<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKEv2 Remote Access guides? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/240918#M46729</link>
    <description>&lt;P&gt;According to this, we support IKEv2 as of E88.40:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166415" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk166415&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;However, it is not enabled by default and requires a registry hack to enable, which is why it isn't working with IKEv2 currently.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 23:35:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-03-04T23:35:12Z</dc:date>
    <item>
      <title>IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175061#M31894</link>
      <description>&lt;P&gt;We have a customer with a requirement to provide remote access connectivity using IKEv2 via the native operating system (no client) VPN supplicant (Windows, MacOS, possibly iOS and Android) and connect to Gateways&amp;nbsp; running R80.40.&amp;nbsp; Has anyone successfully done this and have any guides they'd be willing to share?&amp;nbsp; Figured out how to navigate the conflicting encryption/authentication methods between the various OSes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 01:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175061#M31894</guid>
      <dc:creator>MikeH</dc:creator>
      <dc:date>2023-03-16T01:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175079#M31899</link>
      <description>&lt;P&gt;No. No secure solution available - and R80.40 will be end of support in 8 months...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 09:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175079#M31899</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-16T09:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175081#M31900</link>
      <description>&lt;P&gt;Please refer to&amp;nbsp;&lt;SPAN&gt;sk166415 for the answer, which is "No, not at this moment". If you have a business case for this, please raise an RFE through the usual channels.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 09:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/175081#M31900</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-16T09:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224409#M43118</link>
      <description>&lt;P&gt;This SK is also valid for Gaia&amp;nbsp;embedded&amp;nbsp; right?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 19:55:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224409#M43118</guid>
      <dc:creator>lgarridor</dc:creator>
      <dc:date>2024-08-23T19:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224412#M43119</link>
      <description>&lt;P&gt;It's not explicitly listed, but it should apply there as well.&lt;BR /&gt;Note that the release notes for R82 EA explicitly lists IKEv2 support.&lt;BR /&gt;It also requires specific Endpoint client versions.&lt;/P&gt;
&lt;P&gt;R82 is planned for Embedded Gaia also.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 21:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224412#M43119</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-23T21:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224422#M43120</link>
      <description>&lt;P&gt;Interestingly, we find this in the release notes of R81.20 Take 70:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-White_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-White_Background"&gt;
&lt;P&gt;PRJ-48210,&lt;BR /&gt;PMTR-91011&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-White_Background"&gt;
&lt;P&gt;VPN&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-White_Background"&gt;
&lt;P&gt;IKEv2 Remote Access stability issues.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Sat, 24 Aug 2024 07:09:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224422#M43120</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-08-24T07:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224523#M43145</link>
      <description>&lt;P&gt;Yes, because some clients already use IKEv2:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Capsule VPN clients, which are largely wrappers around the built-in supplicants in the underlying OS, e.g. Windows).&lt;/LI&gt;
&lt;LI&gt;Strongswan for Linux, which has been supported since R81.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;R82 will add support for IKEv2 for our native (Windows, macOS) VPN clients.&lt;/P&gt;
&lt;P&gt;Whether you will be able to configure IKEv2 in e.g. Windows without Capsule VPN is a separate question.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 14:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/224523#M43145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-26T14:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/240904#M46727</link>
      <description>&lt;P&gt;Is there any update to this? I tried last week at CPX 2025 to get a definitive answer about this and hit a brick wall.&lt;BR /&gt;&lt;BR /&gt;I am using R82 in a lab environment. IKE v2 is enabled. Capsule Connect for IOS connects and uses IKE v2, but the latest Windows Remote Access VPN Client (Check Point Mobile) E88.60 Build 986105801 still does not support IKE v2.&lt;BR /&gt;&lt;BR /&gt;VPN connection is only possible when: "Prefer IKE v2, support IKE v1" is selected.&lt;/P&gt;&lt;P&gt;Capsule Connect for IOS connects and uses IKE v2 perfectly, but if "IKE 2 only" is selected, then the Windows VPN Client cannot connect.&amp;nbsp; The documentation says it is supported. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My R82 Gateway is using the following settings for Remote Access VPN:&lt;BR /&gt;&lt;BR /&gt;Phase 1: AES-256. SHA256, DH Group 21 (521-BIT ECP)&lt;BR /&gt;Phase 2: AES-256. SHA256.&lt;BR /&gt;&lt;BR /&gt;The above works perfectly, but only when IKE v1 is supported.&lt;BR /&gt;I've tried low encryption settings, but it makes no difference to the IKE issue.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/240904#M46727</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2025-02-11T14:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/240918#M46729</link>
      <description>&lt;P&gt;According to this, we support IKEv2 as of E88.40:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166415" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk166415&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;However, it is not enabled by default and requires a registry hack to enable, which is why it isn't working with IKEv2 currently.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 23:35:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/240918#M46729</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-04T23:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/242756#M47181</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;BR /&gt;&lt;BR /&gt;Thanks very much for publishing the solution.&lt;BR /&gt;&lt;BR /&gt;I can confirm that IKE v2 is now working with my R82 Lab setup using the Windows Remote Access VPN Client [E88.60] using the Registry modification&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;.&lt;BR /&gt;&lt;BR /&gt;I'm assuming a future release of the Windows Remote Access VPN Client will remove the need to make a manual Registry change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 00:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/242756#M47181</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2025-03-02T00:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/242833#M47190</link>
      <description>&lt;P&gt;I assume so, yes.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/242833#M47190</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-03T16:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/243453#M47300</link>
      <description>&lt;P&gt;Since testing the &lt;STRONG&gt;disable_ikev2&amp;nbsp;&lt;/STRONG&gt;Registry workaround with&amp;nbsp;&lt;STRONG&gt;Remote Access VPN Client for Windows&lt;/STRONG&gt;&amp;nbsp;version&amp;nbsp;&lt;STRONG&gt;E88.60 Build 986105801&lt;/STRONG&gt;, and confirming &lt;STRONG&gt;IKEv2&lt;/STRONG&gt;&amp;nbsp;did actually work, Check Point have now released the the &lt;STRONG&gt;Remote Access VPN Client for Windows&lt;/STRONG&gt; version&amp;nbsp;&lt;STRONG&gt;E88.63 Build 986105843 &lt;/STRONG&gt;- and unfortunately the &lt;STRONG&gt;disable_ikev2&lt;/STRONG&gt;&amp;nbsp;Registry workaround no longer works.&lt;/P&gt;&lt;P&gt;Update: 2025-03-11: The &lt;STRONG&gt;Remote Access VPN Client for Windows&lt;/STRONG&gt; version&amp;nbsp;&lt;STRONG&gt;E88.70 Build 986105912&lt;/STRONG&gt; doesn't work with the Registry workaround either. The only option is to re-enable the setting: &lt;STRONG&gt;Prefer IKEv2, support IKEv1&lt;/STRONG&gt; in Global Properties.&lt;/P&gt;&lt;P&gt;(The &lt;STRONG&gt;Remote Access VPN Client for Windows&lt;/STRONG&gt; is installed in &lt;STRONG&gt;Check Point Mobile Mode&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN connection fails with the message: &lt;STRONG&gt;The gateway does not support IKEv1&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;This is really disappointing.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Can Check Point's official roadmap be shared as to when IKEv2 will be fully supported in the Remote Access VPN Client for Windows?&lt;BR /&gt;&lt;BR /&gt;Also, just my observation, but why does the Remote Access VPN Client for Apple Mac seem to be getting all the attention, with major feature enhancements being released far sooner than the Windows version? In my experience, businesses have far greater dependencies on corporate Windows machines needing VPN access to the network, Mac's are rarely a priority in the corporate landscape.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 20:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/243453#M47300</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2025-03-11T20:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 Remote Access guides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/244111#M47508</link>
      <description>&lt;P&gt;I would report the issue with IKEv2 not working in the newer clients via TAC.&lt;/P&gt;
&lt;P&gt;We paused our normal Harmony Endpoint releases on Windows for a period of time to address some performance, stability, and resource utilization issues, which should be fixed in E88.70 (see also the upcoming TechTalk:&amp;nbsp;&lt;A href="https://checkpoint.zoom.us/webinar/register/7716236883663/WN_H8rPnR5ETkOxoDh9kEdnag" target="_blank"&gt;https://checkpoint.zoom.us/webinar/register/7716236883663/WN_H8rPnR5ETkOxoDh9kEdnag&lt;/A&gt;&amp;nbsp;)&amp;nbsp;&lt;BR /&gt;This impacts the standalone VPN clients also, which use the same code.&lt;BR /&gt;Meanwhile, we've had a couple of Harmony Endpoint releases on macOS (E89.01 being the most current).&lt;/P&gt;
&lt;P&gt;I expect the Windows version will "catch up" to the Mac version in the coming weeks.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 22:21:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKEv2-Remote-Access-guides/m-p/244111#M47508</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-18T22:21:52Z</dc:date>
    </item>
  </channel>
</rss>

