- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- VPN encryption method
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN encryption method
I'm not sure this is the right group, but it's the closest I can find:
Is SHA256 actually supported on R75.20? I can see the tunnel is established using SHA256, but the traffic seems to be trying to go through with SHA1, and failing because there are no valid SAs.
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This appears to be a known bug in R75.20 per this SK: Traffic does not pass over Site-to-Site VPN tunnel when choosing SHA-256 for IKE Phase 2 negotiation
You can try asking TAC for the appropriate hotfix, but I highly recommend upgrading to a supported release as R75.20 has been End of Support for quite some time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the confirmation. We are planning to upgrade this firewall. Hopefully, this will give it some urgency.
