<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R82: Site to site VPN authentication issue when using certificates in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262265#M51493</link>
    <description>&lt;P&gt;Have you raised a case with TAC?&amp;nbsp; If it is an issue with R82 then will need to be engaged.&lt;/P&gt;</description>
    <pubDate>Sun, 09 Nov 2025 16:27:20 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2025-11-09T16:27:20Z</dc:date>
    <item>
      <title>R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262264#M51492</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When testing the R82 version for VPN site to site between two different Check Point sites (Externally Managed VPN Gateway), I found an authentication issue when using certificates exchange as authentication method. The traffic was rejected. There was no issue when using pre-shared secret .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Reject.jpg" style="width: 746px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32034i80A9EC0CBA4CAD8F/image-dimensions/746x589?v=v2" width="746" height="589" role="button" title="Reject.jpg" alt="Reject.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then I updated Gaia in both SMSs with the "Jumbo Hotfix take 44". I thought that it was going to solve the issue. But result was the same: "Authentication failed".&lt;/P&gt;&lt;P&gt;I rebuilt all again in my LAB, reinstalling and configuring everything from scratch ......&amp;nbsp; with the same results.&lt;/P&gt;&lt;P&gt;Finally I did the same with the R81.20 version (just in case...). Everything was working OK when using the R81.20&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i think there is a really issue when using certificates to authenticate the site to site VPN between two different sites (domains)&lt;/P&gt;&lt;P&gt;If somebody could confirm that it is not an isolated issue but a general one ?&lt;/P&gt;&lt;P&gt;Thanks for your feedback&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 16:24:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262264#M51492</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-11-09T16:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262265#M51493</link>
      <description>&lt;P&gt;Have you raised a case with TAC?&amp;nbsp; If it is an issue with R82 then will need to be engaged.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 16:27:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262265#M51493</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-11-09T16:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262267#M51494</link>
      <description>&lt;P&gt;It is not a production case. I was just testing in my LAB.&lt;BR /&gt;That's why I am using this way to inform people about this issue. Somebody should test it to confirm&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 18:31:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262267#M51494</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-11-09T18:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262269#M51495</link>
      <description>&lt;P&gt;Hey Miguel,&lt;/P&gt;
&lt;P&gt;I know this is smb related post,but see if it helps. Its clear based on the message it does not like something about the cert.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/td-p/73299" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/HowTo-Set-Up-Certificate-Based-VPNs-with-Check-Point-Appliances/td-p/73299&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 19:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262269#M51495</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-09T19:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262271#M51496</link>
      <description>&lt;P&gt;I have been using certificates for VPN authentication since R80 version. I have always worked using the same method. Even with the R77.30, the method is quite the same (with some differences in language and interfaces.)&lt;/P&gt;&lt;P&gt;This time, to be sure my platform was working OK, I made the test&amp;nbsp; using certificates with the R81.20 version. A successful test.&lt;/P&gt;&lt;P&gt;Unless the way of exchanging certificates has changed since R82 version, there is a problem when exchanging certificates for creating new VPN tunnels.&lt;/P&gt;&lt;P&gt;It is hard to believe nobody has already test it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 19:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262271#M51496</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-11-09T19:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262272#M51497</link>
      <description>&lt;P&gt;I really cant confirm that, sorry...lets see if anyone else might know.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Nov 2025 19:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262272#M51497</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-09T19:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262294#M51498</link>
      <description>&lt;P&gt;Just to show how simple is the authentication by certificates. It should work this way, and it is not working in R82 version:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First, you save your certificate. You are going to share this certificate with the distant site:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Saving certificate.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32035i347F3C64C6E5DC72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Saving certificate.jpg" alt="Saving certificate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt; Then, you use the certificate shared by the distant site, to create a new "Trusted CA" ( as "External Check Point CA")&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Create trusted CA.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32036iF2C34E4C13C468AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Create trusted CA.jpg" alt="Create trusted CA.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Create trusted CA_1.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32037i2CC0DF2721B811A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Create trusted CA_1.jpg" alt="Create trusted CA_1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; By clicking on "&lt;STRONG&gt;Get&lt;/STRONG&gt;" on the "External Check Point CA" tab, you will select the distant site certificate that have been shared by your partner.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And that's it. Don't forget to uncheck "&lt;STRONG&gt;Use only share Secret for all External&lt;/STRONG&gt; members"&amp;nbsp;in the community and if there is already a tunnel built on the community (same tunnel), use &lt;STRONG&gt;vpn tu&lt;/STRONG&gt; in order to delete the previous tunnels (IPsec + IKE SAs)&lt;/P&gt;&lt;P&gt;For me it is a mystery that authentication by sharing certificates is not working anymore since the R82 version.&lt;/P&gt;&lt;P&gt;I haven't tested what happen when a tunnel is already built with certificates before upgrading from R81.20 to R82.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 08:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262294#M51498</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-11-10T08:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262304#M51499</link>
      <description>&lt;P&gt;Let me see if I can test this in the lab. I had this working before and when I upgraded to R82, it still worked fine.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 11:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262304#M51499</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T11:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262368#M51500</link>
      <description>&lt;P&gt;Is your CRL reachable/resolvable? Have you tried turning it off to see if it makes a difference?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 19:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262368#M51500</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-11-10T19:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262456#M51511</link>
      <description>&lt;P&gt;I am not sure it is about a CRL issue. But I will test it next week. This week I am too busy&lt;BR /&gt;Thank you Alex&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 10:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/262456#M51511</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-11-11T10:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264233#M51905</link>
      <description>&lt;P&gt;I thought it was just me who couldn't do it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I have two R82 gateways with separate managements on the office and DataCenter sides. I'm having the same problem.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 06:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264233#M51905</guid>
      <dc:creator>Feridun_ÖZTOK</dc:creator>
      <dc:date>2025-12-03T06:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264272#M51918</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I must say i have not tried with R82, but the steps i usually follow are quit different.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Importa external CA and create a Trusted CA object.&lt;/LI&gt;
&lt;LI&gt;Go to local gateway object &amp;gt; IPsec VPN &amp;gt; Certificates repository. Click add and generate a CSR selecting the Trusted CA created on step 1.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Send CSR to the peer to get it signed.&lt;/LI&gt;
&lt;LI&gt;Import the signed certificate into IPsec certificates repository.&lt;/LI&gt;
&lt;LI&gt;Go to external peer gateway object &amp;gt; IPsec VPN &amp;gt; Matching Criteria, select the external CA created on step 1. Fill up the match conditions, i usually use DN.&lt;/LI&gt;
&lt;LI&gt;Push policy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 13:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264272#M51918</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-12-03T13:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264302#M51927</link>
      <description>&lt;P&gt;Hey, Same thing &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 17:39:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264302#M51927</guid>
      <dc:creator>Feridun_ÖZTOK</dc:creator>
      <dc:date>2025-12-03T17:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264304#M51928</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The first log with error regarding CRL makes me think it is going in the rigth direction. On the trusted CA object go to OPSEC PKI tab and uncheck both options under Rretrieve CRL From section. Does it change anything?&amp;nbsp; You can check&amp;nbsp;&lt;SPAN&gt;sk109139 for reference, it is the same logic but in the sk the certificates are signed by internal CA (management server) instead of the external CA, it should work no matter wich option you use.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 18:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264304#M51928</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-12-03T18:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264344#M51939</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hi All!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;My&lt;/SPAN&gt; &lt;SPAN class=""&gt;client&lt;/SPAN&gt; &lt;SPAN class=""&gt;had&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;problem&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;certificates&lt;/SPAN&gt;&lt;SPAN&gt; somehow&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;And&lt;/SPAN&gt; &lt;SPAN class=""&gt;we&lt;/SPAN&gt; &lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;DN&lt;/SPAN&gt; &lt;SPAN class=""&gt;value&lt;/SPAN&gt;&lt;SPAN&gt; was &lt;/SPAN&gt;&lt;SPAN class=""&gt;set&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;After&lt;/SPAN&gt; &lt;SPAN class=""&gt;we&lt;/SPAN&gt; &lt;SPAN class=""&gt;set&lt;/SPAN&gt;&lt;SPAN&gt; it &lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;Default&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt;&lt;SPAN&gt; was &lt;/SPAN&gt;&lt;SPAN class=""&gt;resolved&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Maybe&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt;&lt;SPAN&gt; will &lt;/SPAN&gt;&lt;SPAN class=""&gt;help&lt;/SPAN&gt; &lt;SPAN class=""&gt;you&lt;/SPAN&gt;&lt;SPAN&gt; too.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 08:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264344#M51939</guid>
      <dc:creator>ShemHunter</dc:creator>
      <dc:date>2025-12-04T08:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264637#M52034</link>
      <description>&lt;P&gt;Hello RS_Daniel,&lt;BR /&gt;&lt;BR /&gt;That is for a third part CA.&amp;nbsp;&lt;BR /&gt;My VPN tunnel is between to gateways managed by their own Check Point CA&amp;nbsp; each one (managed by their own SMS).&amp;nbsp;&lt;BR /&gt;The way of exchanging certificates is strait (no need to go to the repository)&lt;BR /&gt;&lt;BR /&gt;It is about the R82 version issue rather than a configuration or procedure issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried d&lt;SPAN class=""&gt;isabling CRL checking. One log was like this: "&lt;STRONG&gt;Auth exchange: Could not retrieve CRL.CN=sg1 VPN Certificate,O=sms1..b6gyro"......&amp;nbsp;&lt;/STRONG&gt;without success&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 12:32:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264637#M52034</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-12-06T12:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264639#M52035</link>
      <description>&lt;P&gt;Hello RS_Daniel&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I found a way to d&lt;SPAN class=""&gt;isabling CRL checking from Timothy Hall in another issue:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/Disabling-CRL-checking-for-centrally-managed-VPNs/td-p/4882" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/Disabling-CRL-checking-for-centrally-managed-VPNs/td-p/4882&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I entered the command in both gateways,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="disable_CRL.jpg" style="width: 1033px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32331i3C2A1FA8388600BB/image-dimensions/1033x173?v=v2" width="1033" height="173" role="button" title="disable_CRL.jpg" alt="disable_CRL.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And now it works. So it was an issue of the receiving side not being able to retrieve the CRL on the &lt;STRONG&gt;R82&lt;/STRONG&gt; version.&lt;/P&gt;&lt;P&gt;Until Check Point resolves the issue on the R82 version, the only way to make work the VPN tunnel with 2 Check Point CAs (SMSs), is&amp;nbsp;d&lt;SPAN class=""&gt;isabling CRL checking by using the command&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;above&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;I hope this will help&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Miguel&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 13:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264639#M52035</guid>
      <dc:creator>patones1</dc:creator>
      <dc:date>2025-12-06T13:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: R82: Site to site VPN authentication issue when using certificates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264640#M52036</link>
      <description>&lt;P&gt;Excellent Miguel, thanks for letting us know.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 13:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-Site-to-site-VPN-authentication-issue-when-using/m-p/264640#M52036</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-06T13:13:57Z</dc:date>
    </item>
  </channel>
</rss>

