<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec Problem between Libreswan 4.12 and Check Point Gateway in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199796#M9926</link>
    <description>&lt;P&gt;This is most likely going to require TAC assistance and gathering the following debug:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 19:41:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-12-05T19:41:23Z</dc:date>
    <item>
      <title>IPsec Problem between Libreswan 4.12 and Check Point Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199771#M9925</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having trouble keeping an IPSec tunnel online, in Linux the ESP packets are dropped and it's necessary to restart the tunnel to get it working again.&lt;BR /&gt;My libreswan is on version 4.12 and the SMB Spark 1800 appliance is on R81.10.08.&lt;/P&gt;&lt;P&gt;Can Someone help me?&lt;/P&gt;&lt;P&gt;Below is tcpdump done on Linux:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;11:48:24.687794 ens192 In &amp;nbsp;IP 1xx.xxx.xxx.3 &amp;gt; 1xx.xxx.xxx.15: ESP(spi=0x1c25b9af,seq=0xd6), length 100&lt;BR /&gt;11:48:29.680462 ens192 In &amp;nbsp;IP 1xx.xxx.xxx.3 &amp;gt; 1xx.xxx.xxx.15: ESP(spi=0x1c25b9af,seq=0xd7), length 100&lt;BR /&gt;11:48:34.687092 ens192 In &amp;nbsp;IP 1xx.xxx.xxx.3 &amp;gt; 1xx.xxx.xxx.15: ESP(spi=0x1c25b9af,seq=0xd8), length 100&lt;BR /&gt;11:48:39.686347 ens192 In &amp;nbsp;IP 1xx.xxx.xxx.3 &amp;gt; 1xx.xxx.xxx.15: ESP(spi=0x1c25b9af,seq=0xd9), length 100&lt;BR /&gt;11:48:44.692785 ens192 In &amp;nbsp;IP 1xx.xxx.xxx.3 &amp;gt; 1xx.xxx.xxx.15: ESP(spi=0x1c25b9af,seq=0xda), length 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Linux config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;conn x0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ike=aes-sha-modp1536&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; keyexchange=ike&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ikev2=no&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; aggrmode=no&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; keyingtries=3&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type=tunnel&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; authby=secret&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; leftid=1xx.xxx.xxx.15&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; left=%defaultroute&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; esp=aes-sha&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ikelifetime=8h&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; salifetime=1h&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; auto=start&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pfs=no&lt;BR /&gt;&lt;BR /&gt;conn x1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; also=x0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; leftsubnet=xxx.xxx.xx.xxx/xx&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rightsubnet=xxx.xxx.xx.xxx/xx&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; right=1xx.xxx.xxx.3&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Config Check Point Gw in attach&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199771#M9925</guid>
      <dc:creator>Frank_Aguilieri</dc:creator>
      <dc:date>2023-12-05T15:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Problem between Libreswan 4.12 and Check Point Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199796#M9926</link>
      <description>&lt;P&gt;This is most likely going to require TAC assistance and gathering the following debug:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 19:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199796#M9926</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-05T19:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Problem between Libreswan 4.12 and Check Point Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199801#M9927</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 20:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPsec-Problem-between-Libreswan-4-12-and-Check-Point-Gateway/m-p/199801#M9927</guid>
      <dc:creator>Frank_Aguilieri</dc:creator>
      <dc:date>2023-12-05T20:04:18Z</dc:date>
    </item>
  </channel>
</rss>

