<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Site to Site Encryption Suite Best Practise in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63574#M11908</link>
    <description>&lt;P&gt;I recommend to differentiate between VPN Site-to-Site between Check Point gateways and with 3rd party VPN gateways.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/5863-what-information-do-we-need-from-the-remote-site-customer-when-creating-site-to-site-vpn" target="_self"&gt;&lt;STRONG&gt;Best practice&lt;/STRONG&gt; settings (&lt;EM&gt;&lt;STRONG&gt;bold&lt;/STRONG&gt;&lt;/EM&gt;) for VPN with 3rd party gateways&lt;/A&gt; | &lt;A href="https://community.checkpoint.com/t5/General-Topics/Check-Point-Site-to-Site-VPN-Compatibility-Matrix/td-p/39089" target="_self"&gt;Compatibility matrix&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 14:44:35 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2019-09-24T14:44:35Z</dc:date>
    <item>
      <title>VPN Site to Site Encryption Suite Best Practise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63568#M11905</link>
      <description>&lt;P&gt;Any suggestions about the best performance/security parameters to use in a Site to Site Encryption Suite configuration ? I would stress the phase 1 and leave the phase 2 lighter....in few words&lt;/P&gt;&lt;P&gt;Phase 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encryption Alghoritm --&amp;gt;&amp;nbsp; AES256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data Integrity --&amp;gt; SHA256&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DH Group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; Group14&lt;/P&gt;&lt;P&gt;Phase 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encryption Alghoritm --&amp;gt;&amp;nbsp; 3DES&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data Integrity --&amp;gt; SHA1&lt;/P&gt;&lt;P&gt;unless the other side peer complain &lt;span class="lia-unicode-emoji" title=":monkey_face:"&gt;🐵&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What do you think about it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63568#M11905</guid>
      <dc:creator>Mauro_Conoscian</dc:creator>
      <dc:date>2019-09-24T14:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site Encryption Suite Best Practise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63569#M11906</link>
      <description>&lt;P&gt;Avoid 3DES as it's computationally inefficient compared to AES, and AES-NI will give you much better performance.&lt;/P&gt;&lt;P&gt;SHA1 shouldn't be used anymore in favor of AES256+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63569#M11906</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2019-09-24T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site Encryption Suite Best Practise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63572#M11907</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Refer to &lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105119" target="_blank" rel="noopener"&gt;sk105119 - Best Practices - VPN Performance&lt;/A&gt;&lt;SPAN&gt; and to &lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104760" target="_blank" rel="noopener"&gt;sk104760 - ATRG: VPN Core&lt;/A&gt;.&amp;nbsp;&lt;SPAN&gt;For a comparison of encryption algorithm speeds, refer to &lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk73980" target="_blank" rel="noopener"&gt;sk73980 - Relative speeds of algorithms for IPsec and SSL&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:33:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63572#M11907</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-24T14:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site Encryption Suite Best Practise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63574#M11908</link>
      <description>&lt;P&gt;I recommend to differentiate between VPN Site-to-Site between Check Point gateways and with 3rd party VPN gateways.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/5863-what-information-do-we-need-from-the-remote-site-customer-when-creating-site-to-site-vpn" target="_self"&gt;&lt;STRONG&gt;Best practice&lt;/STRONG&gt; settings (&lt;EM&gt;&lt;STRONG&gt;bold&lt;/STRONG&gt;&lt;/EM&gt;) for VPN with 3rd party gateways&lt;/A&gt; | &lt;A href="https://community.checkpoint.com/t5/General-Topics/Check-Point-Site-to-Site-VPN-Compatibility-Matrix/td-p/39089" target="_self"&gt;Compatibility matrix&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:44:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Site-to-Site-Encryption-Suite-Best-Practise/m-p/63574#M11908</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-09-24T14:44:35Z</dc:date>
    </item>
  </channel>
</rss>

