- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We have a customer with a requirement to provide remote access connectivity using IKEv2 via the native operating system (no client) VPN supplicant (Windows, MacOS, possibly iOS and Android) and connect to Gateways running R80.40. Has anyone successfully done this and have any guides they'd be willing to share? Figured out how to navigate the conflicting encryption/authentication methods between the various OSes?
According to this, we support IKEv2 as of E88.40: https://support.checkpoint.com/results/sk/sk166415
However, it is not enabled by default and requires a registry hack to enable, which is why it isn't working with IKEv2 currently.
No. No secure solution available - and R80.40 will be end of support in 8 months...
Please refer to sk166415 for the answer, which is "No, not at this moment". If you have a business case for this, please raise an RFE through the usual channels.
This SK is also valid for Gaia embedded right?
It's not explicitly listed, but it should apply there as well.
Note that the release notes for R82 EA explicitly lists IKEv2 support.
It also requires specific Endpoint client versions.
R82 is planned for Embedded Gaia also.
Interestingly, we find this in the release notes of R81.20 Take 70:
PRJ-48210, |
VPN |
IKEv2 Remote Access stability issues. |
Yes, because some clients already use IKEv2:
R82 will add support for IKEv2 for our native (Windows, macOS) VPN clients.
Whether you will be able to configure IKEv2 in e.g. Windows without Capsule VPN is a separate question.
Is there any update to this? I tried last week at CPX 2025 to get a definitive answer about this and hit a brick wall.
I am using R82 in a lab environment. IKE v2 is enabled. Capsule Connect for IOS connects and uses IKE v2, but the latest Windows Remote Access VPN Client (Check Point Mobile) E88.60 Build 986105801 still does not support IKE v2.
VPN connection is only possible when: "Prefer IKE v2, support IKE v1" is selected.
Capsule Connect for IOS connects and uses IKE v2 perfectly, but if "IKE 2 only" is selected, then the Windows VPN Client cannot connect. The documentation says it is supported.
My R82 Gateway is using the following settings for Remote Access VPN:
Phase 1: AES-256. SHA256, DH Group 21 (521-BIT ECP)
Phase 2: AES-256. SHA256.
The above works perfectly, but only when IKE v1 is supported.
I've tried low encryption settings, but it makes no difference to the IKE issue.
According to this, we support IKEv2 as of E88.40: https://support.checkpoint.com/results/sk/sk166415
However, it is not enabled by default and requires a registry hack to enable, which is why it isn't working with IKEv2 currently.
Hello PhoneBoy,
Thanks very much for publishing the solution.
I can confirm that IKE v2 is now working with my R82 Lab setup using the Windows Remote Access VPN Client [E88.60] using the Registry modification 😃.
I'm assuming a future release of the Windows Remote Access VPN Client will remove the need to make a manual Registry change?
I assume so, yes.
Since testing the disable_ikev2 Registry workaround with Remote Access VPN Client for Windows version E88.60 Build 986105801, and confirming IKEv2 did actually work, Check Point have now released the the Remote Access VPN Client for Windows version E88.63 Build 986105843 - and unfortunately the disable_ikev2 Registry workaround no longer works.
Update: 2025-03-11: The Remote Access VPN Client for Windows version E88.70 Build 986105912 doesn't work with the Registry workaround either. The only option is to re-enable the setting: Prefer IKEv2, support IKEv1 in Global Properties.
(The Remote Access VPN Client for Windows is installed in Check Point Mobile Mode)
The VPN connection fails with the message: The gateway does not support IKEv1.
This is really disappointing.
Can Check Point's official roadmap be shared as to when IKEv2 will be fully supported in the Remote Access VPN Client for Windows?
Also, just my observation, but why does the Remote Access VPN Client for Apple Mac seem to be getting all the attention, with major feature enhancements being released far sooner than the Windows version? In my experience, businesses have far greater dependencies on corporate Windows machines needing VPN access to the network, Mac's are rarely a priority in the corporate landscape.
I would report the issue with IKEv2 not working in the newer clients via TAC.
We paused our normal Harmony Endpoint releases on Windows for a period of time to address some performance, stability, and resource utilization issues, which should be fixed in E88.70 (see also the upcoming TechTalk: https://checkpoint.zoom.us/webinar/register/7716236883663/WN_H8rPnR5ETkOxoDh9kEdnag )
This impacts the standalone VPN clients also, which use the same code.
Meanwhile, we've had a couple of Harmony Endpoint releases on macOS (E89.01 being the most current).
I expect the Windows version will "catch up" to the Mac version in the coming weeks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
7 | |
6 | |
6 | |
6 | |
5 | |
4 | |
3 | |
3 |
Wed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY