<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSLVPN Issues R82 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277694#M46271</link>
    <description>&lt;P&gt;make wireshark capture and look for any hints like:&amp;nbsp;&lt;SPAN&gt;HTTP response is "200 OK", and the OCSP response is "Successful"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Scan the website with SSL labs that uses the certificate for any hints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it maybe an ancient certificate with low encryption methods?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you updated the CA list on the fw?&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Make 100% sure there is no proxy. OSCP checks will NOT work via proxy&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk121432" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk121432&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jun 2026 18:25:16 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2026-06-01T18:25:16Z</dc:date>
    <item>
      <title>SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277590#M46252</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I'm dealing witih some strange behavior. Let me explain:&lt;/P&gt;&lt;P&gt;Customer has a Maestro Security Group that is running one VS with MAB enabled (for SSL VPN).&amp;nbsp; They are authenticating every user with personal certificates issued by public authorities. Initially the cluster was running R81.10 so being old the customer eventually upgraded to R82 Take 91.&lt;/P&gt;&lt;P&gt;Since then, there's one authority that is no longer working affecting 'bout 400 users.&amp;nbsp; Workaround &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; generated internal certificates and everyone's happy. For the moment!&lt;/P&gt;&lt;P&gt;Upon cvpnd debug (and lol, it's same error in SmartConsole but I though that I will find diamonds there) the error that haunts me is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[5455][28 May 19:34:50][AUTHNMAN] [CVPN_ERROR] Cvpn::AuthnManager::renegotiateCb: res=(0) - there was an error during renegotiation.&lt;BR /&gt;[5455][28 May 19:34:50][AUTHNMAN] [CVPN_INFO] Cvpn::AuthnManager::renegotiateCb: Certificate is not revoked&lt;BR /&gt;[5455][28 May 19:34:50][AUTHNMAN] [CVPN_WARNING] Cvpn::AuthnManager::doFailedOnRenegotiateError: Renegotiation failed. Error message: 'SSL renegotiation failed with error: 'Failed to fetch OCSP. Make sure the security gateway has an outgoing http access, and that the proxy and DNS servers are well configured.''&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried everything!&amp;nbsp; Gateway has full internet access, it can reach the certificate's decalred OCSP server. I have even tried to force CRL. I have replicated the environment in my homelab and I have basically the same configuration (with different public facing IP address) and even installed&amp;nbsp; R82 Take 113 as there was&amp;nbsp;&lt;SPAN&gt;PRJ-65538 that caught my eye.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Case opened - India TAC - allow me to say useless as the engineer was looking at the portal's certificate and said it's not the same as customer's certificate &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I literally have no idea what the hell happened from R81.10 to R82 but "Failed to fetch OCSP" is driving me crazy.&lt;BR /&gt;&lt;BR /&gt;Any ideas will really be appreciated.&amp;nbsp;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 17:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277590#M46252</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2026-05-28T17:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277685#M46268</link>
      <description>&lt;P&gt;Have you confirmed the URL in the Certificate Authority key is reachable from the gateway with curl_cli?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 17:33:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277685#M46268</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-01T17:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277689#M46269</link>
      <description>&lt;P&gt;Do you use a proxy or is there a proxy in the path of the firewall? Can you access with curl from vs0 and from the relevant vs? They both need internet access. g_tcpdump would help if you pull the OSCP server from the certificate and capture on that while you see the error. It should be port 80 with Wireshark you can see if something happens. What was the result of the home lab?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 17:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277689#M46269</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-01T17:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277691#M46270</link>
      <description>&lt;P&gt;Hi gents,&lt;BR /&gt;Yes&amp;nbsp; both vs0 and vs1&amp;nbsp; can reach the OCSP Server (checked by curl_cli -v ).&amp;nbsp;&lt;BR /&gt;There's no proxy between, the gateway has direct internet access.&lt;BR /&gt;&lt;BR /&gt;Homelab as well, same issue with this authority.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 17:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277691#M46270</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2026-06-01T17:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277694#M46271</link>
      <description>&lt;P&gt;make wireshark capture and look for any hints like:&amp;nbsp;&lt;SPAN&gt;HTTP response is "200 OK", and the OCSP response is "Successful"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Scan the website with SSL labs that uses the certificate for any hints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it maybe an ancient certificate with low encryption methods?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you updated the CA list on the fw?&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Make 100% sure there is no proxy. OSCP checks will NOT work via proxy&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk121432" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk121432&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 18:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277694#M46271</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-06-01T18:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSLVPN Issues R82</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277695#M46272</link>
      <description>&lt;P&gt;Yes sir! Followed all possible SKs. There is no proxy in between, as there are other 30+ authorities that are working fine. And again, this was working fine until R82 upgrade.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 18:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SSLVPN-Issues-R82/m-p/277695#M46272</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2026-06-01T18:27:32Z</dc:date>
    </item>
  </channel>
</rss>

