<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switching Capsule client from HTTPS to IPSEC in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242708#M40573</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Did you try deleting and re-adding the site after making this change?&lt;BR /&gt;&lt;/SPAN&gt;Anything from the client logs?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2025 16:52:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-28T16:52:31Z</dc:date>
    <item>
      <title>Switching Capsule client from HTTPS to IPSEC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242633#M40553</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;
&lt;P&gt;Architecturally we have made a decision to move our Capsule clients from connecting via HTTPS to IPSEC to mitigate against potential future vulnerabilities.&lt;/P&gt;
&lt;P&gt;What we are seeing is that as soon as we do that change, mobile clients stop communicating.&amp;nbsp; They manage to log in successfully but nothing further apart from that.&lt;/P&gt;
&lt;P&gt;The weird thing is I also see no drops from the clients OM IP, not through Smartconsole and not through a fw ctl zdebug either.&amp;nbsp; On the clients I also see the encrypted packet count increasing, but not the decrypted.&lt;/P&gt;
&lt;P&gt;The only activity I'm seeing is IKE NAT-T on udp 4500.&amp;nbsp; I've double-checked that I've got no silent drops going on either.&lt;/P&gt;
&lt;P&gt;Would really appreciate any ideas on where to start looking.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 08:41:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242633#M40553</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-02-28T08:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Switching Capsule client from HTTPS to IPSEC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242708#M40573</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Did you try deleting and re-adding the site after making this change?&lt;BR /&gt;&lt;/SPAN&gt;Anything from the client logs?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 16:52:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242708#M40573</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-28T16:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Switching Capsule client from HTTPS to IPSEC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242762#M40583</link>
      <description>&lt;P&gt;Hi Dameon,&lt;/P&gt;
&lt;P&gt;Yes we have re-created the site.&amp;nbsp; We do have a case open with TAC so are providing them with the debugs.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 08:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Switching-Capsule-client-from-HTTPS-to-IPSEC/m-p/242762#M40583</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-03-02T08:49:29Z</dc:date>
    </item>
  </channel>
</rss>

