- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Mates,
Simple question here:
Is the permanent tunnel feature for a site-to-site VPN is enabled via GuiDBEdit, or am I missing something?
Hey brother,
No need, just enable it via tunnel management in community settings in smart console.
But I remembered that sometimes I saw it done in GuiDBEdit as well. Under what circumstances should this be done?
I believe ever since R80.30 or R80.40, its enabled automatically in guidbedit once you set it as permanent tunnel.
ok thank you brother, i'll double check also with TAC
Sure thing, though Im fairly positive thats the case.
And you can obviously also use the relevant Management API commands:
https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/add-vpn-community-meshed~v2.1%20
https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/set-vpn-community-star~v2.1%20
In R81, DPD became the default (i.e. not something you have to enable with guidbedit), as mentioned in Scenario 5 here: https://support.checkpoint.com/results/sk/sk108600
Not sure if this applies if the management was upgraded from a pre-R81 release or not.
In any case, you still have to enable "Permanent Tunnels" in the relevant VPN community.
Reading the admin guide here: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Con...
It appears that a Permanent Tunnel can only be established when both peers in the site-to-site VPN are Check Point gateways.
In cases where the peer is a non–Check Point gateway, it is necessary to enable PDP (Permanent Tunnel via DPD). From what I understand, this configuration seems to require enabling it through GuiDBEdit.
Insight from the guide:
Permanent Tunnels can only be established between Check Point Security Gateways.
Dead Peer Detection (DPD) is a different method to test if VPN tunnels are active. Dead Peer Detection does support third-party Security Gateways and supports permanent tunnels with interoperable devices based on IKEv1/IKEv2 DPD (IKEv1 DPD is based on RFC 3706).
To enable DPD monitoring:
On each VPN gateway in the VPN community, configure the tunnel_keepalive_method property, in Database Tool (GuiDBEdit Tool) or dbedit (see skI3301). This includes third-party gateways. (You cannot configure different monitor mechanisms for the same gateway).
In Database Tool (GuiDBEdit Tool), go to Network Objects > network_objects > <Name of Security Gateways object> > VPN.
For the Value, select a permanent tunnel mode.
Save all the changes.
Install the Access Control Policy.
Its true thats what it says, but in reality, it works fine with any other vendor and no need to change anything in guidbedit once you enable permanent tunnel setting.
Hey, bro,
So why does the administrative guide mention it? I don't get it.
Hello,
We have updated the Site-to-Site VPN Admin Guide, removed the GuiDBedit instructions and added a note:
|
Starting in R81.20, when you create the interoperable device object for the 3rd Party VPN gateway, DPD is automatically set as the permanent tunnel method. |
Thank you for your feedback.
Hi @Gil_Frantsus thank you!
Sounds like an area where the documentation might need to be updated.
Tagging @Sergei_Shir
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY