<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 730 Remote Access VPN: Show/Configure Encryption in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8289#M169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well I want to know and potentially configure how clients are connecting.&amp;nbsp; Supposing I had a requirement not to use 3DES for encryption or MD5 for authentication for IPSEC remote access clients.&amp;nbsp; I don't see any way to verify that or configure that.&amp;nbsp; The options you've shown have some limited control over SSL, but I don't see any for IPSEC beyond IKEv1/v2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2018 15:02:09 GMT</pubDate>
    <dc:creator>Kris_Jurka</dc:creator>
    <dc:date>2018-07-13T15:02:09Z</dc:date>
    <item>
      <title>730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8287#M167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to determine the settings used (or ideally configure them) for the remote access VPN in a 730 appliance.&amp;nbsp; That is to see the encryption/authentication/dhgroup/pfs/.. settings at either the client end in endpoint security or on the server?&lt;/P&gt;&lt;P&gt;Right now it seems like it's completely a black box and I've gotten some questions about whether we are meeting certain standards and haven't found any way to answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 22:50:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8287#M167</guid>
      <dc:creator>Kris_Jurka</dc:creator>
      <dc:date>2018-07-12T22:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: 730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8288#M168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's a couple settings you can change in the advanced settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="67027" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67027_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you create a Site-to-Site VPN you can see some other settings.&lt;/P&gt;&lt;P&gt;Which, even if you can't configure, should give you an idea of what's supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67028_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exact settings are you interested in?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 09:36:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8288#M168</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-13T09:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: 730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8289#M169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well I want to know and potentially configure how clients are connecting.&amp;nbsp; Supposing I had a requirement not to use 3DES for encryption or MD5 for authentication for IPSEC remote access clients.&amp;nbsp; I don't see any way to verify that or configure that.&amp;nbsp; The options you've shown have some limited control over SSL, but I don't see any for IPSEC beyond IKEv1/v2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:02:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8289#M169</guid>
      <dc:creator>Kris_Jurka</dc:creator>
      <dc:date>2018-07-13T15:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: 730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8290#M170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Generally we'll offer all of the above and the client will connect with the strongest supported option between the two.&lt;/P&gt;&lt;P&gt;I believe you can use vpn tu on the CLI to see how clients are connected currently.&lt;/P&gt;&lt;P&gt;Will have to check and see if there's a way to configure what's offered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8290#M170</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-13T15:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: 730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8291#M171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"vpn tu" does not appear to show any of that information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; vpn tu&lt;/P&gt;&lt;P&gt;**********&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Option&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; **********&lt;/P&gt;&lt;P&gt;(1)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List all IKE SAs&lt;BR /&gt;(2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List all IPsec SAs&lt;BR /&gt;(3)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List all IKE SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(4)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List all IPsec SAs for a given peer (GW) or user (Client)&lt;BR /&gt;(5)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec SAs for a given peer (GW)&lt;BR /&gt;(6)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec SAs for a given User (Client)&lt;BR /&gt;(7)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec+IKE SAs for a given peer (GW)&lt;BR /&gt;(8)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec+IKE SAs for a given User (Client)&lt;BR /&gt;(9)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec SAs for ALL peers and users&lt;BR /&gt;(0)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete all IPsec+IKE SAs for ALL peers and users&lt;/P&gt;&lt;P&gt;(Q)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quit&lt;/P&gt;&lt;P&gt;*******************************************&lt;/P&gt;&lt;P&gt;1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer&amp;nbsp; 172.16.10.132, user md5 4d1ec04c938f7451:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. IKE SA &amp;lt;f433b35763e193c9,ad88db390b67a16a&amp;gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer&amp;nbsp; 172.16.10.132, user md5 4d1ec04c938f7451:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. SPI's related to IKE SA &amp;lt;f433b35763e193c9,ad88db390b67a16a&amp;gt;:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INBOUND:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. 0xd70c4ede&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OUTBOUND:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. 0x70b7338c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying "vpn shell" appears not to work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; vpn shell tunnels/show/IPSec/all&lt;BR /&gt;&amp;nbsp;arrange_objects: Not supported&lt;/P&gt;&lt;P&gt;I also tried looking in the log files for both the appliance and the Endpoint Security product, but was unable to find anything informative in their either.&amp;nbsp; Is there a particular log file that would log what settings were used to establish the connection?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 19:18:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8291#M171</guid>
      <dc:creator>Kris_Jurka</dc:creator>
      <dc:date>2018-07-13T19:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: 730 Remote Access VPN: Show/Configure Encryption</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8292#M172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This information can definitely be found in logs when managing the 1400 series appliances with central management.&lt;/P&gt;&lt;P&gt;I am checking with R&amp;amp;D on these locally managed appliances.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 22:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/730-Remote-Access-VPN-Show-Configure-Encryption/m-p/8292#M172</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-13T22:33:13Z</dc:date>
    </item>
  </channel>
</rss>

