[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [FW1] IKE mode for Secure Client connections
Tried this also, and can confirm that my objects.C has (under the firewall object), a line saying: :ISAKMP_aggressive_support (false) So either i've got something else wrong somewhere, or Secure Client doesn't support Main Mode ISAKMP? -jonny On Mon, 30 Jul 2001, Jim Brown wrote: > Push the policy after you make the change in the properties page. > > -----Original Message----- > From: [email protected] > [mailto:[email protected]] > Sent: Sunday, July 29, 2001 11:04 PM > To: [email protected] > Subject: [FW1] IKE mode for Secure Client connections > > > > Hi again folks, > > After having another go at tackling the IPSec RFC's i've answered a few of > my own questions... But still remaining is: > > How do I make my secure client connections negotiate the Security > Association with Main Mode (Identity Protection) IKE? > I'm not too keen to have my User Names passed in cleartext when they > shouldn't need to be. > > On my Firewall object, VPN Tab, under 'IKE' - I have unticked "Supports > Aggresive Mode", yet the Secure Client connections still negotiate the > security association with this mode. > > I've tried updating the Client topology, restarting Secure Remote - but no > joy. The only thing left to try (which i'm not entirely prepared to try) > is a complete firewall restart. > Maybe Secure Client only supports Aggressive Mode? > > Can anyone help?? > > Thanks, > -jonny > > > -- > > Jonny Robertson > Wellington > New Zealand > > > > > > ============================================================================ > ==== > To unsubscribe from this mailing list, please see the instructions at > http://www.checkpoint.com/services/mailing.html > ============================================================================ > ==== > ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|