<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: install a Certificate for IPSec VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159312#M27869</link>
    <description>&lt;P&gt;If you are about to replace the cluster members in an existing cluster, you will only remove the old device from the cluster and initiate SIC with the new member, the policy for the cluster stays&amp;nbsp; the same and the same certificate will be installed on the new device. If you create a new cluster with the new devices you must have the certificate to import it to the new cluster.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 06:24:56 GMT</pubDate>
    <dc:creator>MartinTzvetanov</dc:creator>
    <dc:date>2022-10-12T06:24:56Z</dc:date>
    <item>
      <title>install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/87684#M11002</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;is it possible to install a public certificate for IPSec VPN without creating TrustCA or CSR?&lt;/P&gt;&lt;P&gt;Supposed that I already have a public certificate vpn.domain.com, I just want install it...&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 811px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6388i7620D80A40C6D1F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 01:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/87684#M11002</guid>
      <dc:creator>Alex_Wu</dc:creator>
      <dc:date>2020-06-09T01:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/87851#M11003</link>
      <description>Yes, use Add to import it.&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Jun 2020 07:40:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/87851#M11003</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2020-06-10T07:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/88343#M11004</link>
      <description>&lt;P&gt;finally, you have to generate CSR if you import it...&lt;/P&gt;&lt;P&gt;i now have a certificate, i just want o replace the default certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 08:43:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/88343#M11004</guid>
      <dc:creator>Alex_Wu</dc:creator>
      <dc:date>2020-06-12T08:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159295#M27865</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm worndering the same as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20149"&gt;@Alex_Wu&lt;/a&gt;, in my case I'm replacing old Cluster to new gateway models, so, I need to import the IPSec VPN Certificate which resides in the SMS, but there is no such option to Import the certificate to the new Cluster. If you click "Add" it takes you to generate the CSR, but I already have the signed certificate, you need to import it.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 21:42:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159295#M27865</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2022-10-11T21:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159296#M27866</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm worndering the same as&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20149" target="_blank"&gt;@Alex_Wu&lt;/A&gt;, in my case I'm replacing old Cluster to new gateway models, so, I need to import the IPSec VPN Certificate which resides in the SMS, but there is no such option to Import the certificate to the new Cluster. If you click "Add" it takes you to generate the CSR, but I already have the signed certificate, I just need to import it, ¿is there a way do do this?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 21:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159296#M27866</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2022-10-11T21:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159312#M27869</link>
      <description>&lt;P&gt;If you are about to replace the cluster members in an existing cluster, you will only remove the old device from the cluster and initiate SIC with the new member, the policy for the cluster stays&amp;nbsp; the same and the same certificate will be installed on the new device. If you create a new cluster with the new devices you must have the certificate to import it to the new cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 06:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159312#M27869</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2022-10-12T06:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159359#M27888</link>
      <description>&lt;P&gt;I have a new CLuster because new models (6600) vs old models (4800) are different in hardware and software, also&amp;nbsp;&lt;/P&gt;&lt;P&gt;Indeed I have the certificate which I can export form the SMS, &lt;SPAN&gt;but there is no such option to Import the certificate to the new Cluster. If you click "Add" it takes you to generate the CSR, but I already have the signed certificate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159359#M27888</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2022-10-12T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159365#M27890</link>
      <description>&lt;P&gt;If both the old and new gateways are managed by the same management, there is no need to do this as new certificates will be generated and automatically trusted.&lt;BR /&gt;Any third party will validate the certificate is valid through the certificate authority.&lt;BR /&gt;So I’m not sure why this is necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159365#M27890</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-12T14:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159380#M27893</link>
      <description>&lt;P&gt;Hello and thank you for your support.&lt;/P&gt;&lt;P&gt;Yes, both are managed by the same management, but the certificate is from an external CA (Digicert). Let me show you some images for better explanation:&lt;/P&gt;&lt;P&gt;This is the current CLuster which I need to replace, it has the certificate signed by Digicert CA.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="current_.png" style="width: 532px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18104iACF7D803CEE1B91F/image-size/large?v=v2&amp;amp;px=999" role="button" title="current_.png" alt="current_.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now, this is the new Cluster which I'm preparing for migration, so, I need to ensure it has the same certificate as current Cluster. I know I can export the certificate from the SMS with&amp;nbsp;&lt;EM&gt;export_p12&amp;nbsp;&lt;/EM&gt;command, but there is not option to import such certificate in the Cluster properties:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="new_.png" style="width: 552px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18106iFEE98C575BB2B0E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="new_.png" alt="new_.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I click "Add" this takes me to generate the CSR, but this process was made in the past whe creating the certificate for the current cluster.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="csr.png" style="width: 452px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18107iFD568430561BD26F/image-size/large?v=v2&amp;amp;px=999" role="button" title="csr.png" alt="csr.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So, my question&amp;nbsp; is whether there is a method to import the certificate directly, or need to make the signing process again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 15:43:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159380#M27893</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2022-10-12T15:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159394#M27896</link>
      <description>&lt;P&gt;Thanks for the screenshots, this helps a lot.&lt;BR /&gt;In this case, you must generate a new certificate via a Certificate Signing Request as we do not support importing private keys for VPN usage.&lt;BR /&gt;I suspect we don't allow this to maintain the security of the private key.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 19:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/159394#M27896</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-12T19:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/261964#M51361</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I understand this is quite an old topic. However, since 2022 I’ve been wondering if there’s any way to import an already existing SSL certificate for an IPsec VPN on R81.20 - just like it’s possible to do for the Platform Administration Web Portal, UserCheck and Mobile Access portal ?&lt;BR /&gt;Is there any supported method or workaround to achieve this?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 09:34:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/261964#M51361</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2025-11-06T09:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262013#M51377</link>
      <description>&lt;P&gt;Yes, just follow the same information as listed above.&amp;nbsp;You will have needed to generate the CSR from SmartConsole here, tho, as PhoneBoy noted above. &amp;nbsp;Certificates for the other portals are a separate matter, because they use a different internal infrastructure on the gateways (multiportal), whereas IPsec VPN certificates are the VPN and IKE daemons.&lt;/P&gt;
&lt;P&gt;As far as importing arbitrary pre-made certificates, then no, you cannot do that. &amp;nbsp;The certificate information (CN, etc.) needs to match the gateway's own information in order to be used correctly. &amp;nbsp;This what the CSR generation process does for you. &amp;nbsp;Plus, this ensures the private key is stored securely on the management server (and pushed to the gateways).&lt;/P&gt;
&lt;P&gt;When you have the completed certificate, you can finish the enrollment with the "Complete" button, which will become available for that certificate.&lt;/P&gt;
&lt;P&gt;When the certificate is imported, you can select the certificate within the IPsec VPN configuration for the specific remote VPN gateway peer. &amp;nbsp;Edit the interoperable device peer, select IPsec VPN on the left, and you can choose the match criteria for it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 15:32:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262013#M51377</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-11-06T15:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262086#M51414</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/694"&gt;@Duane_Toler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thank you for your prompt response.&lt;/P&gt;&lt;P&gt;I understand that no changes have been made by Check Point regarding this.&lt;BR /&gt;Unfortunately, the current/supported procedure doesn’t apply to my scenario: I’m using a wildcard SSL certificate issued by a public CA. It would have been ideal to use it not only for other portals, but also for client VPNs.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 23:01:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262086#M51414</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2025-11-06T23:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: install a Certificate for IPSec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262094#M51415</link>
      <description>&lt;P&gt;Ah. Unfortunately, you can't use a wildcard certificate in this fashion.&lt;/P&gt;
&lt;P&gt;Here's the SK article on creating the 3rd party CA and any intermediate CAs, then generating the CSR with that CA:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk149253" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk149253&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 01:06:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/install-a-Certificate-for-IPSec-VPN/m-p/262094#M51415</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-11-07T01:06:08Z</dc:date>
    </item>
  </channel>
</rss>

