<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN Certificates in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87408#M12434</link>
    <description>Thank you, now it's clear, this sk is very helpfull&lt;BR /&gt;Another question on the topic:&lt;BR /&gt;Would gateway work correctly with wildcard certificate like *.mydomain.com?&lt;BR /&gt;Whether full DNS name matching is required?&lt;BR /&gt;For Example mobile access portal has DNS name sslvpn.mydomain.com and vpn site has vpn.mydomain.com</description>
    <pubDate>Fri, 05 Jun 2020 08:27:58 GMT</pubDate>
    <dc:creator>Maxim_Medvedev</dc:creator>
    <dc:date>2020-06-05T08:27:58Z</dc:date>
    <item>
      <title>SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49149#M12427</link>
      <description>&lt;P&gt;I have a question re SSL VPN certificates - using 3rd party certificates.&lt;/P&gt;&lt;P&gt;My understanding is that if you use SNX you generate the CSR via the IPSec VPN page, get the valid cert, then "complete" the cert via the IPsec VPN page.&amp;nbsp; This certificate has no bearing on Mobile Access.&lt;/P&gt;&lt;P&gt;If you enable Mobile Access, you generate the CSR via the command line, get the cert, then import it via the Platform Portal page.&amp;nbsp; So this is a different cert to what SNX would use.&lt;/P&gt;&lt;P&gt;My customer currently uses SNX (not MAB) and has a certificate for that, with 200 clients connecting using the VPN client.&amp;nbsp; That's working well.&amp;nbsp; But now they're interested in Mobile Access which would require purchasing another certificate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will enabling MAB and installing a new certificate cause the existing VPN clients to moan?&lt;/P&gt;&lt;P&gt;Will the new MAB certificate override what the existing VPN clients see when connecting (and cause a certificate mis-match type error message to pop up for the users)?&lt;/P&gt;&lt;P&gt;Is there a way to use the same certificate for both the IPSec and Platform Portal tabs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 10:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49149#M12427</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-03-29T10:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49151#M12428</link>
      <description>&lt;P&gt;You can use the same certificate. Import your existing certificate to the MOB-configuration via SmartConsole.&lt;/P&gt;&lt;P&gt;If the SNs in the certificate will match again the MOB-Portal DNS-name everything should fine.&lt;/P&gt;&lt;P&gt;And yes you're right, if you enable MOB you get the certificate from the MOB-Portal.&lt;/P&gt;&lt;P&gt;What did you mean with VPN-clients ? SNX is clientless SSL VPN, only the small ssl-extender agent is installed, not a real VPN client.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 10:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49151#M12428</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-29T10:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49152#M12429</link>
      <description>IPSec does not use SSL Certificate&lt;BR /&gt;MAB uses either SSL Cert or IPSec host-based-cert.&lt;BR /&gt;I think you need to learn a little about the MAB and Remote Access security from CP ...&lt;BR /&gt;&lt;BR /&gt;seach support site for sk's about MAB.</description>
      <pubDate>Fri, 29 Mar 2019 11:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49152#M12429</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-29T11:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49153#M12430</link>
      <description>&lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/Create-CSR-and-Importing-third-party-certificate-in-Mobile/td-p/39942" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/Create-CSR-and-Importing-third-party-certificate-in-Mobile/td-p/39942&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Mar 2019 11:04:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49153#M12430</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-29T11:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49164#M12431</link>
      <description>&lt;P&gt;Hello Jerry,&lt;/P&gt;&lt;P&gt;you're right with your answer,&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as I understand Matt, he is already using SNX (SSL extender) and for this an SSL certificate is in use.&lt;/P&gt;&lt;P&gt;And this same certificate can be used to import in the MAB. You can use there the one created from SmrtCenters CA or from a Third Party.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 12:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/49164#M12431</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-29T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87284#M12432</link>
      <description>&lt;P&gt;Hello, Wolfgang&lt;BR /&gt;&lt;BR /&gt;I installed new ssl certificate for Mobile Access in &lt;EM&gt;gateway properties Mobile Access --&amp;gt; Portal Settings --&amp;gt; Certificate --&amp;gt; Replace&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;As I understand this shouldn't have affected setting for vpn clients. Certificate for vpn clients is specified in&amp;nbsp;&lt;EM&gt;gateway properties VPN clients --&amp;gt; the gateway authenticates with this certificate&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But &lt;STRONG&gt;Endpoint Security&lt;/STRONG&gt;&amp;nbsp;vpn client get this error:&amp;nbsp;&lt;EM&gt;The site's security certificate is not trusted&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Therefore gateway use Mobile Access certificate for vpn clients and don't use certificate for vpn clients&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Could you please explain is it normal behavior or bug?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 09:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87284#M12432</guid>
      <dc:creator>Maxim_Medvedev</dc:creator>
      <dc:date>2020-06-04T09:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87306#M12433</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6305"&gt;@Maxim_Medvedev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, this is normal behaviour.&lt;/P&gt;
&lt;P&gt;The first connection from the&amp;nbsp; endpoint-client is a SSL handshake with the gateway. If MOB-blade is activated, this will be done with the MOB certificate.&lt;/P&gt;
&lt;P&gt;Same behaviour is described here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk158334" target="_blank" rel="noopener"&gt;Mobile Access certificate fingerprint presented on Remote Access client&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 11:26:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87306#M12433</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-04T11:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87408#M12434</link>
      <description>Thank you, now it's clear, this sk is very helpfull&lt;BR /&gt;Another question on the topic:&lt;BR /&gt;Would gateway work correctly with wildcard certificate like *.mydomain.com?&lt;BR /&gt;Whether full DNS name matching is required?&lt;BR /&gt;For Example mobile access portal has DNS name sslvpn.mydomain.com and vpn site has vpn.mydomain.com</description>
      <pubDate>Fri, 05 Jun 2020 08:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87408#M12434</guid>
      <dc:creator>Maxim_Medvedev</dc:creator>
      <dc:date>2020-06-05T08:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87412#M12435</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6305"&gt;@Maxim_Medvedev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, that works.&lt;/P&gt;
&lt;P&gt;Wolfgang&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 08:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-Certificates/m-p/87412#M12435</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-05T08:49:17Z</dc:date>
    </item>
  </channel>
</rss>

