<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point VPN encprytion and  FIPS 140-2 in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/157623#M10022</link>
    <description>&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264" target="_blank"&gt;Cryptographic Module Validation Program | CSRC (nist.gov)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like #4264 is the latest, still we have FIPs mode disabled on our GW.&amp;nbsp; &amp;nbsp;I assume if FIPs is disabled none of the blades are using this.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2022 11:18:08 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2022-09-20T11:18:08Z</dc:date>
    <item>
      <title>Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93950#M10016</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is the Endpoint Security, SSLVPN (TLS 1.2)&amp;nbsp; or IPSEC tunnel traffic (AES-256, SHA256, Group 2) considered &lt;SPAN&gt;FIPS 140-2 validated encryption? &amp;nbsp; If its not called&amp;nbsp;FIPS 140-2 validated encryption what is it called?&amp;nbsp; Non-validated encryption/basic encryption/encryption?&amp;nbsp; Our security auditors want to know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;side point:&amp;nbsp; It would be nice to be able to print out crypto-maps like CISCO for VPN configs or something else that's graphical and sums up VPN encryption/access or both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This is the official request:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;Encryption configuration for remote access. If FIPS 140-2 validated encryption is being used please demonstrate the cryptographic module was configured in accordance with the CMVP security policy.&lt;/EM&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 13:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93950#M10016</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-08-13T13:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93971#M10017</link>
      <description>&lt;P&gt;Are the auditors asking if Checkpoint is using a validated cryptographic module that needs to be listed here?:&amp;nbsp;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If so....Then as long as you are running R77.30&amp;nbsp;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/2995" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/2995&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 03:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93971#M10017</guid>
      <dc:creator>Ryan_St__Germai</dc:creator>
      <dc:date>2020-08-13T03:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93974#M10018</link>
      <description>&lt;P&gt;There’s also the client side of this:&amp;nbsp;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/2788" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/2788&lt;/A&gt;&lt;BR /&gt;I assume we are working on getting a more recent version of the modules certified but they aren’t substantially different from what’s in these releases.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 04:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/93974#M10018</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-13T04:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/97826#M10019</link>
      <description>&lt;P&gt;FISMA auditors are here &amp;amp; they say&lt;/P&gt;&lt;P&gt;That CMVP cert says “When operated in FIPD mode” in the Caveat section.&amp;nbsp; So there is a switch.&amp;nbsp; Can you check it to find out its status?&lt;/P&gt;&lt;P&gt;Normally, there would be a way to initiate FIPS mode for FIPS capable products. If there is a way to initiate FIPS mode, is that being used?&lt;/P&gt;&lt;P&gt;-Show that the VPN is running in FIPS mode or using FIPS-validated cryptography for data in transit.&amp;nbsp; I believe currently we only have a screenshot showing that TLS 1.2 and higher is being used.&lt;/P&gt;&lt;P&gt;-Show how a user’s VPN connection would be disconnected by an administrator.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/97826#M10019</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-09-29T15:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/109480#M10020</link>
      <description>&lt;P&gt;RE:VPN only&lt;/P&gt;&lt;P&gt;RE: S2S, fat C2S and/or SSLVPN? &amp;nbsp; Maybe, you have to run in the gw in FIPS mode as a pre-req to VPN, I'm not sure.&amp;nbsp; After that, how do you set FIPS on for the TLS 1.2 connection to SSLVPN?&amp;nbsp;&amp;nbsp; I'm guessing there are 3 things involved 1. windows OS 2. browser 3. network extender&lt;/P&gt;&lt;P&gt;I have to assume that FIPS library is enabled by default in the browser when a user connects with TLS 1.2 to our sslvpn, but how can I show proof?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the gateway, is there a way to show an auditor fips is on for VPN?&amp;nbsp; I see here you can turn it ON in general for the gateway, with some serious limitations.&amp;nbsp; &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/FIPS-mode-operation-and-some-manual-configurations/m-p/97289" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/FIPS-mode-operation-and-some-manual-configurations/m-p/97289&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 19:47:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/109480#M10020</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2021-02-01T19:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/157304#M10021</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Another year, here we go agian...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Crypto module and CMVP utilized by the VPN.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Crypto modules and CMVPs that applications instances utilize to communicate inside the cloud.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 12:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/157304#M10021</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-09-15T12:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/157623#M10022</link>
      <description>&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264" target="_blank"&gt;Cryptographic Module Validation Program | CSRC (nist.gov)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like #4264 is the latest, still we have FIPs mode disabled on our GW.&amp;nbsp; &amp;nbsp;I assume if FIPs is disabled none of the blades are using this.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 11:18:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/157623#M10022</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-09-20T11:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point VPN encprytion and  FIPS 140-2</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/207900#M10023</link>
      <description>&lt;P&gt;Now, I'm being asked about FIPS 140-3-certified.&amp;nbsp;&amp;nbsp; I assume that will take a while, maybe R82.&amp;nbsp; Does the current FIPS 140-2-certified include the SD-WAN blade?&amp;nbsp; Or do the blades get grandfathered in?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 21:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-VPN-encprytion-and-FIPS-140-2/m-p/207900#M10023</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-03-05T21:58:13Z</dc:date>
    </item>
  </channel>
</rss>

