<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Crash VPN if CPSM server is not available in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154774#M26302</link>
    <description>&lt;P&gt;CRL is an important part of secured VPN. Once CLR cache is expired GWs are supposed to pull the new one. CRL expiration time is set in the Global Properties on your Management Server.&lt;/P&gt;
&lt;P&gt;If your SmartManagment Server is down for a long time, VPN tunnel failure is very likely. I would suggest Management HA.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Aug 2022 12:05:43 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-08-09T12:05:43Z</dc:date>
    <item>
      <title>Crash VPN if CPSM server is not available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154760#M26299</link>
      <description>&lt;P&gt;Good afternoon!&lt;BR /&gt;If our CPSM server is not available, then the VPN on the devices in the branch stops working after 24 hours hours or less. This is the expected result. But we would like to increase this time in case the CPSM fails. We used on the information in this article: &lt;A href="https://indeni.com/blog/check-point-firewalls-certification-revocation-list-crl-check-mechanism-on-a-check-point-gateway/" target="_blank"&gt;https://indeni.com/blog/check-point-firewalls-certification-revocation-list-crl-check-mechanism-on-a-check-point-gateway/&lt;/A&gt;&lt;BR /&gt;We supposed that the problem occurs when a device in a branch office cannot get an up-to-date list of CRL.&lt;/P&gt;&lt;P&gt;Branches use CheсkPoint 1430/1530. Everything is managed centrally through CPSM.&lt;BR /&gt;The CRL file on the device itself in the /pfrm2.0/config1/fw1/database directory is up to date.The internal_ca parameters are set to "Fetch new CRL after 48 hours", but the desired result has not been achieved. VPN disconnected again after 24 hours.&lt;BR /&gt;How can we increase VPN uptime if CPSM is not available?&lt;/P&gt;&lt;P&gt;In the admin guide I found the following information:&lt;BR /&gt;"If CRL Cache is enabled, choose whether a CRL is deleted from the cache when it expires or after a fixed period of time (unless it expires first). The second option encourages retrieval of a CRL more often as CRLs may be issued more frequently than the expiry time. By default a CRL is deleted from the cache after 24 hours."&lt;/P&gt;&lt;P&gt;With any cache settings in the properties of the certificate authority, will the cache on the device in the branch office be cleared after 24 hours anyway? Is there a way to keep the VPN working if the CPSM/CRL Server is unavailable?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 09:13:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154760#M26299</guid>
      <dc:creator>startlook</dc:creator>
      <dc:date>2022-08-09T09:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Crash VPN if CPSM server is not available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154771#M26300</link>
      <description>&lt;P style="font-weight: 400;"&gt;Some options exist, do you have a secondary manager?&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Please refer:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100731" target="_blank" rel="noopener"&gt;sk100731: VPNs go down within 24 hours after primary Security Management server goes down&lt;/A&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk21156" target="_blank" rel="noopener"&gt;sk21156: Disabling CRL checking when authenticating with certificates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 11:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154771#M26300</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-09T11:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Crash VPN if CPSM server is not available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154774#M26302</link>
      <description>&lt;P&gt;CRL is an important part of secured VPN. Once CLR cache is expired GWs are supposed to pull the new one. CRL expiration time is set in the Global Properties on your Management Server.&lt;/P&gt;
&lt;P&gt;If your SmartManagment Server is down for a long time, VPN tunnel failure is very likely. I would suggest Management HA.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 12:05:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Crash-VPN-if-CPSM-server-is-not-available/m-p/154774#M26302</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-08-09T12:05:43Z</dc:date>
    </item>
  </channel>
</rss>

