Skip to main content
Contributor
April 19, 2005
Question

VPN Security Risk - Subnet Key Exchange

  • April 19, 2005
  • 6 replies
  • 4062 views
We are trying to setup a VPN tunnel to a supplier with a Checkpoint NG/AI Firewall. The supplier only provides Host Key Exchange as they say that there is a security risk with Subnet Key Exchange. Have searched the various groups/net, but been unable to find anything on these risks - is this them being lazy or is there something in this? Dan

    6 replies

    Contributor
    April 19, 2005
    I assume your refering to the subnet range being shared, this is normal and doesn' t involve a security risk. If they are ' scared' to share the subnet the can redefine their VPN policies and change the subnet to be shared so that it only encompasses the servers that need to be accesses.
    Contributor
    April 20, 2005
    This is all I thought they would do. But they are on about Subnet Key Exchange during the phase 2 IKE process. On there Checkpoint box they untick the Support Key Exchange on Subnets and of course we can' t connect using our Fortigate as they only do Subnet Key Exchange not Host. Does anyone else know more about this? Thanks in advance, Dan
    Contributor
    April 20, 2005
    The problem is, that most VPN devices (Cisco, FGT) do not support key exchange for subnets. This is not a security issue, but a configuration issue. Although I agree that you want an SA for each and every connection, it does cost you resources - this imho is the main reason Check Point uses Key Exchange for Subnets. The " security risk" is that the same SA (key set) is used for more than one connection (it is used for a complete subnet) but for most companies this is an acceptable risk. I' d just leave it the way it is now - if it works, you' re fine.
    Contributor
    April 20, 2005
    Zedd, sorry for the confusion but FGT do support Subnet Key Exchange. They don' t support Host Key Exchange but Checkpoint do. The problem is the supplier only uses Host Key Exchange for VPN' s and say Subnet Key Exchange is a security risk. We want to find out if they are talking rubbish! Thanks, Dan
    Contributor
    April 20, 2005
    You' re right - sorry for the mixup :)
    Contributor
    April 30, 2005
    This issue has been recently identified as BUG# 26595 and will be implemented in the next maintenance release which is expected end of May. However if people are having the same problem you will need to get interim build 420 from support which has the fix in it. Dan
    Adrian_Lewis
    New Member
    May 2, 2005
    I think I created this bug recognition. Had the same problem with a 400A and a 3rd party Checkpoint VPN endpoint. Kept pestering Fortinet referring to the RFCs as well as the results from their ICSA labs test on the FG60 and eventually they gave in and promised a fix. MR10 is projected for the end of May but as Dan has mentioned the interim build with the fix is available now with the appropriate support contract.