<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling IKEv2 on Windows clients in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278264#M11464</link>
    <description>&lt;P&gt;I have the exact same question and went through our account rep's technical expert trying to come up with a solution but nothing so far. With the latest CVE, Check Point needs to do an emergency release of the Check Point Endpoint Security VPN for Windows with IKEv2 enabled by default (or at least put a way to enable it within the GUI). Expecting that all users/situations will have the ability to modify the registry is not acceptable.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 15:37:13 GMT</pubDate>
    <dc:creator>Aaron-pr</dc:creator>
    <dc:date>2026-06-10T15:37:13Z</dc:date>
    <item>
      <title>Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278258#M11463</link>
      <description>&lt;P&gt;So according to sk166415, to enable IKEv2 on Windows clients you need to make a registry change;&lt;/P&gt;
&lt;P&gt;configure disable_ikev2 to 0 in&amp;nbsp;&lt;SPAN&gt;HKLM\SOFTWARE\WOW6432Node\CheckPoint\TRAC, the reboot the device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is this the only way?&amp;nbsp; Can't be done via&amp;nbsp;trac_client_1.ttm? Or trac.config?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 15:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278258#M11463</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-10T15:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278264#M11464</link>
      <description>&lt;P&gt;I have the exact same question and went through our account rep's technical expert trying to come up with a solution but nothing so far. With the latest CVE, Check Point needs to do an emergency release of the Check Point Endpoint Security VPN for Windows with IKEv2 enabled by default (or at least put a way to enable it within the GUI). Expecting that all users/situations will have the ability to modify the registry is not acceptable.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 15:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278264#M11464</guid>
      <dc:creator>Aaron-pr</dc:creator>
      <dc:date>2026-06-10T15:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278292#M11465</link>
      <description>&lt;P&gt;Right now, the registry is the only way to enable IKEv2 on the Remote Access clients...which also disables IKEv1 support.&lt;BR /&gt;Hopefully this will be addressed soon.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 23:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278292#M11465</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-10T23:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278307#M11466</link>
      <description>&lt;P&gt;So does it means, that gateway has possibility "Prefer ikev2, support ikev1" but client has only one option ? ie "ikev2 only" or "ikev1 only" ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 07:42:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278307#M11466</guid>
      <dc:creator>Lubomir_Cerny</dc:creator>
      <dc:date>2026-06-11T07:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278345#M11467</link>
      <description>&lt;P&gt;That's what at least one report on the community suggested.&lt;BR /&gt;Additional confirmation would certainly be helpful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 18:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278345#M11467</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-11T18:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278378#M11469</link>
      <description>&lt;P&gt;As a workaround, I created a Compliance Rule under the policy (&lt;STRONG&gt;Application Control &amp;gt; Compliance &amp;amp; Posture &amp;gt; Compliance Rulebase&lt;/STRONG&gt;) to automatically validate and remediate the registry setting required for IKEv2.&lt;/P&gt;&lt;P&gt;The rule checks Windows endpoints and verifies the existence/value of the registry key:&lt;/P&gt;&lt;P&gt;HKLM\SOFTWARE\WOW6432Node\CheckPoint\TRAC\disable_ikev2&lt;/P&gt;&lt;P&gt;If the key is not configured as required, the Compliance Rule performs a remediation action, updating the registry value to:&lt;/P&gt;&lt;P&gt;disable_ikev2 = 0&lt;/P&gt;&lt;P&gt;Configuration details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Operating System: Windows All&lt;/LI&gt;&lt;LI&gt;Action Type: Applications/Files Check&lt;/LI&gt;&lt;LI&gt;Registry Check: Enabled&lt;/LI&gt;&lt;LI&gt;Registry Path: HKLM\SOFTWARE\WOW6432Node\CheckPoint\TRAC\disable_ikev2&lt;/LI&gt;&lt;LI&gt;Registry Value: 0&lt;/LI&gt;&lt;LI&gt;Action: Update&lt;/LI&gt;&lt;LI&gt;Registry Type: REG_DWORD&lt;/LI&gt;&lt;LI&gt;Validation: Check that the registry entry exists&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This approach avoids the need to manually modify the registry on each endpoint and provides centralized enforcement through the Compliance Blade. A reboot is still required for the endpoint to fully apply the IKEv2 configuration, as described in SK166415.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 14:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278378#M11469</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-06-12T14:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling IKEv2 on Windows clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278385#M11471</link>
      <description>&lt;P&gt;This or GPO is OK for internal users but can not be used for our external VPN users/contractors.&lt;BR /&gt;I hope future client versions will solve this.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 15:09:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enabling-IKEv2-on-Windows-clients/m-p/278385#M11471</guid>
      <dc:creator>Lubomir_Cerny</dc:creator>
      <dc:date>2026-06-12T15:09:45Z</dc:date>
    </item>
  </channel>
</rss>

