- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Remote access Menu under Global Properties
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remote access Menu under Global Properties
Hi All,
We have CP R81.10 security gateway, I have come across the 'Remote Access' menu under Global Properties. This menu contains several settings such as 'VPN - Authentication' and 'VPN - Advanced,' among others. Could you explain the purpose of these settings and the impact of modifying them on the system's security and functionality?
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ihenock1011
You can set various things here. To determine which setting change will ruin your Remote Access gateway depends on what you set.
Please narrow down your question, and we will help.
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @AkosBakos for your response. Most specifically I want to know VPN Authentication Tab which holds Encryption Method, Encryption Algorithms, Support Authentication note that I have radius server for remote access Authentication.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ihenock1011
If you want to know the performance impact of changing algorithms this sk useful. I think this is a most important thing in the RemoteAccess GW's life.:
https://support.checkpoint.com/results/sk/sk105119
From the help:
Support Authentication Methods
- Pre-Shared Secret - the user password is specified in the Authentication tab in the user's IKE properties (in the user properties window: Encryption tab > Edit).
- Public Key Signatures - enable Public Key in the Authentication tab in the user's IKE properties. If the certificate presented by the user is issued by the Internal CA, generation of the user's certificate is done in the Certificate tab of user properties (in the user properties window: Encryption tab > Edit).
- Supports Legacy Authentication for SecureClient- This includes Hybrid mode which means other VPN authentication methods, as specified in the Authentication tab of the user properties.
- Support Legacy EAP - EAP stands for Extensible Authentication Protocol.
- Support L2TP with Pre-Shared Key - Use a centrally managed pre-shared key for IKE. Type in the pre-shared key.
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SK @AkosBakos mentioned is your best reference mate. But, having said that, I would NOT modify those settings you mentioned in global properties. I once had customer call me in panic saying, ra is broken, vpn tunnels are broken, I call her, find out she changed bunch of those settings because she read online they can help. Well, needless to say, I told her to revert it and all started working again.
Im sure she had lots of explaining to do with her boss after lol
Anyway, UNLESS there is a good reaosn to change them, I would not bother, just my personal opinion.
Andy
