<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote access vpn with enrolment key certificate not working in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264337#M1436</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using 3600 and 9300 firewall for my customer. I have configured Remote access vpn with enrolment key certificate.&lt;/P&gt;&lt;P&gt;For 3600 firewall it is working fine but for 9300 series firewall it is not working. When I connect through vpn client it shows enrolment failed. Does anybody know why it is not connecting to 9300 series firewall. The configuration is same. Should I have to do any other steps on 9300 series firewall.&lt;/P&gt;&lt;P&gt;Also username + password for RAVPN is working fine but not working for Certifcate+username password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version- R81.20 JHF 118&lt;/P&gt;&lt;P&gt;TAC also haven't find the solution yet. It's pending from 20 days.&lt;/P&gt;&lt;P&gt;Please help me to resolve the issue.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Dec 2025 05:54:24 GMT</pubDate>
    <dc:creator>Mohit136971</dc:creator>
    <dc:date>2025-12-04T05:54:24Z</dc:date>
    <item>
      <title>Remote access vpn with enrolment key certificate not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264337#M1436</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using 3600 and 9300 firewall for my customer. I have configured Remote access vpn with enrolment key certificate.&lt;/P&gt;&lt;P&gt;For 3600 firewall it is working fine but for 9300 series firewall it is not working. When I connect through vpn client it shows enrolment failed. Does anybody know why it is not connecting to 9300 series firewall. The configuration is same. Should I have to do any other steps on 9300 series firewall.&lt;/P&gt;&lt;P&gt;Also username + password for RAVPN is working fine but not working for Certifcate+username password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version- R81.20 JHF 118&lt;/P&gt;&lt;P&gt;TAC also haven't find the solution yet. It's pending from 20 days.&lt;/P&gt;&lt;P&gt;Please help me to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 05:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264337#M1436</guid>
      <dc:creator>Mohit136971</dc:creator>
      <dc:date>2025-12-04T05:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access vpn with enrolment key certificate not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264365#M1439</link>
      <description>&lt;P&gt;Any other relevant messages except enrollment failed?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 14:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264365#M1439</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-04T14:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access vpn with enrolment key certificate not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264367#M1440</link>
      <description>&lt;P&gt;If this is related to machine certificate issue, please see what TAC sent to one of our clients last yer and this actually did work.&lt;/P&gt;
&lt;P&gt;*****************&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Policy had not been installed on the gateways since March 15. Sessions had been published, but not pushed to the gateways. Much of the configuration has taken place since then.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Post installation, we needed to perform sk116997 as the CSP used for the machine certificate did not allow the use of SHA256 hashing for authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- While we were trying to correct the machine certificate CSP, users were unable to connect to the remote access VPN as they did not belong to the remote access community. Performed sk91844 to change "fetch_type" to "fetch_options", and disabled "ldap_fetch" to prevent LDAP lookup of group memberships, as we wanted users to match the generic* profile and not LDAP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Following the successful installation of policy, and the changes detailed in sk116997 and sk91844, we saw machine certificate authentication was being performed during login.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*********************************&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 15:05:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264367#M1440</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-04T15:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access vpn with enrolment key certificate not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264470#M1441</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done the steps under this SK(&lt;SPAN&gt;sk91844) but I didn;t understand the second SK. And there is no solution provided on SK and Microsoft site as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2025 04:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264470#M1441</guid>
      <dc:creator>Mohit136971</dc:creator>
      <dc:date>2025-12-05T04:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access vpn with enrolment key certificate not working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264471#M1442</link>
      <description>&lt;P&gt;No other error&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2025 04:59:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-vpn-with-enrolment-key-certificate-not-working/m-p/264471#M1442</guid>
      <dc:creator>Mohit136971</dc:creator>
      <dc:date>2025-12-05T04:59:49Z</dc:date>
    </item>
  </channel>
</rss>

