Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MikeH
Participant
Jump to solution

IKEv2 Remote Access guides?

We have a customer with a requirement to provide remote access connectivity using IKEv2 via the native operating system (no client) VPN supplicant (Windows, MacOS, possibly iOS and Android) and connect to Gateways  running R80.40.  Has anyone successfully done this and have any guides they'd be willing to share?  Figured out how to navigate the conflicting encryption/authentication methods between the various OSes?

 

 

0 Kudos
1 Solution

Accepted Solutions
_Val_
Admin
Admin

Please refer to sk166415 for the answer, which is "No, not at this moment". If you have a business case for this, please raise an RFE through the usual channels.

View solution in original post

0 Kudos
8 Replies
G_W_Albrecht
Legend Legend
Legend

No. No secure solution available - and R80.40 will be end of support in 8 months...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
_Val_
Admin
Admin

Please refer to sk166415 for the answer, which is "No, not at this moment". If you have a business case for this, please raise an RFE through the usual channels.

0 Kudos
lgarridor
Explorer

This SK is also valid for Gaia embedded  right?

0 Kudos
PhoneBoy
Admin
Admin

It's not explicitly listed, but it should apply there as well.
Note that the release notes for R82 EA explicitly lists IKEv2 support.
It also requires specific Endpoint client versions.

R82 is planned for Embedded Gaia also.

(1)
Alex-
Leader Leader
Leader

Interestingly, we find this in the release notes of R81.20 Take 70:

 

PRJ-48210,
PMTR-91011

VPN

IKEv2 Remote Access stability issues.

0 Kudos
PhoneBoy
Admin
Admin

Yes, because some clients already use IKEv2:

  • Capsule VPN clients, which are largely wrappers around the built-in supplicants in the underlying OS, e.g. Windows).
  • Strongswan for Linux, which has been supported since R81.

R82 will add support for IKEv2 for our native (Windows, macOS) VPN clients.

Whether you will be able to configure IKEv2 in e.g. Windows without Capsule VPN is a separate question.

0 Kudos
ccsjnw
Participant

Is there any update to this? I tried last week at CPX 2025 to get a definitive answer about this and hit a brick wall.

I am using R82 in a lab environment. IKE v2 is enabled. Capsule Connect for IOS connects and uses IKE v2, but the latest Windows Remote Access VPN Client (Check Point Mobile) E88.60 Build 986105801 still does not support IKE v2.

VPN connection is only possible when: "Prefer IKE v2, support IKE v1" is selected.

Capsule Connect for IOS connects and uses IKE v2 perfectly, but if "IKE 2 only" is selected, then the Windows VPN Client cannot connect.  The documentation says it is supported.  

My R82 Gateway is using the following settings for Remote Access VPN:

Phase 1: AES-256. SHA256, DH Group 21 (521-BIT ECP)
Phase 2: AES-256. SHA256.

The above works perfectly, but only when IKE v1 is supported.
I've tried low encryption settings, but it makes no difference to the IKE issue.

0 Kudos
PhoneBoy
Admin
Admin

According to this, we support IKEv2 as of E88.40: https://support.checkpoint.com/results/sk/sk166415 
However, it is not enabled by default and requires a registry hack to enable, which is why it isn't working with IKEv2 currently.
The hack is listed in the internal notes of this SK, which I've asked to be made public.
Meanwhile, TAC should be able to provide the necessary change.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events