<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New VPN site to site on the same domain &amp;quot;Main Mode Sent Notification to Peer: invalid certi in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218392#M41687</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both gateways version R81.20 Jumbo 65 and on the other one 26. Installed policy on both.&lt;BR /&gt;The communication to the management is via Internet and there is a firewall which protects it.&lt;BR /&gt;The new firewall is configure to have a private ip natted to public one, to go on Internet.&lt;BR /&gt;On gateway object, I configured under vpn link selection use Ip selection by remote peer, always use as statically natted ip, its public one.&lt;BR /&gt;As source ip address,I selected manually on the topology, using the internal ip address which is nattet to the public ip.&amp;nbsp;&lt;BR /&gt;I configured master file to use public management and log ip addresses and on vpn excluded services, FW ICA is excluded.&lt;BR /&gt;The vpn to management works, but communication to crl does not happen and no log seen on management firewall about it.&lt;/P&gt;</description>
    <pubDate>Sat, 22 Jun 2024 21:48:15 GMT</pubDate>
    <dc:creator>Ilovecheckpoint</dc:creator>
    <dc:date>2024-06-22T21:48:15Z</dc:date>
    <item>
      <title>New VPN site to site on the same domain "Main Mode Sent Notification to Peer: invalid certificate"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218368#M41680</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have just installed a firewall on an existing MDS domain.&lt;/P&gt;&lt;P&gt;I haven't specified the PSK key, as it needs to use certificate authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the message seen on new gateway:&amp;nbsp;&amp;nbsp;Main Mode Sent Notification to Peer: invalid certificate&lt;/P&gt;&lt;P&gt;This is the log on old gateway:&amp;nbsp;&amp;nbsp; Phase1 Received Notification from Peer: invalid certificate&lt;/P&gt;&lt;P&gt;It reaches the crl.&lt;/P&gt;&lt;P&gt;What could be the cause?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 18:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218368#M41680</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2024-06-21T18:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: New VPN site to site on the same domain "Main Mode Sent Notification to Peer: invalid certi</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218369#M41681</link>
      <description>&lt;P&gt;What's the version/JHF level?&lt;BR /&gt;Did you push policy to the old and new gateways?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 18:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218369#M41681</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-21T18:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: New VPN site to site on the same domain "Main Mode Sent Notification to Peer: invalid certi</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218392#M41687</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both gateways version R81.20 Jumbo 65 and on the other one 26. Installed policy on both.&lt;BR /&gt;The communication to the management is via Internet and there is a firewall which protects it.&lt;BR /&gt;The new firewall is configure to have a private ip natted to public one, to go on Internet.&lt;BR /&gt;On gateway object, I configured under vpn link selection use Ip selection by remote peer, always use as statically natted ip, its public one.&lt;BR /&gt;As source ip address,I selected manually on the topology, using the internal ip address which is nattet to the public ip.&amp;nbsp;&lt;BR /&gt;I configured master file to use public management and log ip addresses and on vpn excluded services, FW ICA is excluded.&lt;BR /&gt;The vpn to management works, but communication to crl does not happen and no log seen on management firewall about it.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2024 21:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218392#M41687</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2024-06-22T21:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: New VPN site to site on the same domain "Main Mode Sent Notification to Peer: invalid certi</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218393#M41688</link>
      <description>&lt;P&gt;I would start with basic debug&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-generate some traffic&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;check vpnd and iked files in $FWDIR/log&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2024 00:20:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218393#M41688</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-23T00:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: New VPN site to site on the same domain "Main Mode Sent Notification to Peer: invalid certi</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218412#M41690</link>
      <description>&lt;P&gt;sometimes just renewing the certificate on both peers resolves such issues.&lt;/P&gt;
&lt;P&gt;if that won't help, verify crl check is made and to what IP, and if communication works bi directional by running: 'tcpdump -nnei any port 18264'&lt;/P&gt;
&lt;P&gt;if that is not the issue, i agree to continue with vpn debug on both sides.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2024 18:05:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-VPN-site-to-site-on-the-same-domain-quot-Main-Mode-Sent/m-p/218412#M41690</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-06-23T18:05:42Z</dc:date>
    </item>
  </channel>
</rss>

