NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] IKE mode for Secure Client connections



Tried this also, and can confirm that my objects.C has (under the firewall
object), a line saying:

:ISAKMP_aggressive_support (false)

So either i've got something else wrong somewhere, or Secure Client
doesn't support Main Mode ISAKMP?

-jonny



On Mon, 30 Jul 2001, Jim Brown wrote:

> Push the policy after you make the change in the properties page.
>
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]]
> Sent: Sunday, July 29, 2001 11:04 PM
> To: [email protected]
> Subject: [FW1] IKE mode for Secure Client connections
>
>
>
> Hi again folks,
>
> After having another go at tackling the IPSec RFC's i've answered a few of
> my own questions...  But still remaining is:
>
> How do I make my secure client connections negotiate the Security
> Association with Main Mode (Identity Protection) IKE?
> I'm not too keen to have my User Names passed in cleartext when they
> shouldn't need to be.
>
> On my Firewall object, VPN Tab, under 'IKE' - I have unticked "Supports
> Aggresive Mode", yet the Secure Client connections still negotiate the
> security association with this mode.
>
> I've tried updating the Client topology, restarting Secure Remote - but no
> joy.  The only thing left to try (which i'm not entirely prepared to try)
> is a complete firewall restart.
> Maybe Secure Client only supports Aggressive Mode?
>
> Can anyone help??
>
> Thanks,
> -jonny
>
>
> --
>
> Jonny Robertson
> Wellington
> New Zealand
>
>
>
>
>
> ============================================================================
> ====
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
> ============================================================================
> ====
>




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.