<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forcing AES encryption Algorithm for SNX user in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183693#M4819</link>
    <description>&lt;P&gt;You may want to make 100% certain 3DES is disabled globally per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113114" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk113114&lt;/A&gt;&lt;BR /&gt;Otherwise, I suggest a TAC case to assist: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2023 16:03:30 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-09T16:03:30Z</dc:date>
    <item>
      <title>Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183621#M4816</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, Expert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to force AES for SNX user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;I’ve tried many ways, but user is keep using 3DES only. Can we force AES?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JaeYoung_An_0-1686213903859.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21340iCB9A44AA6CB05EC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JaeYoung_An_0-1686213903859.png" alt="JaeYoung_An_0-1686213903859.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JaeYoung_An_1-1686213903865.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21341i3BDD1C4370A23F01/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JaeYoung_An_1-1686213903865.png" alt="JaeYoung_An_1-1686213903865.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’ve also followed &lt;A href="https://support.checkpoint.com/results/sk/sk113114" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk113114&lt;/A&gt; to disable 3DES, but always 3DES is used.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is same even in latest version. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone Advise how to use AES or confirm we can’t use AES?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JaeYoung_An_2-1686213903866.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21339i768B15616E5142C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JaeYoung_An_2-1686213903866.png" alt="JaeYoung_An_2-1686213903866.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-06-08_14-57-21.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21342i68F04FF6A82C23FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-06-08_14-57-21.png" alt="2023-06-08_14-57-21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183621#M4816</guid>
      <dc:creator>JaeYoung_An</dc:creator>
      <dc:date>2023-06-08T08:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183668#M4817</link>
      <description>&lt;P&gt;What precisely are the clients in this case?&lt;BR /&gt;If they're Linux, I suspect you're out of luck similar to:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180837" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180837&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Windows and macOS SNX support AES on currently supported versions.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 22:17:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183668#M4817</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-08T22:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183679#M4818</link>
      <description>&lt;P&gt;It's Windows 10 client with chrome browser&lt;/P&gt;&lt;P&gt;gateway version is R81.20&lt;/P&gt;&lt;P&gt;please refer to below pic&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-06-09_13-11-01.png" style="width: 943px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21348i68CE6B03D0B50EF9/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-06-09_13-11-01.png" alt="2023-06-09_13-11-01.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 04:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183679#M4818</guid>
      <dc:creator>JaeYoung_An</dc:creator>
      <dc:date>2023-06-09T04:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183693#M4819</link>
      <description>&lt;P&gt;You may want to make 100% certain 3DES is disabled globally per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113114" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk113114&lt;/A&gt;&lt;BR /&gt;Otherwise, I suggest a TAC case to assist: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 16:03:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/183693#M4819</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-09T16:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/235990#M4820</link>
      <description>&lt;P data-unlink="true"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk116156&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;https://support.checkpoint.com/results/sk/sk116156&amp;nbsp; tell AES is supported by MacOS SNX client starting from R80.10&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 732px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28852iBAE528D8AD2D24BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this obviously suggest that the SNX Server side support this encryption method&amp;nbsp; as showed here:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 697px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28853i96DE9808AC8CB082/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Why this is not working ?&lt;/P&gt;&lt;P&gt;if I use SNX client or CAPSULE from windows the connections is always in 3DES.&lt;/P&gt;&lt;P&gt;there is a Check Point Employee that can explain how to solve&amp;nbsp; using GuiDBEDIT?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Massimo&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 11:49:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/235990#M4820</guid>
      <dc:creator>Massimo_Manzato</dc:creator>
      <dc:date>2024-12-17T11:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing AES encryption Algorithm for SNX user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/236019#M4821</link>
      <description>&lt;P&gt;Don't know that (gui)dbedit is the solution here.&lt;BR /&gt;I know this SK only mentions SMB appliances, but I see the referenced kernel variable on regular gateways (at least in R82):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112314" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112314&lt;/A&gt;&lt;BR /&gt;It's worth a shot.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 14:23:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-AES-encryption-Algorithm-for-SNX-user/m-p/236019#M4821</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-17T14:23:17Z</dc:date>
    </item>
  </channel>
</rss>

