Index
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X Y Z
A
A Closer Look
A Complete Example of a local.scv File
About ActiveX Controls
Accepting all Encrypted Traffic
Access Control and VPN Communities
Active IPsec PMTU
Add Rules Allowing Communication Inside the VPN Domain
Adding a Language
Adding Matching Criteria to the Validation Process
Additional Considerations
Additional Script Elements
Advanced IKE DoS Attack Protection Settings
Advanced Permanent Tunnel Configuration
Advanced Settings
After Running the Wizard
Allocating Customized Ports
Allowing Clients to Route all Traffic Through a Security Gateway
Allowing Firewall Control Connections Inside a VPN
Anti-Spoofing
Assigning IP Addresses
Associating a RADIUS Server with a Security Gateway
Auth+Encrypt Rules
Authenticating the Client Machine During IKE
Authenticating the User
Authentication
Authentication Between Community Members
Authentication Methods
Authentication of Users
Authentication Timeout and Password Caching
Authentication Timeout Interval
Auto Topology Update (Connect Mode only)
Automatic Enrollment with the Certificate Authority
Automatic RIM
Automatically Renewing a Users' Certificate
Avoiding Double Authentication for Policy Server
B
Behavior of an L2TP Connection
By VPN Domain
C
CA Certificate Rollover
CA Certificate Rollover CLI
CA Located on the LAN
CA of An External Security Management Server
CA Services Over the Internet
Cached Information
Capsule Connect for iOS
Capsule VPN for Android
Capsule Workspace for Android
Capsule Workspace for iOS
Certificate Recovery and Renewal
Certificate Revocation (All CA Types)
Certificates
Check Point GO
Check Point Mobile for Windows
Check Point Remote Access Solutions
Check Point SCV Checks
Check Point Solution for Connectivity Issues
Check Point Solution for Greater Connectivity and Security
Check Point VPN Plugin for Windows 8.1
Checking the Syntax
Choosing a Topology
Choosing the Authentication Method
Choosing the Certificate Authority
Client Properties
Client Side Configuration
Client Side Configuration
Client Side Configuration
Client to Client via Multiple Hubs Using Hub Mode
Client-Based vs. Clientless
Client-side Pre-Requisites
Command Line
Common Attributes
Commonly Used Concepts
Completing the Configuration
Confidentiality
Configurable Objects in a Direction
Configuration File Attributes
Configuration of Client to Client Routing by Including the Office Mode Range of Addresses in the VPN Domain of the Security Gateway
Configuration of PKI Operations
Configuration via Editing the VPN Configuration File
Configuring a Loopback Interface
Configuring a Meshed Community Between Internally Managed Gateways
Configuring a Remote Access Environment
Configuring a Star VPN Community
Configuring a Virtual Interface Using the VPN Shell
Configuring a VPN using a Pre-Shared Secret
Configuring a VPN with External Security Gateways Using PKI
Configuring a VPN with External Security Gateways Using Pre-Shared Secret
Configuring Advanced IKE Properties
Configuring an SCV Policy on the Security Management Server
Configuring Anti-Spoofing on VTIs
Configuring Authentication for NT groups and RADIUS Classes
Configuring CRL Grace Period
Configuring Desktop Security
Configuring Directional VPN Between Communities
Configuring Directional VPN with Remote Access Communities
Configuring Directional VPN Within a Community
Configuring Domain Based VPN
Configuring ESOD Policies
Configuring Explicit MEP
Configuring IKE Over TCP
Configuring Implicit First to Respond
Configuring Implicit Load Distribution
Configuring Implicit MEP
Configuring Implicit Primary-Backup
Configuring IP Assignment Based on Source IP Address
Configuring IP pool NAT
Configuring IP pool NAT
Configuring IP Pool NAT
Configuring IP Selection by Remote Peer
Configuring Link Selection for Remote Access Only
Configuring LSV
Configuring MEP
Configuring MEP
Configuring MEP
Configuring Microsoft Internet Explorer
Configuring Multiple Hubs
Configuring NAT Traversal (UDP Encapsulation)
Configuring Numbered VTIs
Configuring Numbered VTIs
Configuring Numbered VTIs
Configuring OCSP
Configuring Office Mode
Configuring Office Mode and L2TP Support
Configuring On Demand Links
Configuring Outgoing Route Selection
Configuring Preferred Backup Security Gateway
Configuring Remote Access Connectivity
Configuring Remote Access for Microsoft IPsec / L2TP Clients
Configuring Remote Access VPN
Configuring Remote Clients to Work with Proxy Servers
Configuring Return Packets
Configuring RIM
Configuring RIM in a Meshed Community:
Configuring RIM in a Star Community:
Configuring RIM on Gaia
Configuring SCV
Configuring SDL Timeout
Configuring Secure Domain Logon
Configuring Service Based Link Selection
Configuring Site to Site VPNs
Configuring Small IKE phase II Proposals
Configuring Source IP Address Settings
Configuring SSL Network Extender
Configuring the 'Accept VPN Traffic Rule'
Configuring the Languages Option
Configuring the SecuRemote DNS Server
Configuring the Security Gateway as a Member of the Remote Access Community
Configuring the Security Gateway to Support the SSL Network Extender
Configuring the Server
Configuring the Skins Option
Configuring the SSL Network Extender
Configuring Third-Party PKI Certificates
Configuring Traditional Mode VPNs
Configuring Trusted Links
Configuring Tunnel Features
Configuring Unnumbered VTIs
Configuring User Certificate Purposes
Configuring Visitor Mode
Configuring VPN Between Internal Gateways using ICA Certificates
Configuring VPN Routing and Access Control on Security Management Server A
Configuring VPN Routing and Access Control on Security Management Server B
Configuring VPN Routing for Remote Access VPN
Configuring VPN Routing for Security Gateways through SmartDashboard
Configuring VPN with Externally Managed Gateways Using Certificates
Configuring VTIs in a Clustered Environment
Configuring VTIs in a Gaia Environment
Configuring Windows Proxy Replacement
Configuring Wire Mode
Confirming a VPN Tunnel Successfully Opens
Connect Mode
Considerations for Choosing Microsoft IPsec / L2TP Clients
Considerations for VPN Creation
Considerations regarding SCV
Conversion of Auth Encrypt Rules
Conversion of Client Encrypt Rules
Conversion of Encrypt Rule
Converting a Traditional Policy to a Community Based Policy
Creating a P12 Certificate File
Creating a Skin
Creating and Configuring the Security Gateway
Creating Certificate Registration Key
Creating Remote Access VPN Certificates for Users
CRL
CRL Cache Usage
CRL Grace Period
CRL Prefetch-Cache
Custom Scripts
Customizing the SSL Network Extender Portal
D
Dead Peer Detection
Default Policy
Defense Against IKE DoS Attacks
Defining a User Group
Defining a VPN Community and its Participants
Defining Access Control Rules
Defining an LDAP User Group
Defining the CAs
Defining the Client Machines and their Certificates
Defining the Encrypt Rule
Defining the Encrypt Rule
Defining the Encrypt Rule
Defining the Encrypt Rule
Defining the Encrypt Rule
Defining the Externally Managed Security Gateways
Defining the Internally Managed Security Gateways
Defining the Security Gateways
Defining the Security Gateways
Defining the Security Gateways
Defining the Security Gateways
Defining User and Authentication Methods in LDAP
Defining User Authentication Methods in Hybrid Mode
Defining VPN Properties
Desktop Policy Commands
Desktop Security
Desktop Security Considerations
Desktop Security Considerations
Desktop Security Considerations
Desktop Security Solution
DHCP Server
DHCP Server
DHCP Server
Diffie Hellman Groups
Directional Enforcement between Communities
Directional Enforcement within a Community
Directional VPN Enforcement
Directional VPN in RA Communities
Disabling a Language
Disabling a Skin
Disabling MEP
Disabling MEP
Disabling MEP
Discovering Which Services are Used for Control Connections
Distributed Key Management and Storage
Domain Based VPN
Domain Based VPN
Domain Based VPN
Domain Controller Name Resolution
Downloading and Connecting the Client
Downloading the SCV Policy to the Client
DPD Responder Mode
During IKE phase I
During IKE phase II
During IPsec
Dynamically Assigned IP Security Gateways
E
Editing a Traditional Mode Policy
Enabling a User Certificate
Enabling and Disabling Secure Domain Logon
Enabling Dynamic Routing Protocols on VTIs
Enabling Hub Mode for Remote Access clients
Enabling Hybrid Mode and Methods of Authentication
Enabling IP Address per User
Enabling Route Based VPN
Enabling the RIM_inject_peer_interfaces flag
Enabling Visitor Mode Using a Connection Profile
Enabling Wire Mode on a Specific Security Gateway
Enabling Wire Mode on a VPN Community
Endpoint Security on Demand
Endpoint Security Suite
Endpoint Security VPN
Endpoint Security VPN for Mac
Enrolling a Managed Entity
Enrolling through a Subordinate CA
Enrolling User Certificates - ICA Management Tool
Enrolling with a Certificate Authority
ESOD Issues
ESOD Policy per User Group
Establishing a VPN between a IPsec / L2TP Client and a Gateway
Example
Example
Example
Example
Excluded Services
Explicit MEP
Expressions
Expressions and Labels with Special Meanings
F
Features
Fetching the XML Configuration File
First to Respond
First to Respond
First to Respond
First to Respond
For Internally Managed Users
For More Information
For Users Managed in LDAP
G
Gateway with a Single External Interface
Gateway with an Interface Behind a Static NAT Device
Gateway with Several IP Addresses Used by Different Parties
Granting User Access Using RADIUS Server Groups
Granular Routing Control
H
High Availability and Load Balancing
How an Encrypt Rule Works in Traditional Mode
How does SCV work?
How Office Mode Works
How the Converter Handles Disabled Rules
How the SSL Network Extender Works
How to Authorize Firewall Control Connections in VPN Communities
How to Work with non-Check Point Firewalls
How Traditional VPN Mode Differs from a Simplified VPN Mode
How VPN Works
Hub Mode (VPN Routing for Remote Clients)
I
IKE DoS Attacks
IKE DoS Protection
IKE Over TCP
IKE Phase I
IKE Phase II (Quick mode or IPSec Phase)
ike_dos_max_puzzle_time_daip
ike_dos_max_puzzle_time_gw
ike_dos_max_puzzle_time_sr
ike_dos_puzzle_level_identified_initiator
ike_dos_puzzle_level_unidentified_initiator
ike_dos_supported_protection_sr
ike_dos_threshold
IKEv1 and IKEv2
Implementation
Implicit MEP
Implied Rules
Important Information
Injecting Peer Security Gateway Interfaces
Installation for Users without Administrator Privileges
Installing SCV Plugins on the Client
Installing the Policy
Instructions for End Users
Integrity
Interface Resolution
Internal User Database vs. External User Database
Internally and Externally Managed Security Gateways
Introducing Desktop Security
Introducing Secure Configuration Verification
Introduction to Converting to Simplified VPN Mode
Introduction to L2TP Clients
Introduction to the SSL Network Extender
Introduction to Traditional Mode VPNs
Introduction to VPN
IP Address Lease duration
IP Assignment Based on Source IP Address
IP Compression
IP Pool
IP Pool NAT
IP Pool Network Address Translation (NAT)
IP Pool versus DHCP
ipassignment.conf File
IPsec & IKE
IPsec Path Maximum Transmission Units
IPv6 Support and Limitations
J
Java
L
L2TP Global Configuration
Large Scale VPN
Last Known Available Peer IP Address
Layer Two Tunneling Protocol (L2TP) Clients
Link Selection
Link Selection and ISP Redundancy
Link Selection for Remote Access Clients
Link Selection Overview
Link Selection Scenarios
Link Selection with non-Check Point Devices
LMHOSTS
Load Distribution
Load Distribution
Load Distribution
Load Sharing Cluster Support
Logical Sections
Logs and Alerts
M
Making the L2TP Connection
Making the Organizational Security Policy SCV-Aware
Management of Internal CA Certificates
Managing a CA Certificate Rollover
Managing User Certificates
Manual Enrollment with OPSEC Certified PKI
Manually Set Priority List
MEP Selection Methods
Meshed VPN Community
Methods of Encryption and Integrity
Migrating from Traditional Mode to Simplified Mode
Modifying a Language
Modifying Encryption Properties for Remote Access VPN
Modifying the CRL Pre-Fetch Cache
Monitoring LSV Peers and Tunnels
Multiple Certificates per User
Multiple Entry Point (MEP) VPNs
Multiple Entry Point for Remote Access VPNs
N
NAT and Load Sharing Clusters
NAT Traversal (UDP Encapsulation for Firewalls and Proxies)
Need for Integration with Different PKI Solutions
Non-Private Client IP Addresses
NT Group/RADIUS Class Authentication Feature
Number of Users
Numbered VTI
O
Obtain Information from the Peer Administrator
Obtain Information from the Peer Administrator
Obtain Information from the Peer Administrator
OCSP
Office Mode
Office Mode
Office Mode
Office Mode
Office Mode - DHCP Configuration
Office Mode - IP Pool Configuration
Office Mode - Using a RADIUS Server
Office Mode and Static Routes in a Non-flat Network
Office Mode Configuration on SecureClient
Office Mode Considerations
Office Mode IP assignment file
Office Mode per Site
Office Mode per Site
Office Mode Per Site
Office Mode through the ipassignment.conf File
On Demand Links (ODL)
On the Gateway Network Object
On the Security Gateway:
On the VPN Community Network Object
Other Connectivity Issues
Outgoing Link Tracking
Overcoming NAT Related Issues
Overcoming Restricted Internet Access
Overview
Overview
Overview
Overview of Directional VPN
Overview of Domain-based VPN
Overview of MEP
Overview of Route Injection
Overview of Route-based VPN
Overview of Tunnel Management
Overview of Wire Mode
P
Passive IPsec PMTU
Password Caching
Perfect Forward Secrecy
Permanent Tunnel Mode Based on DPD
Permanent Tunnels
Permanent Tunnels
Permanent Tunnels
Permanent Tunnels in a MEP Environment
Phase I modes
PKI and Remote Access Users
PKI Deployments and VPN
Placing the Client Certificate in the Machine Certificate Store
Placing the Security Gateways into the Communities
Placing the User Certificate in the User Certificate Store
Planning the SCV Policy
Policy Definition for Remote Access
Policy Download
Policy Server
Preferred Backup Security Gateway
Preparing the Client Machines
Pre-Requisites
Preventing a Client Inside VPN Domain from Encrypting
Primary-Backup
Primary-Backup Security Gateways
Principles of the Conversion to Simplified Mode
Protection After Successful Authentication
Public Key Infrastructure
R
RADIUS Server
Random Selection
Recovery and Renewal with Internal CA
Remote Access Advanced Configuration
Remote Access Community
Remote Access Community
Remote Access Community
Remote Access Solution Comparison
Remote Access VPN
Remote Access VPN
Remote Access VPN
Remote Access VPN Workflow
Remote Client to Client Communication
Removing an Imported Certificate
Renegotiating IKE & IPsec Lifetimes
Resolving Connectivity Issues
Resolving Internal Names with the SecuRemote DNS Server
Revocation Checking
Revoking Certificates
RIM
Route Based VPN
Route Based VPN
Route Based VPN
Route Injection Mechanism
Routing all Traffic through the Security Gateway
Routing Multicast Packets Through VPN Tunnels
Routing Return Packets
Routing Return Packets
Routing Return Packets
Routing Table Modifications
Routing Traffic within a VPN Community
Routing VPN Traffic
Runtime SCV Checks
S
Sample
Sample Combination VPN Community
Sample ipassignment.conf File
Sample Remote Access VPN Workflow
Sample Site to Site VPN Deployment
Screened Software Types
SCV Checks
SCV Checks
SCV Checks
SCV Policy Syntax
SCVGlobalParams
SCVNames
SCVPolicy
Secure Configuration Verification
Secure Connectivity and Endpoint Security
Secure Domain Logon (SDL)
Secure Remote Access
SecureClient Commands
SecureClient Connect Profiles and MEP
SecuRemote
SecurID Authentication Devices
Security Gateway Requirements for IPsec / L2TP
Server Configuration
Server Side Configuration
Server Side Configuration
Server Side Configuration
Server-Side Configuration
Server-Side Pre-Requisites
Service Based Link Selection
Service Based Link Selection Scenarios
Sets and Sub-sets
Setting up the Microsoft IPsec/L2TP Client Connection Profile
Simple Deployment – Internal CA
Site to Site VPN
Small IKE Phase II Proposals
SmartDashboard IKE DoS Attack Protection Settings
SmartDashboard Toolbar
SoftID and SecureClient
Solving Remote Access Issues
Special Condition for VPN Security Gateways
Special Considerations
Special Considerations for PKI
Special Considerations for Planning a VPN Topology
Special Considerations for the CRL Pre-fetch Mechanism
Special Considerations for the SSL Network Extender
Special Considerations for Windows Proxy Replacement
Special Considerations for Wire Mode
SSL Network Extender
SSL Network Extender
SSL Network Extender
SSL Network Extender Command Attributes
SSL Network Extender Issues
SSL Network Extender User Experience
Star VPN Community
Subnet masks and Office Mode Addresses
Subnets and Security Associations
Subordinate Certificate Authorities
Summary of Remote Access Options
Supporting a Wide Variety of PKI Solutions
T
Take out Unneeded Drop Rules
Terminating Permanent Tunnels
The Check Point Solution for Multiple Entry Points
The Check Point VPN Solution
The Desktop Security Policy
The Difference between SCVNames and SCVPolicy
The local.scv Sets
The Need for Connectivity Resolution Features
The Need for Desktop Security
The Need for Multiple Entry Point Security Gateways
The Need for Remote Clients to be Part of the LAN
The Need for Supporting L2TP Clients
The Need for VPN
The Need for VPN Routing
The Need to Verify Remote Client's Security Status
The Problem
The Problem
The Problem
The Problem
The Problem
The Secure Configuration Verification Solution
The Solution
The Solution
The Solution
The Solution
The Solution
The Solution
Third Party SCV Checks
To configure the CA to Issue Certificates with Purposes
To Configure the Microsoft IPsec/L2TP Clients so they do not Check for the "Server Authentication" Purpose
Topology and Encryption Issues
Tracing the Status of User's Certificate
Tracking
Tracking Options
Tracking Options
Tracking Options
Traditional Mode VPNs
Troubleshooting SSL Network Extender
Trusted Links
Trusted Links Scenarios
Trusted Sites Configuration
Trusting a CA – Step-By-Step
Trusting An External CA
Trusting an Externally Managed CA
Trusting an ICA
Trusting an OPSEC Certified CA
Tunnel Management
Tunnel Testing for Permanent Tunnels
Types of Solutions
U
Understanding DoS Attacks
Understanding the Terminology
Uninstall on Disconnect
Unique SA Per Pair of Peers
Unnumbered VTI
Upgrading ESOD
User Certificate Creation Methods when Using the ICA
User Certificate Purposes
User Granularity
User Groups as the Destination in RA communities
User Privileges
Using a Pre-Shared Secret
Using Certificates Using Third Party PKI
Using Directional VPN for Remote Access
Using Dynamic Routing Protocols
Using Name Resolution - WINS and DNS
Using Office Mode with Multiple External Interfaces
Using Remote Access VPN
Using Route Based Probing
Using Secure Domain Logon
Using SmartDashboard
Using SSL Network Extender on Linux / Mac Operating Systems
Using the CLI
Using the Internal CA vs. Deploying a Third Party CA
Using the Multiple External Interfaces Feature
Using Trusted Links with Service Based Link Selection
Utilizing Load Sharing
V
Validation of a Certificate
Verifying the SCV Policy
Visitor Mode
Visitor Mode
Visitor Mode
Visitor Mode and Gateway Clusters
Visitor Mode and MEP
Visitor Mode and Proxy Servers
Visitor Mode in a MEP Environment
Visitor Mode When the Port 443 is Occupied By an HTTPS Server
Visitor Mode with SecurePlatform /IPSO
VPN Administration Guide
VPN Between Internal Gateways Using Third Party CA Certificates
VPN Command Line Interface (CLI)
VPN Commands
VPN Communities
VPN Communities
VPN Communities
VPN Components
VPN Connectivity Modes
VPN Domains and Encryption Rules
VPN for a SmartLSM Profile
VPN for Remote Access Considerations
VPN High Availability Using MEP or Clustering
VPN Routing - Remote Access
VPN Routing and Access Control
VPN Shell
VPN Topologies
VPN Tunnel Interface (VTI)
VPN Tunnel Sharing
VPN Tunnel Sharing
VPN Tunnel Sharing
VPN with One or More LSM Profiles
VTIs in a Clustered Environment
W
What is a Policy Server?
When is a Policy Downloaded?
When Responding to a Remotely Initiated Tunnel
When the Client Has a Private Address
When the Converted Rule Base is too Restrictive
Why Turning off Firewall Implied Rules Blocks Control Connections
Windows Proxy Replacement
WINS (Connect Mode Only)
Wire Mode
Wire Mode Between Two VPN Communities
Wire Mode in a MEP Configuration
Wire Mode Scenarios
Wire Mode with Route Based VPN
Working in Connect Mode While Not Connected
Working with Remote Access VPN
Working with RSA Hard and Soft Tokens
Working with Site-to-Site VPN