<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: migrating remote access client to IKEv2 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282686#M11663</link>
    <description>&lt;P&gt;Well, I am not sure that XAUTH is an exclusive indicator for using IKEv2. Afaik it reflects Cross Authentication methods like MFA relying on a third party authentication or MFA connected backend (i.e. certificates/PKI, RADIUS, etc.)&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2026 08:31:56 GMT</pubDate>
    <dc:creator>dunkelmorten</dc:creator>
    <dc:date>2026-09-23T08:31:56Z</dc:date>
    <item>
      <title>migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278802#M11482</link>
      <description>&lt;P&gt;So we want to move or client from using IKEv1 to v2.&lt;/P&gt;
&lt;P&gt;On the gateways we've selected Prefer IKEv2, support IKEv1.&lt;/P&gt;
&lt;P&gt;We've started pushing registry changes to set disable_ikev2 to 0. I can't seem to find a way to verify if people connect with IKEv1 or v2.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn tu tlist doesn't show that info. I tried&amp;nbsp;fw tab -t userc_key -f and it shows Schema: IKE(3). Anyone knows what IKE(3) means?&lt;/P&gt;
&lt;P&gt;Or any other way to show which IKE version clients are using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 15:20:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278802#M11482</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-22T15:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278824#M11484</link>
      <description>&lt;P&gt;I believe it will show in the log entry when the user connects.&lt;BR /&gt;That said, I've seen reports that suggest the registry change on clients will cause the clients to use IKEv2 only.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 22:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278824#M11484</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-22T22:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278937#M11486</link>
      <description>&lt;P&gt;Indeed try to filter with:&amp;nbsp;action:Connect AND "Remote Access" or&amp;nbsp;action:Login AND "Remote Access"&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278937#M11486</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-24T19:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278938#M11487</link>
      <description>&lt;P&gt;I can filter with&amp;nbsp;action:"Log In" AND blade:"Mobile Access". All I see in the details is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data Protocol IPSec&lt;/P&gt;
&lt;P&gt;Data Encryption AES-256 + SHA256 + Group 14, Certificate&lt;/P&gt;
&lt;P&gt;Nothing about IKEv1 or v2&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278938#M11487</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-24T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278939#M11488</link>
      <description>&lt;P&gt;can I have a vpn tu tlist output of a few clients? Just remove the external IP info, dont need that.&lt;/P&gt;
&lt;P&gt;Also anything in cpview? There should a global counter for ikev1 and ikve2 tunnels to give you a global idea what is mostly used&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278939#M11488</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-24T19:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278940#M11489</link>
      <description>&lt;P&gt;Didn't think to look at cpview. It does show the Concurrent IKEv1 SAs and IKEv2 SAs.&lt;/P&gt;
&lt;P&gt;Unfortunately for me IKEv2 SAs shows 0.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So with the gateway set to&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Prefer IKEv2, support IKEv1 and the registry change on the client it' s still using IKEv1. Or it fails IKEv2 and reverts to v1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 19:46:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/278940#M11489</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-06-24T19:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279146#M11494</link>
      <description>&lt;P&gt;Yes, indeed to be found at cpview: software-blades &amp;gt; VPN &amp;gt; Overview&lt;/P&gt;&lt;P&gt;An additional indicator could be the FW log for 'action:"Key Install" which is showing information like:&lt;BR /&gt;VPN Feature: IKE&lt;/P&gt;&lt;P&gt;or in section "More":&lt;BR /&gt;Ike: Quick Mode completion (which is in indicator for IKEv1) as there ain't no Quick Mode on IKEv2.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 10:54:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279146#M11494</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-07-01T10:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279846#M11553</link>
      <description>&lt;P&gt;vpn tu list ike&lt;/P&gt;&lt;P&gt;Peer 10.131.32.254, user md5 d5d97eebc9c840d3:&lt;/P&gt;&lt;P&gt;Realm: vpn&lt;/P&gt;&lt;P&gt;Machine cert authentication: false&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IKEv2 SA &amp;lt;e9b394c9b4ac0872,d206797d57731d61&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunalty it works only once per client.&amp;nbsp;Each time the user disconnect and reconnect again, he didn't not succeed, until the connection IKEv2 SA timed out and "vpc tu tlist" is empty for this user. Otherwise in our testing environment, we reboot the gateway and afterwards it works again, but only once.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TAC case is open&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 13:49:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/279846#M11553</guid>
      <dc:creator>PeterH</dc:creator>
      <dc:date>2026-07-17T13:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282648#M11662</link>
      <description>&lt;P&gt;After upgrading the gateway to R82.10 I finally got some clients to connect with IKEv2. In SmartView monitor I see XAUTH for the authentication method for the clients using IKEv2.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_49dd48c9b21cedflachance_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 14:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282648#M11662</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-09-22T14:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282686#M11663</link>
      <description>&lt;P&gt;Well, I am not sure that XAUTH is an exclusive indicator for using IKEv2. Afaik it reflects Cross Authentication methods like MFA relying on a third party authentication or MFA connected backend (i.e. certificates/PKI, RADIUS, etc.)&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 08:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282686#M11663</guid>
      <dc:creator>dunkelmorten</dc:creator>
      <dc:date>2026-09-23T08:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282696#M11664</link>
      <description>&lt;P&gt;Thanks for the clarification. It's just odd since everybody is using the same authentication method (certificate) but only the few clients that have switched to ikev2 shows XAUTH. There must be something else I'm missing but in my case, whatever the reason, I can use this to quickly see who is now using IKEv2.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 11:59:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282696#M11664</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2026-09-23T11:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: migrating remote access client to IKEv2</title>
      <link>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282724#M11665</link>
      <description>&lt;P&gt;Be careful - I have had endless problems trying to migrate Windows Remote Access VPN client's to IKEv2. (I'm running R82.10 on my Security Gateways). Upgrading the Windows Remote Access VPN client version will remove your Registry Tweak and revert to IKEv1.&lt;/P&gt;
&lt;P&gt;The Windows Client IKEv1 / IKEv2 is still very buggy. I had a laptop that needed to connect to two different organisations. One origanisation was configured so that their Security Gateways *only* supported IKEv2, the other organisation was set to Prefer IKEv2, support IKEv1 clients.&lt;BR /&gt;&lt;BR /&gt;The client had the IKEv2 Registry tweak applied. Initially everything seemed OK, but after connecting *once* successfully to the site that enforced IKEv2, the client then could not re-connect to that site, until the site was deleted, and reconfigured. Then it could connect just once again. The only meaningful solution was reverting the Security Gateway to Prefer IKEv2, support IKE1.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This issue is repeatable. For now, there is no way you can *reliably* enforce the use of IKEv2 on your Security Gateways and have the confidence that your Windows Remote Access VPN clients will be able to connect every time they need to.&lt;BR /&gt;&lt;BR /&gt;The problem is, the Windows Remote Access VPN client, does &lt;EM&gt;not&lt;/EM&gt; negotiate IKEv1 or IKEv2 with the Security Gateway. It uses one or the other (depending on the Registry value), and it can just plain break after performing a topology download from one of the sites, which seems to somehow effect connectivity with another site (?). The same set of problems have been present in many different versions of the client.&lt;BR /&gt;&lt;BR /&gt;I really don't know why Check Point can't make IKE negotiation work properly for the Windows Remote Access VPN client / EndPoint Protection clients. The Capsule Connect VPN client for iOS works absolutely perfectly - it happily &lt;EM&gt;negotiates&lt;/EM&gt; IKEv1 or IKEv2 with the Security Gateway and works every time.&lt;BR /&gt;&lt;BR /&gt;The only issue with Capsule Connect VPN on iOS is that it only supports up to SHA265, it does &lt;EM&gt;not&lt;/EM&gt; support SHA384 (the Windows Remote Access VPN Client happily supports SHA384 and has for sometime).&lt;BR /&gt;&lt;BR /&gt;Everything works very happily with DF Group 21 - so that's good news.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 18:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/migrating-remote-access-client-to-IKEv2/m-p/282724#M11665</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2026-09-23T18:13:11Z</dc:date>
    </item>
  </channel>
</rss>

