- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi ,
I need to do below changes on the Traditional Mode Configuration in checkpoint VPN .
Phase 1 and 2 Algorithm
DPD Action
DPD Delay
DPS timeout
Can anyone suggest , how we can do those changes as I am in R81.20 version
Afaik, since R77.30 you are no more able to create or edit Traditional Mode Policies, In https://support.checkpoint.com/results/sk/sk171035 you can read details. I would suggest to contact CP TAC as this is a very special case...
What precise reason do you still use Traditional Mode VPN?
DPD support was added in R77.10, which is well after Traditional Mode VPN were formally deprecated in the NGX (R60) release.
What you're asking for, I suspect, is not possible.
Hi Phone,
Thanks for the reply.
We are having old VPN is in place and now vendor came us to do few changes at VPN end for more security.
Thanks
I would suggest to contact CP TAC to review the situation and provide an easy solution here!
I agree with @G_W_Albrecht , just call TAC and see what can be done to fix this.
Andy
I don't see how TAC can help someone to move forward from a non-supported tech. It looks more like a PS project. However, I would suggest re-hauling the VPN solution and moving to supported features. There is not much justification for using Traditional VPN at all.
I would say that sk Guenther provided is a good start. I just ran it in my lab and Im sure it can help.
Andy
https://support.checkpoint.com/results/sk/sk171035
Command from the lab:
[Expert@CP-MANAGEMENT:0]# mgmt_cli show package name "R81.20-CP-LAB-POLICY"
The main reasons come customers were still using Traditional Mode VPN have been solved:
Traditional Mode VPN also isn't accelerated with SecureXL, if I recall correctly (thus worse performance).
So, yeah, there really isn't a reason to run Traditional Mode VPN anymore.
There could be a possible workaround like tweaking Trad VPN Config using dbedit that is only known to TAC...
Good point...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY