Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
akurtasanov
Participant
Jump to solution

StrongSwan and SCV

Good day.

According to manual StrongSwan doesn't support SCV. But are there any options to exclude StrongSwan clients from SCV checking? We need to use StrongSwan and we need to use SCV for Endpoint. Right now it's imposible.

0 Kudos
1 Solution

Accepted Solutions
akurtasanov
Participant

Found answer 

:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine


View solution in original post

0 Kudos
8 Replies
PhoneBoy
Admin
Admin

SCV can be disabled for clients that don't support it in Global Properties:

image.png

0 Kudos
akurtasanov
Participant

I know about this option. But unfortunately it does not cover strongswan.

0 Kudos
PhoneBoy
Admin
Admin

Possible this feature doesn't cover Strongswan since it was only added in R81.
However, it's reasonable to expect it to work since even the product documentation says this isn't supported: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/T... 

This should be reported via TAC: https://help.checkpoint.com

0 Kudos
akurtasanov
Participant

From my understanding doesn't support means that strongSwan clients will be excluded from checking but not blocking.

So I hope that somewhere in registry or config file you have solution for this case.

0 Kudos
PhoneBoy
Admin
Admin

All roads lead to TAC.

This checkbox (and the logic behind it) is meant to address non-SCV clients.
The fact it is not working in this case suggests a possible bug.
If this is a bug, TAC would have to confirm.
If there is a fix for this, TAC would have to deliver it.

0 Kudos
akurtasanov
Participant

Found answer 

:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine


0 Kudos
PhoneBoy
Admin
Admin

I assume this is in trac.config, right?

0 Kudos
akurtasanov
Participant

No.

In local.scv file 🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 11 Jul 2024 @ 10:00 AM (BST)

    CheckMates Live London

    Tue 30 Jul 2024 @ 05:00 PM (CEST)

    Under the Hood: CloudGuard Controller Unleashed

    Thu 11 Jul 2024 @ 10:00 AM (BST)

    CheckMates Live London
    CheckMates Events