<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Significance of Gateway Certificate when we have Pre-shared Keys based S2S VPNS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/201500#M37951</link>
    <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone can help me understanding the Certificate significance in case we are not using it for S2S VPN:--&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue: S2S VPNs between Checkpoint gateways weren't working; identified expired certificates. Renewing them resolved the problem.&amp;nbsp; We renewed the certificate on both the gateways. Its a Mesh Topology and in Hub and Spoke deployment. Only Checkpoint gateways are affected. Other Spokes are working fine in the community which are not the checkpoint gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queries:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In Pre-shared key VPN deployment (Meshed/Star topology), is a certificate necessary? If yes why ? what is the significance of this certificate ?&lt;/LI&gt;&lt;LI&gt;Are the renewed certificates signed by the CMA ?&lt;/LI&gt;&lt;LI&gt;The current certificate is renewed for a year. Is there a provision for extending the renewal period or adjusting the expiration date?&lt;/LI&gt;&lt;LI&gt;Can you share the SNMP traps so that we can actively monitor it.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Tue, 26 Dec 2023 04:48:18 GMT</pubDate>
    <dc:creator>bSingh</dc:creator>
    <dc:date>2023-12-26T04:48:18Z</dc:date>
    <item>
      <title>Significance of Gateway Certificate when we have Pre-shared Keys based S2S VPNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/201500#M37951</link>
      <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone can help me understanding the Certificate significance in case we are not using it for S2S VPN:--&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue: S2S VPNs between Checkpoint gateways weren't working; identified expired certificates. Renewing them resolved the problem.&amp;nbsp; We renewed the certificate on both the gateways. Its a Mesh Topology and in Hub and Spoke deployment. Only Checkpoint gateways are affected. Other Spokes are working fine in the community which are not the checkpoint gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queries:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In Pre-shared key VPN deployment (Meshed/Star topology), is a certificate necessary? If yes why ? what is the significance of this certificate ?&lt;/LI&gt;&lt;LI&gt;Are the renewed certificates signed by the CMA ?&lt;/LI&gt;&lt;LI&gt;The current certificate is renewed for a year. Is there a provision for extending the renewal period or adjusting the expiration date?&lt;/LI&gt;&lt;LI&gt;Can you share the SNMP traps so that we can actively monitor it.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 26 Dec 2023 04:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/201500#M37951</guid>
      <dc:creator>bSingh</dc:creator>
      <dc:date>2023-12-26T04:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Significance of Gateway Certificate when we have Pre-shared Keys based S2S VPNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/201670#M37952</link>
      <description>&lt;P&gt;Some answers:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The default VPN authentication for S2S VPN is certificate-based. Pre-Shared is considered less secure and is only supported for cases when your VPN peer belongs to another security domain.&lt;/LI&gt;
&lt;LI&gt;GW VPN certificates, like all other internal certificates, are signed by your domain CA&lt;/LI&gt;
&lt;LI&gt;The default expiration period for VPN certificates is one year for all supported versions. You can extend it to three years, see&amp;nbsp;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk176527.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;AFAIK, there are no SNMP traps for certificates. However, there are multiple other means to follow up and check the validity of GW VPN certificates. Look into&amp;nbsp;&lt;SPAN&gt;sk104400,&amp;nbsp;sk178304,&amp;nbsp;sk102092,&amp;nbsp;sk97792. In essence, you will have either SmartConsole warning, or you can run a CLI command to check.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 28 Dec 2023 08:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/201670#M37952</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-12-28T08:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Significance of Gateway Certificate when we have Pre-shared Keys based S2S VPNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/202487#M38102</link>
      <description>&lt;P&gt;Thanks Val for sharing the information..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 14:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Significance-of-Gateway-Certificate-when-we-have-Pre-shared-Keys/m-p/202487#M38102</guid>
      <dc:creator>bSingh</dc:creator>
      <dc:date>2024-01-08T14:26:25Z</dc:date>
    </item>
  </channel>
</rss>

