Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
MVP Diamond
MVP Diamond
Jump to solution

Ikev2 support for RA vpn clients in R82

Hey guys,

I really hope someone can clarify this for me, because logically, its not clear at all, to me, anyway. So, below sk states following:

https://support.checkpoint.com/results/sk/sk166415

Currently, Security Gateway does not support for IKEv2 connections from Remote Access VPN Clients.

Implementing IKEv2 support is on our roadmap.

It is expected to be available in the R82 release.

Well, R82 is now officially GA, yet, we see this in smart console global properties. Im not sure I understand what word some means in this context...are we talking certain version of vpn clients? if so, which ones?

Screenshot_1.png

 

Thanks as always!

 

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
2 Solutions

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

 

Ultimately yes whilst support is for E88.40 and higher, it also appears that some client versions are impacted by the following limitation e.g E87.60 / E87.62

ESVPN-4235 Connection to R82 Security Gateway may fail if IKEv2 protocol is enabled on that Security Gateway.

CCSM R77/R80/ELITE

View solution in original post

HeikoAnkenbrand
MVP Diamond
MVP Diamond

The info can be found in the following sk181127.

CUT>>>
- What's New in R82
  - Remote Access VPN

  • Security Gateway now supports the IKEv2 protocol for connections from Remote Access VPN Clients (E88.40 and higher).

<<<CUT

➜ CCSM Elite, CCME, CCTE, CCVS ➜ www.checkpoint.tips

View solution in original post

10 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

 

Ultimately yes whilst support is for E88.40 and higher, it also appears that some client versions are impacted by the following limitation e.g E87.60 / E87.62

ESVPN-4235 Connection to R82 Security Gateway may fail if IKEv2 protocol is enabled on that Security Gateway.

CCSM R77/R80/ELITE
HeikoAnkenbrand
MVP Diamond
MVP Diamond

The info can be found in the following sk181127.

CUT>>>
- What's New in R82
  - Remote Access VPN

  • Security Gateway now supports the IKEv2 protocol for connections from Remote Access VPN Clients (E88.40 and higher).

<<<CUT

➜ CCSM Elite, CCME, CCTE, CCVS ➜ www.checkpoint.tips
the_rock
MVP Diamond
MVP Diamond

Thanks a lot, appreciate it!

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Thanks Chris!

 

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
THX1138UK
Explorer

IKEv2 still doesn't work for Windows VPN Clients ☹.

I am using R82 (Release Version) in my Home Lab:

 

SK166415 Updated on 31st October 2024:

THX1138UK_0-1730821188559.png

 

 

 

R82 – Global Properties:

THX1138UK_1-1730821188562.png

 


If Prefer IKEv2, support IKEv1 is selected, then the Windows Client only uses IKEv1.

 

CheckPoint VPN Client for Windows E88.60 – Installed on Windows 11 Pro v24H2:

THX1138UK_2-1730821188566.png

 

 

CheckPoint VPN Client for Windows E88.60 – Latest available (CheckPoint Mobile Mode):

THX1138UK_3-1730821188568.png

 


In addition to E88.60, I also tested E88.40. There is nothing in any release notes that mentions support for IKEv2.

The only VPN client that I have tested that will successfully negotiate IKEv2 with the Security Gateway is Capsule Connect for iOS.
(I don’t have an Apple Mac or Android device available for testing).

0 Kudos
Martin_Raska
Advisor
Advisor

Can someone from Check Point explain why in 2026 you have to change registry to support IKEv2 for VPN. This really does not make any sense to me at all!

Support for IKEv2 in Remote Access VPN Clients - sk166415

What happen when you dont have access to registry, how you handle that situation?

PhoneBoy
Admin
Admin

Part of the issue is gateways don't support IKEv2 for Remote Access until R82.
We actually support deploying the necessary change via Endpoint managed in the Check Point (formerly Infinity) Portal.

0 Kudos
Martin_Raska
Advisor
Advisor

Hi PhoneBoye,

I am aware of that.

The question still remain, why do you have to touch registry in order to support IKEv2, why its not enabled by default?

The client could chose during negotiation what to choose ikev1 or ikev2 or am I wrong?

PhoneBoy
Admin
Admin

The only way to adjust is the registry at current.
Why this method was chosen, I don't know.

0 Kudos
Martin_Raska
Advisor
Advisor

That is the reason I am poiting it out. This must be changed.

IKEv2 = standard, should be default

registry change = no way

0 Kudos
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events