<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness collector agent and GW VPN certificate renewal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204475#M38569</link>
    <description>&lt;P&gt;That for sure makes sense to me. Just doing some Azure studying now, but will check later in the lab,&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 00:05:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-01-30T00:05:04Z</dc:date>
    <item>
      <title>Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203772#M38404</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The gateway VPN certificates are coming up to expire so need to renew those.&amp;nbsp; I gather though that that is the certificate that is used for trust between the identity collector agent.&amp;nbsp; Is there anything that needs to be done on the IA Agent server as well and would there be impact for when we do the renewal on the GW in terms of identities?&amp;nbsp; We're not using third party certificate provider for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 21:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203772#M38404</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2024-01-21T21:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203773#M38405</link>
      <description>&lt;P&gt;Normally, you would get at least one week warning, but with R81+, I believe its 60 days. There is no risk, you can easily do it in the middle of the day. I done so with customers many times before and was fine. Though, to be 100% sure, maybe better do it after normal working hours. I never even seen a single case where any VPN tunnel went down when this was done. To my recollection, there was never an issue with IA agents either.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 21:42:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203773#M38405</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-21T21:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203793#M38408</link>
      <description>&lt;P&gt;Thanks for the advice and didn't have any blips for IA or need to do anything on the collector side which is great &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 04:49:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203793#M38408</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2024-01-22T04:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203820#M38413</link>
      <description>&lt;P&gt;Good to hear &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 12:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/203820#M38413</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-22T12:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204471#M38565</link>
      <description>&lt;P&gt;Could you please advise on how to renew this certificate or how can i check the expiration date. The gateway is only running ID blade and not any VPN blade. The ID collector says VPN certificate so where do I view or renew on the Gateway&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 23:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204471#M38565</guid>
      <dc:creator>Sajid_Abbas</dc:creator>
      <dc:date>2024-01-29T23:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204472#M38566</link>
      <description>&lt;P&gt;I was referring to vpn cert, which would be there if you are running vpn blade on the fw. If not, maybe attach a screenshot, so we can verify.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 23:49:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204472#M38566</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-29T23:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204474#M38568</link>
      <description>&lt;P&gt;You need to temporarily enable IPSEC VPN blade, then IPSec VPN then select the cert and click renew then disable VPN blade again.&amp;nbsp; You don't need to push after enabling/disabling is just to get the VPN section in GW properties to appear.&amp;nbsp; I did have an SK showing this but can't find it at the moment but will add if I can find it&lt;/P&gt;&lt;P&gt;This should give the expiry date&lt;/P&gt;&lt;P&gt;cpca_client lscert -stat Valid -kind IKE&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 23:59:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204474#M38568</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2024-01-29T23:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204475#M38569</link>
      <description>&lt;P&gt;That for sure makes sense to me. Just doing some Azure studying now, but will check later in the lab,&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 00:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204475#M38569</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-30T00:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204476#M38570</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14352"&gt;@Sajid_Abbas&lt;/a&gt;&amp;nbsp;Just tested what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31775"&gt;@cem82&lt;/a&gt;&amp;nbsp;said, worked exactly how he described.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 00:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/204476#M38570</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-30T00:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205509#M38784</link>
      <description>&lt;P&gt;Hey bro, this one?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk97792" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk97792&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205509#M38784</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-02-08T20:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205516#M38786</link>
      <description>&lt;P&gt;Was a combination of these.&amp;nbsp; There was another one that said to run a tcpdump as well to see cert expiry that got me on the right track but can't locate or that SK has been updated/removed to not show that bit anymore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk113021" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk113021&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105723" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105723&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk97792" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk97792&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205516#M38786</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2024-02-08T20:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness collector agent and GW VPN certificate renewal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205517#M38787</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:52:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-collector-agent-and-GW-VPN-certificate/m-p/205517#M38787</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T20:52:12Z</dc:date>
    </item>
  </channel>
</rss>

