<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capsule Connect VPN Issue(The site's certificate has expired) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257053#M1663</link>
    <description>&lt;P&gt;Good points&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Sep 2025 19:35:33 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-10T19:35:33Z</dc:date>
    <item>
      <title>Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257021#M1660</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;!-- StartFragment  --&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;Hi all,&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I'm encountering a problem. I have a 5000 series gateway (R81.10) managed by SMS (R81.20). Last Friday, I renewed the VPN certificate for the 5000 series gateway. After renewing the certificate, both the IPsec VPN and the desktop Remote Access VPN client are working well.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;However, VPN connections from mobile devices using Capsule Connect are not working. When attempting to connect via Capsule Connect, the client displays a message indicating that the site's certificate has expired.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;!-- EndFragment  --&gt;Please suggest. Many thanks.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 12:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257021#M1660</guid>
      <dc:creator>Amber</dc:creator>
      <dc:date>2025-09-10T12:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257040#M1661</link>
      <description>&lt;P&gt;Hey Amber,&lt;/P&gt;
&lt;P&gt;Can you have them try delete/re-create the site and test? Just have one or two random users do that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 15:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257040#M1661</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-10T15:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257052#M1662</link>
      <description>&lt;P&gt;You sure the clients trust the new certificate?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167255" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167255&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Just to make sure you done policy push after cert renewal?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 19:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257052#M1662</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-10T19:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257053#M1663</link>
      <description>&lt;P&gt;Good points&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 19:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257053#M1663</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-10T19:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257089#M1664</link>
      <description>&lt;P&gt;Hi Lesley,&lt;/P&gt;&lt;P&gt;When using Capsule Connect to establish a VPN connection, the self-signed certificate does not appear to trust. According to sk167255, the recommended solution is to add a third-party trusted certificate to the Mobile Access Blade.&lt;BR /&gt;May I kindly ask if it is possible to use the gateway’s self-signed certificate for Mobile Access instead?&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 08:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257089#M1664</guid>
      <dc:creator>Amber</dc:creator>
      <dc:date>2025-09-11T08:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257104#M1665</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;As user still is able not to trust a third party (not self-signed) certificate. If you import certificate without the &lt;SPAN&gt;Intermediate CA and only the certificate systems can complain about it: invalid certificate. Normally you import all&amp;nbsp;Intermediate CA's including the certificate and not the root CA. You can also include root ca but that should not be needed as it is expected that all clients are known with the root ca.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 14:39:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257104#M1665</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-11T14:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257109#M1666</link>
      <description>&lt;P&gt;You can use the Internal CA for this, but for the error message to go away, the end user will have to manually configure the CA as trusted on their device.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 14:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257109#M1666</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-11T14:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257112#M1667</link>
      <description>&lt;P&gt;I guess similar to ssl inspection...maybe not best comparison though.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 15:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/257112#M1667</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-11T15:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/258279#M1668</link>
      <description>&lt;P&gt;&lt;!--  StartFragment   --&gt;&lt;/P&gt;&lt;P&gt;Many thanks to everyone for their help. I opened a technical ticket with Check Point support. They suggested using the command "#fw kill vpnd" to restart the VPN process. I tried it, and it worked. Thank you very much again.&lt;/P&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 03:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/258279#M1668</guid>
      <dc:creator>Amber</dc:creator>
      <dc:date>2025-09-26T03:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Capsule Connect VPN Issue(The site's certificate has expired)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/258280#M1669</link>
      <description>&lt;P&gt;Great! Thanks for letting us know, appreciated.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 03:20:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Capsule-Connect-VPN-Issue-The-site-s-certificate-has-expired/m-p/258280#M1669</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-26T03:20:30Z</dc:date>
    </item>
  </channel>
</rss>

