<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.10 L2TP config in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146759#M6910</link>
    <description>&lt;P&gt;What's the security argument against L2TP-over-IPSec?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 21:08:24 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2022-04-21T21:08:24Z</dc:date>
    <item>
      <title>R81.10 L2TP config</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146622#M6907</link>
      <description>&lt;P&gt;Need to vent a bit... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp; We've grown pretty frustrated with CP's VPN clients.&amp;nbsp; &amp;nbsp;The issues surrounding needing Local Admin to install or upgrade SNX/SSL client or the Standalone Endpoint VPN client on corporate PCs that live OUTSIDE our internal LAN / Domain is really a PITA to manage.&amp;nbsp; We turned to using the Check Point Capsule VPN from the MS Store as it does not need Local Admin privileges to install and pretty easy for our &lt;U&gt;very non-technical&lt;/U&gt; healthcare providers to configure with just a phone call.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;We have run into issues with the Capsule Client -- won't register in our DNS and Split Tunneling does not seem to work.&amp;nbsp; &amp;nbsp;We want Internet traffic to go out the user's local Internet.&amp;nbsp; &amp;nbsp;So I contact TAC over all the VPN Client issues.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read the SK about using MSIEXEC to install SNX/SSL.&amp;nbsp; &amp;nbsp;This requires we do this for every remote PC we have -- which is really not plausible.&amp;nbsp; &amp;nbsp;And when we upgrade to R81.20, we can be sure that the SNX version will change.&amp;nbsp; Yes, I know how to modify slim_ver and snx_ver files to suppress upgrade.&amp;nbsp; &amp;nbsp;However, I was just informed by TAC that SNX/SSL does NOT support Win 11 yet -- with no date yet for official support.&amp;nbsp; &amp;nbsp;Well that explained the Install error "30" I was getting on my Win 11 Laptop (I have Local Admin rights).&amp;nbsp; I asked if there was an SK on it and was pointed to the Generic SK and told if the OS is not specifically listed, it is not supported.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Endpoint Standalone VPN client.&amp;nbsp; Same general issues as SNX/SSL in that we'd have to reach out individually to install or update on the Remote PCs.&amp;nbsp; It has a way to create a package with all the necessary settings for the user.&amp;nbsp; I have the manual but quite haven't gotten it figured out.&amp;nbsp; &amp;nbsp;Even our old CP SE, couldn't figure it out!&amp;nbsp; &amp;nbsp;I miss the old method of using ORCA to modify the MSI's variables!&amp;nbsp; Plus it was inferred that this client may not officially support Win11.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back the Capsule Client in the MS store - which works on Win 11.&amp;nbsp; &amp;nbsp;Yes, I gather it is a shell wrapped around native Windows IPsec connectivity support.&amp;nbsp; Regarding the issues mentioned above, we talked to Microsoft support, they say its Check Point responsibility.&amp;nbsp; Check Point TAC says talk to Microsoft.&amp;nbsp; I hate to side with Microsoft, but it is branded as a Check Point product - so Check Point TAC should be able to support it.&amp;nbsp; Would love to figure out a way to incorporate it into our corporate PC image.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we thought about trying L2TP,&amp;nbsp; &amp;nbsp;So I bring up&amp;nbsp;&lt;SPAN&gt;sk63324.&amp;nbsp; The screen shots look nothing like what we see in R81.10.&amp;nbsp; I searched thru all the VPN settings on our GW and the RemoteAccess Community.&amp;nbsp; &amp;nbsp;I can't find anywhere where the L2TP PSK would be entered.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;We do have Radius and DUO config'd for 2FA or any VPN connection.&amp;nbsp; We use OfficeMode IPs.&amp;nbsp; So I am not sure if that suppresses some of the setting options shown in the SK.&amp;nbsp; It seems that the sk should at least be updated.&lt;/P&gt;&lt;P&gt;So I am looking for hints on the L2TP setup in hopes it fixes some of the above issues regarding split-tunnel, client DNS registrations.&lt;/P&gt;&lt;P&gt;Thanks for "listening"!&lt;/P&gt;&lt;P&gt;Perry&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 17:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146622#M6907</guid>
      <dc:creator>Perry_McGrew</dc:creator>
      <dc:date>2022-04-20T17:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 L2TP config</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146648#M6908</link>
      <description>&lt;P&gt;Lots to unpack here but I'll address some key points in the interest of timeliness.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also depending on your user experience objectives Harmony Connect Remote Access options (Application Access or VPNaaS) might be worth evaluating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows 11&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Win11 is supported from E85.40 (Endpoint Security VPN) and above, refer:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115192" target="_self"&gt;&lt;SPAN&gt;sk115192&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;/&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175451" target="_self"&gt;&lt;SPAN&gt;sk175451&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Split tunnel support was enhanced in E86.20 and above per&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000" target="_self"&gt;&lt;SPAN&gt;sk167000&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;/&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176853" target="_self"&gt;&lt;SPAN&gt;sk176853&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;L2TP&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Note this isn't located in the Gateway properties - navigate as follows:&lt;/P&gt;
&lt;P&gt;Menu &amp;gt; Global Properties &amp;gt; Remote Access &amp;gt; VPN - Authentication&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="L2TP.png" style="width: 886px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16105i5E9AD5D507CEBCBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="L2TP.png" alt="L2TP.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(Please be aware L2TP isn't generally recommended for security reasons).&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 01:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146648#M6908</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-21T01:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 L2TP config</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146755#M6909</link>
      <description>&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;Thanks for the answer ... and reading thru my rant!&amp;nbsp; I found L2TP was set per the screenshot.&amp;nbsp; &amp;nbsp;I knew we had tried it a long time ago.&amp;nbsp; I agree it is not deemed secure and I am not pushing to implement.&amp;nbsp; &amp;nbsp;It was a request from my boss (CIO) due to the frustration(s) over CP's VPN client(s) issues.&amp;nbsp; &amp;nbsp;He now has requested me to look into other vendor client VPN solutions.&amp;nbsp; &amp;nbsp;I have reached out to our CP SE and our VAR to see if there is a reasonable solution.&amp;nbsp; &amp;nbsp;I had a look &amp;amp; demo of Harmony early on and it did not seem to address what we were looking for / needed and licensing model - cost was prohibitive for us,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 19:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146755#M6909</guid>
      <dc:creator>Perry_McGrew</dc:creator>
      <dc:date>2022-04-21T19:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 L2TP config</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146759#M6910</link>
      <description>&lt;P&gt;What's the security argument against L2TP-over-IPSec?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 21:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146759#M6910</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-04-21T21:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 L2TP config</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146810#M6911</link>
      <description>&lt;P&gt;Yes not to be confused with barebones L2TP of course, it's generalized and not specific to Check Point.&lt;/P&gt;
&lt;P&gt;The SK itself sights historic client side vulnerabilities with Android.&lt;/P&gt;
&lt;P&gt;Many implementations are also talked about as having hard coded or mass distributed PSK and or fallback to weak alternatives upon failure scenarios.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 01:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-10-L2TP-config/m-p/146810#M6911</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-22T01:40:05Z</dc:date>
    </item>
  </channel>
</rss>

