance, correct?&lt;BR /&gt;The Check Point gateway expects to send only encrypted traffic to the remote VPN IP address (i.e. it's included in the encryption domain).&lt;BR /&gt;If the remote end isn't configured appropriately, the traffic will fail as it is doing.&lt;BR /&gt;That's scenario 3 here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If your SMB is not managed externally with a Smart-1, you can still apply the changes mentioned in this SK in expert mode.&lt;BR /&gt;For the change to take effect, however, you will either need to reboot OR execute the command fw_configload and wait a few minutes.&lt;/P&gt;
&lt;P&gt;If that doesn't work, you can try and debug the VPN per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 20:48:16 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-20T20:48:16Z</dc:date>
    <item>
      <title>Can't Ping gateway IP of End VPN IP Address</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Can-t-Ping-gateway-IP-of-End-VPN-IP-Address/m-p/178321#M8741</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;Currently, I'm facing with the Ping and cannot access of another side Public IP address.&lt;/P&gt;&lt;P&gt;I have the IPsec configuration between Checkpoint Quantum 1550 Appliance to Palo alto Firewall 220. For the VPN tunnel and connection is working fine between both side. The problem is under of checkpoint office internet users are cannot ping and connect to another side of public IP address, which is create for using cisco AnyConnect VPN 202.80.78.168:444 for other purpose. These users are need to connect that 202.80.78.168:444 but can't access.&lt;/P&gt;&lt;P&gt;If we use the 1.1.1.1 cloud flare VPN software in users client pc of under checkpoint internet, they can access ping that public ip address and can access AnyConnect VPN with 202.80.78.168:444. without any other issues.&lt;/P&gt;&lt;P&gt;So, how can i solve my issues our client users want to access 202.80.78.168:444 without 1.1.1.1 vpn using.&lt;/P&gt;&lt;P&gt;Please kindly help investigate my issues, many thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Pyie Phyo Htay.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 04:16:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Can-t-Ping-gateway-IP-of-End-VPN-IP-Address/m-p/178321#M8741</guid>
      <dc:creator>pyiephyohtay</dc:creator>
      <dc:date>2023-04-18T04:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping gateway IP of End VPN IP Address</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Can-t-Ping-gateway-IP-of-End-VPN-IP-Address/m-p/178652#M8776</link>
      <description>&lt;P&gt;Just to be clear, the IP address you're having trouble with is configured as a VPN peer in the Quantum Spark appliance, correct?&lt;BR /&gt;The Check Point gateway expects to send only encrypted traffic to the remote VPN IP address (i.e. it's included in the encryption domain).&lt;BR /&gt;If the remote end isn't configured appropriately, the traffic will fail as it is doing.&lt;BR /&gt;That's scenario 3 here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If your SMB is not managed externally with a Smart-1, you can still apply the changes mentioned in this SK in expert mode.&lt;BR /&gt;For the change to take effect, however, you will either need to reboot OR execute the command fw_configload and wait a few minutes.&lt;/P&gt;
&lt;P&gt;If that doesn't work, you can try and debug the VPN per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 20:48:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Can-t-Ping-gateway-IP-of-End-VPN-IP-Address/m-p/178652#M8776</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-20T20:48:16Z</dc:date>
    </item>
  </channel>
</rss>

