<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to Site vpn with 3rd party DAIP gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/7050#M800</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why checkpoint is not allowing to use preshared key for the DAIP gateway or 3rd party gateway. i know it works only with a certificate&amp;nbsp;but is there any future release for this feature.&amp;nbsp;other competitors&amp;nbsp;are compatible with PSK if the remote is DAIP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Preshared key is supported on&amp;nbsp;embeded&amp;nbsp;gaia&amp;nbsp;for Daip gateway but not in main stream gaia.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Oct 2017 07:32:32 GMT</pubDate>
    <dc:creator>Libin_Thomas</dc:creator>
    <dc:date>2017-10-04T07:32:32Z</dc:date>
    <item>
      <title>Site to Site vpn with 3rd party DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/7050#M800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why checkpoint is not allowing to use preshared key for the DAIP gateway or 3rd party gateway. i know it works only with a certificate&amp;nbsp;but is there any future release for this feature.&amp;nbsp;other competitors&amp;nbsp;are compatible with PSK if the remote is DAIP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Preshared key is supported on&amp;nbsp;embeded&amp;nbsp;gaia&amp;nbsp;for Daip gateway but not in main stream gaia.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/7050#M800</guid>
      <dc:creator>Libin_Thomas</dc:creator>
      <dc:date>2017-10-04T07:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with 3rd party DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/7051#M801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using an IPsec Pre-Shared Key with a dynamic IP endpoint has additional security risks, mainly because of the need to use IKE Aggressive Mode for authentication, which sends some key information "in the clear."&lt;/P&gt;&lt;P&gt;Refer to the following articles for more information:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="link-titled" href="https://blog.webernetz.net/2015/01/19/considerations-about-ipsec-pre-shared-keys-psks/" title="https://blog.webernetz.net/2015/01/19/considerations-about-ipsec-pre-shared-keys-psks/"&gt;Considerations about IPsec Pre-Shared Keys | Blog Webernetz.net&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A class="link-titled" href="https://security.stackexchange.com/questions/76444/what-are-the-practical-risks-of-using-ike-aggressive-mode-with-a-pre-shared-key" title="https://security.stackexchange.com/questions/76444/what-are-the-practical-risks-of-using-ike-aggressive-mode-with-a-pre-shared-key"&gt;vpn - What are the practical risks of using IKE Aggressive mode with a pre-shared key? - Information Security Stack Exch…&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As such, at least for the Enterprise products, we require certificates to be used when a VPN endpoint is dynamic.&lt;/P&gt;&lt;P&gt;Embedded Gaia only supports IPsec on a dynamic IP endpoint when it is self-managed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Oct 2017 21:38:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/7051#M801</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-06T21:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with 3rd party DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/80999#M16361</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can you please direct me to a document describing configuration for certificate based site-to-site VPN with 3rd party vendor (Fortigate in our case) because it seems I'm not able to find related documentation..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 15:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/80999#M16361</guid>
      <dc:creator>anstelios</dc:creator>
      <dc:date>2020-04-06T15:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with 3rd party DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/81005#M16362</link>
      <description>&lt;P&gt;Your question is answered her:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36968&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk36968: Cannot establish &lt;STRONG&gt;VPN&lt;/STRONG&gt; tunnel with &lt;STRONG&gt;3rd&lt;/STRONG&gt; &lt;STRONG&gt;Party&lt;/STRONG&gt; DAIP using Pre-shared Secret&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and it gives the statement:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For information about how to configure VPN between Check Point and Cisco DAIP, refer to the "Configuring a VPN with External Security Gateways Using Certificates" in the &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm" target="_blank" rel="noopener"&gt;R80.10 Site To Site VPN Administration Guide&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 16:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/81005#M16362</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-04-06T16:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with 3rd party DAIP gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/81007#M16363</link>
      <description>&lt;P&gt;I also found it on CheckMates:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Checkpoint-to-Fortinet-VPN/m-p/13915#M2468" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Checkpoint-to-Fortinet-VPN/m-p/13915#M2468&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 16:44:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-vpn-with-3rd-party-DAIP-gateway/m-p/81007#M16363</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-04-06T16:44:33Z</dc:date>
    </item>
  </channel>
</rss>

