<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: migrating remote access client to IKEv2 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279846#M11553</link>
    <description>&lt;P&gt;vpn tu list ike&lt;/P&gt;&lt;P&gt;Peer 10.131.32.254, user md5 d5d97eebc9c840d3:&lt;/P&gt;&lt;P&gt;Realm: vpn&lt;/P&gt;&lt;P&gt;Machine cert authentication: false&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IKEv2 SA &amp;lt;e9b394c9b4ac0872,d206797d57731d61&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunalty it works only once per client.&amp;nbsp;Each time the user disconnect and reconnect again, he didn't not succeed, until the connection IKEv2 SA timed out and "vpc tu tlist" is empty for this user. Otherwise in our testing environment, we reboot the gateway and afterwards it works again, but only once.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TAC case is open&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2026 13:49:05 GMT</pubDate>
    <dc:creator>PeterH</dc:creator>
    <dc:date>2026-07-17T13:49:05Z</dc:date>
    <item>
      <title>migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278802#M11482</link>
      <description>&lt;P&gt;So we want to move or client from using IKEv1 to v2.&lt;/P&gt;
&lt;P&gt;On the gateways we've selected Prefer IKEv2, support IKEv1.&lt;/P&gt;
&lt;P&gt;We've started pushing registry changes to set disable_ikev2 to 0. I can't seem to find a way to verify if people connect with IKEv1 or v2.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn tu tlist doesn't show that info. I tried&amp;nbsp;fw tab -t userc_key -f and it shows Schema: IKE(3). Anyone knows what IKE(3) means?&lt;/P&gt;
&lt;P&gt;Or any other way to show which IKE version clients are using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 15:20:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278802#M11482</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-22T15:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278824#M11484</link>
      <description>&lt;P&gt;I believe it will show in the log entry when the user connects.&lt;BR /&gt;That said, I've seen reports that suggest the registry change on clients will cause the clients to use IKEv2 only.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 22:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278824#M11484</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-22T22:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278937#M11486</link>
      <description>&lt;P&gt;Indeed try to filter with:&amp;nbsp;action:Connect AND "Remote Access" or&amp;nbsp;action:Login AND "Remote Access"&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278937#M11486</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-24T19:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278938#M11487</link>
      <description>&lt;P&gt;I can filter with&amp;nbsp;action:"Log In" AND blade:"Mobile Access". All I see in the details is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data Protocol IPSec&lt;/P&gt;
&lt;P&gt;Data Encryption AES-256 + SHA256 + Group 14, Certificate&lt;/P&gt;
&lt;P&gt;Nothing about IKEv1 or v2&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278938#M11487</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-24T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278939#M11488</link>
      <description>&lt;P&gt;can I have a vpn tu tlist output of a few clients? Just remove the external IP info, dont need that.&lt;/P&gt;
&lt;P&gt;Also anything in cpview? There should a global counter for ikev1 and ikve2 tunnels to give you a global idea what is mostly used&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278939#M11488</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-24T19:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278940#M11489</link>
      <description>&lt;P&gt;Didn't think to look at cpview. It does show the Concurrent IKEv1 SAs and IKEv2 SAs.&lt;/P&gt;
&lt;P&gt;Unfortunately for me IKEv2 SAs shows 0.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So with the gateway set to&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Prefer IKEv2, support IKEv1 and the registry change on the client it' s still using IKEv1. Or it fails IKEv2 and reverts to v1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:46:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278940#M11489</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-24T19:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279146#M11494</link>
      <description>&lt;P&gt;Yes, indeed to be found at cpview: software-blades &amp;gt; VPN &amp;gt; Overview&lt;/P&gt;&lt;P&gt;An additional indicator could be the FW log for 'action:"Key Install" which is showing information like:&lt;BR /&gt;VPN Feature: IKE&lt;/P&gt;&lt;P&gt;or in section "More":&lt;BR /&gt;Ike: Quick Mode completion (which is in indicator for IKEv1) as there ain't no Quick Mode on IKEv2.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 10:54:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279146#M11494</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-07-01T10:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279846#M11553</link>
      <description>&lt;P&gt;vpn tu list ike&lt;/P&gt;&lt;P&gt;Peer 10.131.32.254, user md5 d5d97eebc9c840d3:&lt;/P&gt;&lt;P&gt;Realm: vpn&lt;/P&gt;&lt;P&gt;Machine cert authentication: false&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IKEv2 SA &amp;lt;e9b394c9b4ac0872,d206797d57731d61&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunalty it works only once per client.&amp;nbsp;Each time the user disconnect and reconnect again, he didn't not succeed, until the connection IKEv2 SA timed out and "vpc tu tlist" is empty for this user. Otherwise in our testing environment, we reboot the gateway and afterwards it works again, but only once.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TAC case is open&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 13:49:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279846#M11553</guid>
      <dc:creator>PeterH</dc:creator>
      <dc:date>2026-07-17T13:49:05Z</dc:date>
    </item>
  </channel>
</rss>

