<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73649#M11780</link>
    <description>Great job and work. Keep sharing.</description>
    <pubDate>Wed, 29 Jan 2020 10:08:11 GMT</pubDate>
    <dc:creator>Kim_Moberg</dc:creator>
    <dc:date>2020-01-29T10:08:11Z</dc:date>
    <item>
      <title>HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73299#M11777</link>
      <description>&lt;DIV class=""&gt;&lt;P data-unlink="true"&gt;I am sure that the majority of CheckMates users sometime already stumbled upon the article "&lt;A href="https://community.checkpoint.com/t5/Access-Control-Products/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/td-p/38371" target="_self"&gt;HowTo Set Up Certificate Based VPNs with Check Point Appliances - R77 edition&lt;/A&gt;" written by&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;. He is our instructor and CTO at&amp;nbsp;&lt;A href="https://techblog.esc.de/" target="_self"&gt;ESC&lt;/A&gt;&amp;nbsp;and has been working with Check Point Firewalls for almost two decades.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the new &lt;STRONG&gt;R80&lt;/STRONG&gt;.x release an update to his great VPN article was needed. Here we go:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT size="6"&gt;Preface&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Securing virtual private networks (VPNs) in enterprise Site-to-Site environments is an important task for keeping the trusted network and data protected. Also it's critical to avoid any loss of data sovereignty.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When it comes to VPN security many security experts first think of encryption algorithms, perfect forward secrecy (PFS), Diffie-Hellman groups... and a long&amp;nbsp;&lt;SPAN&gt;&lt;U&gt;pre-shared key (PSK).&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What about VPN certificates?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Every security expert knows how much better certificates are for gaining high security levels. Therefore&amp;nbsp;&lt;SPAN&gt;&lt;U&gt;certificates are always best practice&lt;SPAN&gt;&amp;nbsp;in enterprise grade security environments.&lt;/SPAN&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However, most VPN Site-to-Site setups are still based on simple, long lasting pre-shared keys. In many cases these keys were even forgotten by the administrators in charge of keeping the network secure because once configured for the VPN tunnel they are not needed anymore.&lt;/P&gt;&lt;P&gt;This is because it's much quicker and really easy to set up a VPN with a simple pre-shared key than having to deal with certificates and a certificate authority (CA).&lt;/P&gt;&lt;P&gt;But the comfort of choosing PSKs over certificates does not only minimize your security level it also makes you vulnerable to potential attacks and is not as safe as you might expect. Even if you pick a long PSK! This is because tools like 'ike-scan' (&lt;EM&gt;also comes preinstalled with Kali Linux&lt;/EM&gt;), pks-crack etc. make it really easy to crack your PSK. It's just a matter of time.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As a rule of thumb: &lt;STRONG&gt;VPN certificates significantly increase VPN security!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;So let's get started!&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When working with VPN tunnels between Check Point gateways there is &lt;STRONG&gt;&lt;U&gt;absolutely no reason not to use VPN certificates.&amp;nbsp;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 635px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4175i5EAF1BC3B8E0555D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We used the following setup :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway : Check Point Firewall &amp;amp; VPN&lt;/P&gt;&lt;P&gt;Management : Check Point SmartCenter (R80.40)&lt;/P&gt;&lt;P&gt;Remote Office : Check Point 1550 Appliance&lt;/P&gt;&lt;P data-unlink="true"&gt;(it is important to&amp;nbsp;&lt;SPAN&gt;notice that the 1500 SMB appliances can only be centrally managed with R80.30 Jumbo Take_76&amp;nbsp; or R80.40 as mentioned in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157412" target="_self"&gt;sk157412&lt;/A&gt;&amp;nbsp;and &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk163296" target="_self"&gt;sk163296&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;FONT size="5"&gt;Centrally managed&lt;/FONT&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Check Point is well-known for its superior security management solution to which all Check Point gateways are connected. This central management approach makes it remarkably easy to deploy security settings to all connected gateways with a single click on policy installation.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check Point's security management is called SmartCenter Server (or Multi-Domain Security Management) and has a built-in internal certificate authority. This &lt;EM&gt;Internal CA&amp;nbsp;&lt;/EM&gt;enables the global use of certificates between all connected components and gateways right out-of-the-box.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;SPAN&gt;&lt;I&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 678px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4140iEF0F5A8019E6669F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Check Point automatically generates certificates whenever a new Check Point object is created, so you don't have to take care of certificate handling. Check Point does it all for you.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;I&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild3 bearbeitet.png" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4166iB0A54356ABCE6DF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bild3 bearbeitet.png" alt="Bild3 bearbeitet.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Establishing a certificate based VPN in centrally managed Check Point environments is as easy as 1-2-3.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First, create a VPN community for certificate based VPNs (Mesh or Star topology)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild4 bearbeitet.PNG" style="width: 521px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4168i7D1DDEF6FB7B931C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bild4 bearbeitet.PNG" alt="Bild4 bearbeitet.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now let's take a closer look at the settings of the created VPN community.&lt;/P&gt;&lt;P&gt;Check the "Accept all encrypted traffic on: " box and select the "Both center and satellite gateways" in the "&lt;EM&gt;Encrypted Traffic" &lt;/EM&gt;tab&lt;EM&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 612px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4169iCE87A73E1D073FD8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Configure your preferred VPN encryption settings for Phase 1 (IKE) and Phase 2 (IPsec) and allow permanent tunnels if needed.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 625px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4170i9BACFC15598A836D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Leave the checkbox for pre-shared keys unchecked!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 551px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4171i93E5E479DD6D83FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;In the next step we want to activate and configure the needed IPSec VPN blade on the participating gateways. There are two possible options to do this. You can activate the blade in the “&lt;I&gt;General Properties” &lt;/I&gt;tab on the gateway or during the installation when using the &lt;I&gt;&lt;I&gt;“Wizard Method”.&amp;nbsp;&lt;/I&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Classic Method&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Activate the IPSec VPN blade in the "&lt;EM&gt;General Properties" &lt;/EM&gt;tab.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4172iF8CA8BDBA487B1F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Choose your VPN community.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4174iED19E4F2672AEEB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Activate NAT on the participant gateways.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4179i0445BDF659438699/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;..and select the VPN encryption domain of the specific object.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Gateway :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 765px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4191iCA9965A9E449B355/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;RemoteOffice :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4181i945878803AF49393/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(end of Classic Method)&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Wizard Method&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Activate IPSec VPN on your participant gateways.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 776px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4182i6BA7F7BBE29FD31D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Choose your VPN community and activate NAT&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 776px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4183iF33E74FB3EA50151/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;..and select the VPN encryption domain of the specific gateway.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 776px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4184iC11C1C825B05EF72/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;When everything is set verify your VPN certificate and IPSec VPN community.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4186iC68B4C58B793BAC1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;After you have configured the VPN topology for your VPN gateways you should add them to your VPN community (if not already done).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 608px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4188i81DACFC4C6A7B4E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Finally, install the security policy.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 995px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4189i59896A32128FF8A1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The certificate based VPN tunnel is now up and working!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 885px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4190i22A25092386515A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Should the connection to the SMB appliance (in our case the "RemoteOffice") get lost after the policy installation check the "&lt;EM&gt;Connection Persist&lt;/EM&gt;" option and activate "Keep all connections".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4192iA4132C6226A9C8D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;U&gt;&lt;STRONG&gt;Locally managed&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;Check Point's 700 appliances are locally managed. So can be 1100 / 1400 / 1500 appliances.&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4193iC49FE49E032F7E69/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;These SMB appliances have their own local CA!&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;First, let's export our &lt;EM&gt;Internal CA&amp;nbsp;&lt;/EM&gt;to the 1100 / 1400 / 1500 appliance at our remote office.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;In SmartDashboard just navigate to &lt;EM&gt;&lt;STRONG&gt;Manage &amp;gt; Servers and OPSEC Applications... &amp;gt; internal_ca &amp;gt; Edit... &amp;gt; Local Security Management Server &amp;gt; Save As... &lt;/STRONG&gt;&lt;/EM&gt;and export the certificate.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="5"&gt;&lt;FONT size="4"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1to local extended + save .png" style="width: 678px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4195iDB3CD9341490D4B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1to local extended + save .png" alt="1to local extended + save .png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Verify that the locally managed SMB appliance has Site-to-Site VPN enabled.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 599px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4197i95BDFA3C2E95D435/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Import the &lt;EM&gt;&lt;STRONG&gt;internal_ca.crt&lt;/STRONG&gt;&lt;/EM&gt; file to your locally managed SMB appliance.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 963px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4198i1149B46D41418F67/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may want to disable CRL checking if your Management as primary CRL Distribution Point can't be reached or isn't resolvable.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4199i8713BFFB37B2446A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Easy, isn't it? Now we want to export the SMB appliance's certificate to our Management or (if you prefer) issue a certificate request to be signed by our management's &lt;EM&gt;Internal CA&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Option A - Export the SMB appliance's certificate&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Highlight the Internal CA of our SMB appliance (NOT the one we just imported), then click "&lt;STRONG&gt;Export&lt;/STRONG&gt;" and save the file.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4200i5C1A662C06065151/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Go to &lt;EM&gt;&lt;STRONG&gt;VPN &amp;gt;Certificates &amp;gt; Internal Certificates&lt;/STRONG&gt;&lt;/EM&gt; and copy the Certificate CN of the &lt;EM&gt;&lt;STRONG&gt;Internal VPN Certificate&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4201i055618A0A0383E89/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Create a &lt;STRONG&gt;VPN site&lt;/STRONG&gt; for the certificate based VPN tunnel to our VPN Gateway and configure the site to use &lt;STRONG&gt;Certificate&lt;/STRONG&gt; as authentification.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4203iE0AA0CD6DE1619D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Don't forget to select the Remote Site Encryption Domain.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4204iA23C6950975A5AC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the tab &lt;EM&gt;&lt;STRONG&gt;Advanced &amp;gt; Certificate Matching&lt;/STRONG&gt;&lt;/EM&gt; set the "Remote Site Certificate should be issued by" to our Management trusted CA's name and enable permanent tunnels if needed.&lt;/P&gt;&lt;P&gt;We are now finalizing our VPN setup in SmartDashboard on our Management.&lt;/P&gt;&lt;P&gt;Navigate to &lt;EM&gt;&lt;STRONG&gt;Manage &amp;gt; Servers and OPSEC Applications.. &amp;gt; New &amp;gt; CA &amp;gt; Trusted&lt;/STRONG&gt;&lt;/EM&gt; select &lt;EM&gt;&lt;STRONG&gt;OPSEC PKI&lt;/STRONG&gt;&lt;/EM&gt; and open the tab &lt;EM&gt;&lt;STRONG&gt;OPSEC PKI&lt;/STRONG&gt;&lt;/EM&gt; to import our saved SMB &lt;EM&gt;&lt;STRONG&gt;Internal CA&lt;/STRONG&gt;&lt;/EM&gt; file.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 344px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4205iE7DE4C2498EAB1F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 696px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4206i3E11724A6AF27513/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Again, you may want to disable CRL Checking if required.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 376px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4207i82B94E29BA266FFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You'll then find our imported SMB certificate '&lt;EM&gt;CP1550&lt;/EM&gt;' next to our &lt;EM&gt;internal_ca&lt;/EM&gt; within the &lt;STRONG&gt;Trusted CA&lt;/STRONG&gt; list of our Management.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 231px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4208i5C2F8B462DF3BFA2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(end of Option A)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Option B - Issue a certificate request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Go to VPN &amp;gt; Certificates &amp;gt; Installed Certificates and click New Signing Request to generate a new certificate.&lt;/P&gt;&lt;P&gt;Enter a &lt;STRONG&gt;Certificate name&lt;/STRONG&gt; and &lt;STRONG&gt;Subject DN&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 935px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4209i6D2E6E9504E3222F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Export the signing request to a file.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4210iEDB409B8116F17D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Copy the content of the exported file.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 858px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4211i29728795F6CC1D4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the Management start the &lt;STRONG&gt;ICA Management Tool&lt;/STRONG&gt; (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39915" target="_self"&gt;sk39915&lt;/A&gt;), go to &lt;STRONG&gt;Create Certificates&lt;/STRONG&gt; and paste the certificate request into the PKCS#10 text box.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 641px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4212i818EB1361F388BFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create&lt;/STRONG&gt; the signed certificate.&lt;/P&gt;&lt;P&gt;If required change the file name extension of the created certificate to &lt;STRONG&gt;.crt&lt;/STRONG&gt; .&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 241px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4213iD14E9B0620F352E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the SMB appliance click '&lt;STRONG&gt;Upload Signed Certificate'&lt;/STRONG&gt;, select the certificate and click '&lt;STRONG&gt;Complete'&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4214i772B4EE41E15B966/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(end of Option B)&lt;/P&gt;&lt;P&gt;Now simply create an &lt;STRONG&gt;Externally Managed Check Point Gateway&lt;/STRONG&gt; for our SMB appliance and you are all set up and done.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4215iCFA0D23597DD5C76/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When configurating the &lt;STRONG&gt;Matching Criteria&lt;/STRONG&gt; for our SMB appliance, check the &lt;STRONG&gt;DN&lt;/STRONG&gt; box and paste the subject of our SMB appliance &lt;STRONG&gt;Default Certificate&lt;/STRONG&gt; if you took &lt;STRONG&gt;Option A&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4217iB48CBEC284326EDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In case of &lt;STRONG&gt;Option B&lt;/STRONG&gt; first copy the &lt;STRONG&gt;DN&lt;/STRONG&gt; of the created certificate from within &lt;STRONG&gt;ICA Management Tool&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 702px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4218i1C8C2FE0548DB54A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then paste it into the &lt;STRONG&gt;DN&lt;/STRONG&gt; field of the VPN certificate as issued by our &lt;STRONG&gt;&lt;EM&gt;internal_ca&lt;/EM&gt;&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 765px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4219i55D34ABBFC5DD4CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Install the security policy.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 998px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4220i7392E8C664AFC1C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;And check out the working VPN tunnel.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 377px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4221i2E50E9AD0B3FC515/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Special thanks to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32376"&gt;@Ziegelsambach&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32377"&gt;@Joshua&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32375"&gt;@jannag&lt;/a&gt;&amp;nbsp;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Thank you.&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Jan 2020 15:55:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73299#M11777</guid>
      <dc:creator>Dennis_M</dc:creator>
      <dc:date>2020-01-27T15:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73337#M11778</link>
      <description>Great job, guys!</description>
      <pubDate>Fri, 24 Jan 2020 18:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73337#M11778</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-01-24T18:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73647#M11779</link>
      <description>&lt;P&gt;Great work!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 08:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73647#M11779</guid>
      <dc:creator>jannag</dc:creator>
      <dc:date>2020-01-29T08:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73649#M11780</link>
      <description>Great job and work. Keep sharing.</description>
      <pubDate>Wed, 29 Jan 2020 10:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73649#M11780</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2020-01-29T10:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73688#M11781</link>
      <description>&lt;P&gt;OMG Thank you &lt;span class="lia-unicode-emoji" title=":face_blowing_a_kiss:"&gt;😘&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It helped so much. I cannot describe it because I was looking for a solution for hours( I am new to Check Point)&lt;/P&gt;&lt;P&gt;I forgot the VPN domain, silly I know.&lt;/P&gt;&lt;P&gt;Keep up your great work&lt;/P&gt;&lt;P&gt;Greedings &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/73688#M11781</guid>
      <dc:creator>Ziegelsambach</dc:creator>
      <dc:date>2020-01-29T15:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/90419#M11782</link>
      <description>&lt;P&gt;Great job and explained well.&amp;nbsp;&lt;BR /&gt;Can you help me in case certificate is provided by third party for third pary remote gateways in VSX environment?&lt;BR /&gt;CSR provided with help of&amp;nbsp;&lt;SPAN&gt;sk69660.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Harish Rao&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 16:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/90419#M11782</guid>
      <dc:creator>HarishRao</dc:creator>
      <dc:date>2020-07-02T16:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/91969#M11783</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149253" target="_self"&gt;How to generate and install a third-party IPSec Certificate -&amp;nbsp;sk149253&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 21:32:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/91969#M11783</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-07-20T21:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/197629#M36917</link>
      <description>&lt;P&gt;Thanks Much for this. Great article&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 17:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/197629#M36917</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-11-09T17:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo Set Up Certificate Based VPNs with Check Point Appliances – R80.x edition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/213809#M40759</link>
      <description>&lt;P&gt;Great job!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 21:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/m-p/213809#M40759</guid>
      <dc:creator>acantu</dc:creator>
      <dc:date>2024-05-09T21:01:50Z</dc:date>
    </item>
  </channel>
</rss>

