<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81 - New VPN users unable to establish VPN via SHA256 in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113883#M9035</link>
    <description>&lt;P&gt;We’ve supported SHA-256 for many many versions.&lt;BR /&gt;Seems like some issue comes up with CAPI which is also…not new.&lt;BR /&gt;Did TAC suggest:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116997&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116997&amp;amp;partition=Advanced&amp;amp;product=Endpoint&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 02:23:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-18T02:23:18Z</dc:date>
    <item>
      <title>R81 - New VPN users unable to establish VPN via SHA256</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113828#M9034</link>
      <description>&lt;P&gt;In our R81 lab we encountered an interesting issue with CAPI certificate enrollment for &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&lt;U&gt;new&lt;/U&gt; VPN users&lt;/FONT&gt;&lt;/STRONG&gt;.&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Existing VPN users don't experience this issue.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When using SHA256 for data integrity the VPN site creation within the VPN client succeeds, but afterwards the VPN connection to the R81 VPN server fails. With SHA1 connecting to the VPN server succeeds.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;TAC support writes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;According to the logs, our failure is most probably related to the hashing algorithm, which is currently SHA256&lt;BR /&gt;&lt;BR /&gt;[ 5048 8084][15 Mar 17:32:00][IKE] create_MM5(certificates authentication): Failed to sign hash (-996)&lt;BR /&gt;[ 5048 8084][15 Mar 17:32:00][rais] [DEBUG] [RaisMessages::CreateMessageSet(s)] message: (msg_obj&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;:format (1.0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;:id (ClipsMessagesInternalError)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;:def_msg ("Internal error; connection failed. &amp;nbsp;More details may be available in the logs")&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;:arguments ()&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#008080"&gt;I suggest changing the data integrity hashing algorithm to SHA1 instead&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;Go to 'Global Properties &amp;gt; Remote Access &amp;gt; VPN – Authentication and Encryption &amp;gt; Encryption algorithms &amp;gt; IKE Security Association (Phase 1)'.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;Make sure that "SHA1" is selected under "Support Data Integrity".&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;Select "SHA1" under "Use Data Integrity".&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;Click "OK".&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#008080"&gt;&lt;SPAN&gt;Install policy.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Why doesn't Check Point R81 support the more secure SHA256 algorithm for VPN Remote Access for new users, which was working in previous versions? Tested with Endpoint Security Client &lt;FONT color="#339966"&gt;E82.40&lt;/FONT&gt; (&lt;EM&gt;working&lt;/EM&gt;), &lt;FONT color="#FF0000"&gt;E83.30 &amp;amp; E84.50 not working.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38469"&gt;@amitshr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 15:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113828#M9034</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-03-17T15:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: R81 - New VPN users unable to establish VPN via SHA256</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113883#M9035</link>
      <description>&lt;P&gt;We’ve supported SHA-256 for many many versions.&lt;BR /&gt;Seems like some issue comes up with CAPI which is also…not new.&lt;BR /&gt;Did TAC suggest:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116997&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116997&amp;amp;partition=Advanced&amp;amp;product=Endpoint&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 02:23:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113883#M9035</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T02:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81 - New VPN users unable to establish VPN via SHA256</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113886#M9036</link>
      <description>&lt;P&gt;According to the R&amp;amp;D, it seems to be a bug, and it is currently investigated on their end.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 05:26:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/113886#M9036</guid>
      <dc:creator>amitshr</dc:creator>
      <dc:date>2021-03-18T05:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: R81 - New VPN users unable to establish VPN via SHA256</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/117715#M9037</link>
      <description>&lt;P&gt;Any Update on this behaviour, may it get fixed in E81?&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 07:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/117715#M9037</guid>
      <dc:creator>Christoph_Hornu</dc:creator>
      <dc:date>2021-05-05T07:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: R81 - New VPN users unable to establish VPN via SHA256</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/122592#M9038</link>
      <description>&lt;P&gt;We hit the same issue with R80.40 JHF236,&amp;nbsp; using machine certificate from CAPI and E84.00 client.&lt;BR /&gt;Error messages in trac.log are the same.&lt;/P&gt;&lt;P&gt;Lowering Data Integrity to SHA1 is a working solution, but hope this bug will get fixed soon.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 12:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R81-New-VPN-users-unable-to-establish-VPN-via-SHA256/m-p/122592#M9038</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2021-06-30T12:09:24Z</dc:date>
    </item>
  </channel>
</rss>

