<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN IPSec certificate - different expiration date between cluster object and physical node in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228654#M38214</link>
    <description>&lt;P&gt;Yes, the certificates might be different as the cluster node wasn't part of the cluster at one time (namely when you created the object).&lt;/P&gt;
&lt;P&gt;The cluster certificate is the most relevant here and will be used as long as the gateway is still part of the cluster.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2024 15:41:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-01T15:41:08Z</dc:date>
    <item>
      <title>VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228630#M38207</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have a cluster of firewalls, composed of 2 nodes.&lt;/P&gt;&lt;P&gt;We are using Infinity Playblocks to monitor the expiration date of vpn IPSec certificate.&lt;/P&gt;&lt;P&gt;Infinity Playblocks informed us that the VPN certificate of the physical node-01 was expiring.&lt;/P&gt;&lt;P&gt;The certificate regarding the HA (the cluster object) was not about to expire. I am referring to the certificate we can see from smartconsole in the cluster object&amp;gt;IPSec&amp;gt;view certificate .&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;Is it normal that the VPN certificate of the phisical node has a different expiration date respect the HA VPN certificate?&lt;/P&gt;&lt;P&gt;If it is normal, which certificate is important? If we let the VPN certificate of the physical node expire, but the VPN certificate of cluster is still valid, the vpn will work?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 13:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228630#M38207</guid>
      <dc:creator>Mec</dc:creator>
      <dc:date>2024-10-01T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228654#M38214</link>
      <description>&lt;P&gt;Yes, the certificates might be different as the cluster node wasn't part of the cluster at one time (namely when you created the object).&lt;/P&gt;
&lt;P&gt;The cluster certificate is the most relevant here and will be used as long as the gateway is still part of the cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 15:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228654#M38214</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-01T15:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228656#M38216</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thank you for the reply.&lt;/P&gt;&lt;P&gt;The cluster exist from at least 5 years. We already renew the certificate in the past, so i do not think that is the cause of the different dates.&lt;/P&gt;&lt;P&gt;If we know that the HA certificate is the relevant one, we will disable the alert regarding the expiration of the physical node certificate and we will let them expire .&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 15:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228656#M38216</guid>
      <dc:creator>Mec</dc:creator>
      <dc:date>2024-10-01T15:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228661#M38218</link>
      <description>&lt;P&gt;Are you experiencing any issues or just wondering if its normal?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 16:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228661#M38218</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-01T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228709#M38233</link>
      <description>&lt;P&gt;We do not have any issues.&lt;/P&gt;&lt;P&gt;I was just wondering if it is normal having different expyring dates and if both certificate (physical node and cluster object) are important or if only the cluster certificate matter.&lt;/P&gt;&lt;P&gt;if the physical node certificate does not matter we don't want to receive alert from playblock regarding this certificate.&lt;/P&gt;&lt;P&gt;Since the physical node was expiring i renew the cluster certificate.&lt;/P&gt;&lt;P&gt;Let me add a question.&lt;/P&gt;&lt;P&gt;Renew the certificate of the cluster object from smartconsole, it also renew automatically the certificates of the physicals node?&lt;/P&gt;&lt;P&gt;Thank you all for the reply.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 06:54:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228709#M38233</guid>
      <dc:creator>Mec</dc:creator>
      <dc:date>2024-10-02T06:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec certificate - different expiration date between cluster object and physical node</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228745#M38242</link>
      <description>&lt;P&gt;Fairly certain the answer is no here.&lt;BR /&gt;As stated previously, the member's own certificate is not relevant when the gateway is in a cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 13:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-IPSec-certificate-different-expiration-date-between-cluster/m-p/228745#M38242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T13:58:04Z</dc:date>
    </item>
  </channel>
</rss>

