<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN Certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33004#M12591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;all you need really is a p12/capi certificate which can be generated from users group under SmartConsole.&lt;/P&gt;&lt;P&gt;that's all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Feb 2019 14:33:45 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2019-02-13T14:33:45Z</dc:date>
    <item>
      <title>Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33001#M12588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Check Point cluster that has remote access turned on for remote access VPN use.&amp;nbsp; The certificate that secure remote access is using has been found to be using a weak hashing algorithm and/or a RSA key less than 2048 bits.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in need of correcting this and have not been able to find a way to make remote access use a different certificate without possibly breaking SIC or my point to point VPN connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I go into the gateway cluster properties &amp;gt; VPN Clients - I see that "defaultCert" is selected but have not been successful in finding a way to add a new and more secure certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see there are options in Global Properties from the file / launch menu but am hesitant to change anything in there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone assist?&amp;nbsp; Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2019 20:45:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33001#M12588</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2019-02-12T20:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33002#M12589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Try to add it on IPSec VPN tab. Then you should be able change it for VPN Clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 12:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33002#M12589</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2019-02-13T12:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33003#M12590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/78434_cannot generate cert.PNG" /&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the IPSEC options in Gateway Cluster Properties I click on "Add" &amp;gt; enter a certificate name &amp;gt; click " Generate" &amp;gt; and then I receive an error stating "Cannot generate certificate from "internal_ca" Certificate Authority because MY_CLUSTER_NAME already has a certificate generated by "internal_ca" Certificate Authority.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 13:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33003#M12590</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2019-02-13T13:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33004#M12591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;all you need really is a p12/capi certificate which can be generated from users group under SmartConsole.&lt;/P&gt;&lt;P&gt;that's all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33004#M12591</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-02-13T14:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33005#M12592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jerry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what a p12/capi certificate is.&amp;nbsp; The certificate I am trying to replace is the server certificate, not the user or laptop certificates(s).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33005#M12592</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2019-02-13T14:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33006#M12593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The local VPN certificate is actually signed by the Internal CA.&lt;/P&gt;&lt;P&gt;Assuming the remote end is configured to trust certificates signed by the ICA, then replacing the certificate should only involve minimal disruption.&lt;/P&gt;&lt;P&gt;However, the existing VPN certificate must be revoked first.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 03:11:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33006#M12593</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-14T03:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33007#M12594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are describing is exactly what I need to do, I just don't know how to to do it and can't find instructions.&amp;nbsp; I am also cautious as I don't want to inadvertently revoke a cert that is used for SIC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to point me in the right direction or coach me on how to revoke this VPN cert and generate a new one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 16:07:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33007#M12594</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2019-02-14T16:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33008#M12595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I'm having a little trouble figuring that one out as well &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if you merely "renew" the certificate?&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should generate you a new certificate and you can review the number of bits to ensure it's correct.&lt;/P&gt;&lt;P&gt;I believe this will require a policy installation to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, I suggest consulting with the TAC.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/message/39214"&gt;How To Open a Case with TAC and/or Account Services&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 21:20:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/33008#M12595</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-14T21:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/91965#M12596</link>
      <description>&lt;P&gt;In case anyone comes across this post, here is the SK to increase the key size and renew the VPN cert&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111492&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111492&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 20:21:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/91965#M12596</guid>
      <dc:creator>lbcadenco10</dc:creator>
      <dc:date>2020-07-20T20:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/93304#M12597</link>
      <description>&lt;P&gt;Dear&lt;BR /&gt;I have completed all certificate-base remote access vpn,but it prompt below：&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="unknow user.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7474i4F0897BA12AAFE9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="unknow user.png" alt="unknow user.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;"Connection Failed:User Email=jeff.gao@example.com,CN=Jeff.gao,OU=IT,DC=example,DC=cn unknow"&lt;/P&gt;&lt;P&gt;I can not search the example from sk or google&lt;/P&gt;&lt;P&gt;GW:R80.30 and take 214&lt;/P&gt;&lt;P&gt;CA：windows server 2019 and&amp;nbsp;together with AD&lt;/P&gt;&lt;P&gt;client:Non-join-AD and trust CA root cert&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 14:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/93304#M12597</guid>
      <dc:creator>Jeff_Gao</dc:creator>
      <dc:date>2020-08-04T14:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/209734#M12598</link>
      <description>&lt;P&gt;Have you found out the solution? I am having the same issue .-.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 15:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/209734#M12598</guid>
      <dc:creator>VascoNunes</dc:creator>
      <dc:date>2024-03-26T15:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/235306#M12599</link>
      <description>&lt;P&gt;We are having the same issue, did you get the solution for the certificate base authetication.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 11:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Certificate/m-p/235306#M12599</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-11T11:37:20Z</dc:date>
    </item>
  </channel>
</rss>

