- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Cluster of 4800 8GB running R80.30 Take 155 distributed.
No issues running VPN with all kind of Windows PC (Windows client, SSL Extender), but as soon as Mac's stepped in they were unable to launch SNX (would pop up then immediately disconnect) and the VPN client would fail at the site creation. No drops seen in FW logs from the public IP of the client to the public IP of the cluster.
No issues with the same users on the PC systems. After investigation it turned out that cipher_util was used to allow only TLS 1.2 ciphers on primary gateway, but not yet on secondary. Doing a failover solved the issue and Mac OS can now use the client or SNX.
I quickly had a look and don't see this limitation in the release notes or the known limitations, but it works and for now that's all we ask of the system.
So it's a n FYI in case you would suddenly need to support MAC VPN on your TLS 1.2-only MOB and wonder why nothing is working.
I checked with TAC and you need to support the following suites:
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_RC4_128_MD5
I've added the AES ones back and both the client and SNX work now.
Actually, reading the RFC, TLS_RSA_WITH_AES_128_CBC_SHA is mandatory to be supported in TLS 1.2
I checked with TAC and you need to support the following suites:
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_RC4_128_MD5
I've added the AES ones back and both the client and SNX work now.
Actually, reading the RFC, TLS_RSA_WITH_AES_128_CBC_SHA is mandatory to be supported in TLS 1.2
Thanks @Alex-, in my case I only enabled "TLS_RSA_WITH_AES_256_CBC_SHA" and the MAC clients were able to login once more.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY