<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIC not automatically renewing certificate in VSX in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258583#M43681</link>
    <description>&lt;P&gt;Thanks PhoneBoy, that looks promising, I will try out the commands to adjust the IP on the standby and see how I get on.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@FW-01:0]# vsenv 2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 2).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:2]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254) &lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:2]# vsenv 3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 3).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:3]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254)&amp;nbsp;&lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:3]# vsenv 4&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 4).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:4]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254)&amp;nbsp;&lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:4]# vsenv 6&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 6).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:6]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (172.x.x.30)&amp;nbsp;&lt;STRONG&gt;CORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2025 15:11:24 GMT</pubDate>
    <dc:creator>P_Williams</dc:creator>
    <dc:date>2025-09-30T15:11:24Z</dc:date>
    <item>
      <title>SIC not automatically renewing certificate in VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258541#M43675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a VSX Cluster that was built nearly 5 years ago and the SIC certificates are expiring in 2026 and in googling how to renew these certificates its becoming clear that it should have done these automatically. I found SK164255 which speaks about SIC not renewing automatically and I found the logs on the firewall&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[CPD 108554 4133026112]@Our-FIREWALL-01[9 Jun 20:48:04] Renew_SIC_Cert_cb: CPD failed to renew sic certificate. status = 3, rc - -1.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;In the SK it lists three ports that are used in the process&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ICA_PULL (port 18210)&lt;/LI&gt;&lt;LI&gt;ICA_PUSH (port 18211)&lt;/LI&gt;&lt;LI&gt;ICA_SERVICES (port 18191)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And when I looked in the logs for port 18191 I can see that the firewalls are trying to communicate on that port with a host called (worryingly) 'sms-dummy' with a different IP to the SMS we use. As this was a completely new build in 2021 by a 3rd party potentially they have created the environment with a temporary SMS and then later on switched over to current SMS, but the firewalls are left trying to renew SIC to the original IP?&lt;/P&gt;&lt;P&gt;What are the options that open to us?&lt;/P&gt;&lt;P&gt;Could I NAT that traffic to the actual SMS?&lt;/P&gt;&lt;P&gt;Or am I going to have go through the resetting of SIC across the environment?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk164255" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk164255&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 11:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258541#M43675</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2025-09-30T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: SIC not automatically renewing certificate in VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258570#M43677</link>
      <description>&lt;P&gt;There's an SK for this situation, it appears:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk103356" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103356&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 13:49:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258570#M43677</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-30T13:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: SIC not automatically renewing certificate in VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258583#M43681</link>
      <description>&lt;P&gt;Thanks PhoneBoy, that looks promising, I will try out the commands to adjust the IP on the standby and see how I get on.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@FW-01:0]# vsenv 2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 2).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:2]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254) &lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:2]# vsenv 3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 3).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:3]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254)&amp;nbsp;&lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:3]# vsenv 4&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 4).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:4]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (10.253.253.254)&amp;nbsp;&lt;STRONG&gt;INCORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:4]# vsenv 6&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Context is set to Virtual Device (ID 6).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[Expert@FW-01:6]# grep -i icaip $CPDIR/registry/HKLM_registry.data&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:ICAip (172.x.x.30)&amp;nbsp;&lt;STRONG&gt;CORRECT&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 15:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258583#M43681</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2025-09-30T15:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: SIC not automatically renewing certificate in VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258660#M43695</link>
      <description>&lt;P&gt;Not sure if you ever enabled below on mgmt server, but might be worth doing it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30501" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30501&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 10:35:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-not-automatically-renewing-certificate-in-VSX/m-p/258660#M43695</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T10:35:01Z</dc:date>
    </item>
  </channel>
</rss>

