Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JaeYoung_An
Explorer

Forcing AES encryption Algorithm for SNX user

Hi, Expert.

I would like to force AES for SNX user?

 I’ve tried many ways, but user is keep using 3DES only. Can we force AES?

JaeYoung_An_0-1686213903859.png

 

 JaeYoung_An_1-1686213903865.png

 

I’ve also followed https://support.checkpoint.com/results/sk/sk113114 to disable 3DES, but always 3DES is used.

This is same even in latest version.

Can anyone Advise how to use AES or confirm we can’t use AES?

JaeYoung_An_2-1686213903866.png

 

2023-06-08_14-57-21.png

 

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

What precisely are the clients in this case?
If they're Linux, I suspect you're out of luck similar to: https://support.checkpoint.com/results/sk/sk180837 
Windows and macOS SNX support AES on currently supported versions.

0 Kudos
JaeYoung_An
Explorer

It's Windows 10 client with chrome browser

gateway version is R81.20

please refer to below pic

2023-06-09_13-11-01.png

0 Kudos
PhoneBoy
Admin
Admin

You may want to make 100% certain 3DES is disabled globally per: https://support.checkpoint.com/results/sk/sk113114
Otherwise, I suggest a TAC case to assist: https://help.checkpoint.com 

0 Kudos
Massimo_Manzato
Participant

sk116156 https://support.checkpoint.com/results/sk/sk116156  tell AES is supported by MacOS SNX client starting from R80.10

 

image.png

 

this obviously suggest that the SNX Server side support this encryption method  as showed here:

image.png

Why this is not working ?

if I use SNX client or CAPSULE from windows the connections is always in 3DES.

there is a Check Point Employee that can explain how to solve  using GuiDBEDIT?

thanks

Massimo

0 Kudos
PhoneBoy
Admin
Admin

Don't know that (gui)dbedit is the solution here.
I know this SK only mentions SMB appliances, but I see the referenced kernel variable on regular gateways (at least in R82): https://support.checkpoint.com/results/sk/sk112314
It's worth a shot.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events