<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261427#M44231</link>
    <description>&lt;P&gt;No problem!&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2025 14:07:56 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-10-30T14:07:56Z</dc:date>
    <item>
      <title>Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261384#M44211</link>
      <description>&lt;P&gt;Check Point R81.20&lt;BR /&gt;Good afternoon, when you uncheck the box "Allow older clients to connect to this gateway"&amp;nbsp;&amp;nbsp;in the cluster settings in section VPN Clients,&amp;nbsp;L2TP + IPSec is disabled.&amp;nbsp;&lt;BR /&gt;The question is, is it possible to somehow limit the standard authentication profile to connect, for example, only local checkpoint users?&lt;BR /&gt;Or is there any way to uncheck this box and still have L2TP+IPSec working?&lt;BR /&gt;&lt;BR /&gt;The idea is to leave only the authentication methods we created for connecting via Check Point Endpoint Security VPN, or to limit the standard authentication method to local Check Point users (not domain ones) and to have the ability to connect via L2TP + IPSec&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 09:16:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261384#M44211</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T09:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261408#M44216</link>
      <description>&lt;P&gt;Yes, you can control which users authenticate by:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Authentication Method&lt;/STRONG&gt;: L2TP/IPsec supports &lt;STRONG&gt;username/password (PAP/EAP-MD5)&lt;/STRONG&gt; or &lt;STRONG&gt;certificates&lt;/STRONG&gt;. You can configure the gateway to use only the &lt;STRONG&gt;Internal User Database&lt;/STRONG&gt; for these credentials.&lt;/LI&gt;
&lt;LI&gt;In &lt;STRONG&gt;SmartConsole&lt;/STRONG&gt;, go to:
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;Gateway Properties → VPN Clients → Authentication&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Set the authentication scheme to &lt;STRONG&gt;Internal User Database&lt;/STRONG&gt; (or create a dedicated group for L2TP users).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;This way, domain users (LDAP/RADIUS) won’t be accepted for L2TP/IPsec&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;***************************&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Is there any workaround to uncheck the box and still have L2TP/IPsec?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Unfortunately, no documented workaround exists. The “Allow older clients” flag is tied to enabling legacy protocols like L2TP/IPsec. If you disable it, the gateway enforces modern VPN clients only (Harmony Endpoint / Check Point Mobile)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 30 Oct 2025 12:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261408#M44216</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T12:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261409#M44217</link>
      <description>&lt;P&gt;My situation is that I need L2TP + IPsec, but I also need to disable the standard authentication method, or limit the standard authentication method to local users only.&amp;nbsp;In my case, there is no need to restrict L2TP+IPSec to local users only; this is more a question for the standard authentication method.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 12:26:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261409#M44217</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T12:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261412#M44218</link>
      <description>&lt;P&gt;Auth itself can be controlled from the screen I attached, which Im sure you have configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 12:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261412#M44218</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T12:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261413#M44219</link>
      <description>&lt;P&gt;Yes, I have 3 custom profiles, and users can only connect through them, but at the moment, since this checkbox "&lt;SPAN&gt;Allow older clients to connect to this gateway"&lt;/SPAN&gt; is checked, they can choose the standard method and log in using their username and password (without 2FA)&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 12:49:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261413#M44219</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T12:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261415#M44220</link>
      <description>&lt;P&gt;Ok...and if you uncheck that option, then works as expected?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 13:06:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261415#M44220</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T13:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261418#M44223</link>
      <description>&lt;P&gt;Yes, it is impossible to connect using the standard authentication method, but L2TP+IPSec, which I need, also doesn’t work.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 13:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261418#M44223</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T13:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261419#M44224</link>
      <description>&lt;P&gt;Wait, just to make sure Im not missing anything...are you saying IF that setting is on to allow older clients to connect, user/pass auth does not work?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 13:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261419#M44224</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T13:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261421#M44226</link>
      <description>&lt;P&gt;No, this checkbox works as it should in terms of limiting the default authentication method, I just want to understand if it is possible to limit this default authentication method to connections from local users only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 13:48:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261421#M44226</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T13:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261423#M44228</link>
      <description>&lt;P&gt;I dont believe you can, but I could be mistaken...maybe best to confirm with TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 13:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261423#M44228</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T13:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261426#M44230</link>
      <description>&lt;P&gt;OK, thank you for help!!!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 14:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261426#M44230</guid>
      <dc:creator>NikolayNikolay</dc:creator>
      <dc:date>2025-10-30T14:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261427#M44231</link>
      <description>&lt;P&gt;No problem!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 14:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261427#M44231</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T14:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allow older clients to connect to this gateway disabling L2TP+IPSec mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261433#M44234</link>
      <description>&lt;P&gt;Considering L2TP + IPsec support goes back to the days of SecuRemote, I suspect it's considered an "older client" and would be disabled by that option.&lt;BR /&gt;Also of note that L2TP requires the use of Legacy Authentication, as noted in the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/L2TP-Clients.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/L2TP-Clients.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect what you're trying to do is an RFE.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 14:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-older-clients-to-connect-to-this-gateway-disabling-L2TP/m-p/261433#M44234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-30T14:31:22Z</dc:date>
    </item>
  </channel>
</rss>

