- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- StrongSwan and SCV
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
StrongSwan and SCV
Good day.
According to manual StrongSwan doesn't support SCV. But are there any options to exclude StrongSwan clients from SCV checking? We need to use StrongSwan and we need to use SCV for Endpoint. Right now it's imposible.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found answer
:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SCV can be disabled for clients that don't support it in Global Properties:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know about this option. But unfortunately it does not cover strongswan.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Possible this feature doesn't cover Strongswan since it was only added in R81.
However, it's reasonable to expect it to work since even the product documentation says this isn't supported: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/T...
This should be reported via TAC: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From my understanding doesn't support means that strongSwan clients will be excluded from checking but not blocking.
So I hope that somewhere in registry or config file you have solution for this case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All roads lead to TAC.
This checkbox (and the logic behind it) is meant to address non-SCV clients.
The fact it is not working in this case suggests a possible bug.
If this is a bug, TAC would have to confirm.
If there is a fix for this, TAC would have to deliver it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found answer
:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume this is in trac.config, right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No.
In local.scv file 🙂
