<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate VPN Certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172191#M31279</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71552"&gt;@GSallin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it is possible, but below discussion might be helpful:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/quot-unknown-quot-certificate-on-management-server/m-p/164407#M32920" target="_blank"&gt;https://community.checkpoint.com/t5/Management/quot-unknown-quot-certificate-on-management-server/m-p/164407#M32920&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 15:22:59 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-21T15:22:59Z</dc:date>
    <item>
      <title>Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172177#M31268</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have a question. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My customer&amp;nbsp;is currently using a virtual GW as VPN GW, the VPN users have to authenticate themselves with a certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The customer wants to replace his GW with a new one (new release), is it possible to migrate the certificate from the old GW to the the new one?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 14:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172177#M31268</guid>
      <dc:creator>GSallin</dc:creator>
      <dc:date>2023-02-21T14:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172183#M31272</link>
      <description>&lt;P&gt;Why not update the existing GW to the new release ? This would keep everything...&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:05:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172183#M31272</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-21T15:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172184#M31273</link>
      <description>&lt;P&gt;Because he want to restart from scratch with a new one&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172184#M31273</guid>
      <dc:creator>GSallin</dc:creator>
      <dc:date>2023-02-21T15:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172188#M31276</link>
      <description>&lt;P&gt;Not possible without TAC afaik.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:12:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172188#M31276</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-21T15:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172189#M31277</link>
      <description>&lt;P&gt;In general, there is no way to export the private key of a gateway and import it to another.&lt;BR /&gt;If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.&lt;BR /&gt;Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.&lt;/P&gt;
&lt;P&gt;More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172189#M31277</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-21T15:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172191#M31279</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71552"&gt;@GSallin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it is possible, but below discussion might be helpful:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/quot-unknown-quot-certificate-on-management-server/m-p/164407#M32920" target="_blank"&gt;https://community.checkpoint.com/t5/Management/quot-unknown-quot-certificate-on-management-server/m-p/164407#M32920&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/172191#M31279</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-21T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189536#M34905</link>
      <description>&lt;P&gt;Hi Phone Boy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 GWs, a 3800 (R80.40) and an 1800 (R80.20.50).&lt;/P&gt;&lt;P&gt;According to your comment, can I use the same certificate to connect to different GW's VPN if they use the same MGMT (Same CA)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried, but in the logs (after&amp;nbsp;&lt;STRONG&gt;vpn debug ikeon&lt;/STRONG&gt;), I see the below in the smart logs:&lt;/P&gt;&lt;P&gt;It's strange, it can see the correct DN, but shows "user DN unknown" and for the key install it shows "invalid certificate".&lt;/P&gt;&lt;P&gt;Any ideas please?&lt;/P&gt;&lt;P&gt;I also tried to create a new client certificate and enroll that one to the other GW, but still fails.&amp;nbsp; (i.e. one client certificate per gw per user)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN-unknownuser.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22065i8A1EE22A1A1EEC98/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN-unknownuser.png" alt="VPN-unknownuser.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN-unknownuser1.png" style="width: 658px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22066iFBA538A4675941A0/image-dimensions/658x386?v=v2" width="658" height="386" role="button" title="VPN-unknownuser1.png" alt="VPN-unknownuser1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 13:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189536#M34905</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-08-15T13:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189559#M34915</link>
      <description>&lt;P&gt;Suggest involving the TAC to troubleshoot this: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:45:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189559#M34915</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-15T21:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189569#M34920</link>
      <description>&lt;P&gt;Please also note that R80.20.x will be EOL in Oct-23, please refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/#embedded-security" target="_blank"&gt;https://www.checkpoint.com/support-services/support-life-cycle-policy/#embedded-security&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 22:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-VPN-Certificate/m-p/189569#M34920</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-15T22:27:15Z</dc:date>
    </item>
  </channel>
</rss>

