- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Good day.
According to manual StrongSwan doesn't support SCV. But are there any options to exclude StrongSwan clients from SCV checking? We need to use StrongSwan and we need to use SCV for Endpoint. Right now it's imposible.
Found answer
:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine
SCV can be disabled for clients that don't support it in Global Properties:
I know about this option. But unfortunately it does not cover strongswan.
Possible this feature doesn't cover Strongswan since it was only added in R81.
However, it's reasonable to expect it to work since even the product documentation says this isn't supported: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/T...
This should be reported via TAC: https://help.checkpoint.com
From my understanding doesn't support means that strongSwan clients will be excluded from checking but not blocking.
So I hope that somewhere in registry or config file you have solution for this case.
All roads lead to TAC.
This checkbox (and the logic behind it) is meant to address non-SCV clients.
The fact it is not working in this case suggests a possible bug.
If this is a bug, TAC would have to confirm.
If there is a fix for this, TAC would have to deliver it.
Found answer
:skip_firewall_enforcement_check (false) caused trouble. With :skip_firewall_enforcement_check (true) works fine
I assume this is in trac.config, right?
No.
In local.scv file 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY