<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56691#M12203</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11457"&gt;@Jonathan_Griffi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding this support exists on our long term road map for the Endpoint VPN clients.&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote, contacting your local office to open an RFE can speed this up and prioritize it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Royi.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2019 08:32:56 GMT</pubDate>
    <dc:creator>Royi_Priov</dc:creator>
    <dc:date>2019-06-26T08:32:56Z</dc:date>
    <item>
      <title>R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56177#M12199</link>
      <description>&lt;P&gt;Info:&lt;/P&gt;&lt;P&gt;Security Manager / Gateway Environment R80.10&lt;/P&gt;&lt;P&gt;Endpoint Security VPN Client: E80.97&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I won't pretend to know the cryptographic intricacies of all the differences between the numerous Diffie-Hellman groups; my question / concern is based on best practice while providing a balance between security and usability.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've spent the last few hours trying to find content relating to why I can't use Diffie-Hellman Group 19/20 with my Remote Access VPN clients...using Endpoint Security E80.9x.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within global properties on my SMS I can set some pretty respectable Encryption / Integrity algorithms. However, the "best" offering regarding Diffie-Hellman Groups is 14 (2048bits). I would like to know why I am unable to use Diffie-Hellman Groups 19/20 as this is really the minimum standard for IPSec as far as I can tell...happy to be corrected if this understanding is wrong?&lt;/P&gt;&lt;P&gt;I'm beginning to suspect this is a client limitation. I have checked the database with the guiDB tool and can see groups 19 and 20 are defined.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some clarification and /or direction to the relevant resource would be much appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 12:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56177#M12199</guid>
      <dc:creator>Jonathan_Griffi</dc:creator>
      <dc:date>2019-06-19T12:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56489#M12200</link>
      <description>You're correct that our VPN clients currently do not support DH Group 19/20.&lt;BR /&gt;You can see a reference to it here: &lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=60345" target="_blank"&gt;http://downloads.checkpoint.com/dc/download.htm?ID=60345&lt;/A&gt;</description>
      <pubDate>Sun, 23 Jun 2019 21:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56489#M12200</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T21:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56624#M12201</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thanks for letting me know...out of curiosity, do you know if this is something which will be added in future versions of the Endpoint Security Clients?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 14:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56624#M12201</guid>
      <dc:creator>Jonathan_Griffi</dc:creator>
      <dc:date>2019-06-25T14:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56634#M12202</link>
      <description>&lt;P&gt;Not aware of specific plans in this area.&lt;BR /&gt;If anyone knows,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;does.&lt;BR /&gt;You may also want to check in with your local Check Point office regarding this requirement.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 18:51:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56634#M12202</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-25T18:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56691#M12203</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11457"&gt;@Jonathan_Griffi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding this support exists on our long term road map for the Endpoint VPN clients.&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote, contacting your local office to open an RFE can speed this up and prioritize it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Royi.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 08:32:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56691#M12203</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-06-26T08:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Remote Access VPN - Endpoint Security Diffie-Hellman Support</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56707#M12204</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp; thanks for confirming. Much appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 10:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Remote-Access-VPN-Endpoint-Security-Diffie-Hellman/m-p/56707#M12204</guid>
      <dc:creator>Jonathan_Griffi</dc:creator>
      <dc:date>2019-06-26T10:08:48Z</dc:date>
    </item>
  </channel>
</rss>

