<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL network extender uses wrong certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149228#M6799</link>
    <description>&lt;P&gt;Okay so i checked the File....&lt;/P&gt;&lt;P&gt;The UserCheck Portal is running following settings:&lt;/P&gt;&lt;P&gt;: (&lt;BR /&gt;:type (portal_settings)&lt;BR /&gt;:portal_name (UserCheck)&lt;BR /&gt;:ssl_certificate (ReferenceObject&lt;BR /&gt;:Uid ("{BE6C0102-E935-4917-8B3E-A81DEE2577D3}")&lt;BR /&gt;:Name (cert_9)&lt;BR /&gt;:Table (ssl_certificates)&lt;BR /&gt;)&lt;BR /&gt;:internal_port (8887)&lt;BR /&gt;:is_enabled (true)&lt;BR /&gt;:priority (1000)&lt;BR /&gt;:encrypted_connection (true)&lt;BR /&gt;:dmz_internal_interfaces (false)&lt;BR /&gt;:portal_access (internal_interfaces)&lt;BR /&gt;:is_any_host (false)&lt;BR /&gt;:ip_address (w.x.y.z)&lt;BR /&gt;:allow_additional_clear_port (false)&lt;BR /&gt;:main_url ("&lt;A href="https://server.domain.net/UserCheck" target="_blank" rel="noopener"&gt;https://server.domain.net/UserCheck&lt;/A&gt;")&lt;BR /&gt;:undefined_internal_interfaces (false)&lt;BR /&gt;:certificate_mode (all_with_same_ip)&lt;BR /&gt;:is_encrypted (true)&lt;BR /&gt;:path_prefix ("/UserCheck")&lt;BR /&gt;:hostname (server.domain.com)&lt;BR /&gt;:external_port (443)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It references to the ceretificate cert-9 but in the certificates section there is only the certs EuropeanSSL_Intermediate-2 and internal_ca... could that be related? and am i allowed to add a certificate to the config of the snx portal?&lt;/P&gt;&lt;P&gt;: (&lt;BR /&gt;:type (portal_settings)&lt;BR /&gt;:portal_name (VPN_SNX)&lt;BR /&gt;:internal_port (444)&lt;BR /&gt;:is_enabled (true)&lt;BR /&gt;:priority (1000)&lt;BR /&gt;:encrypted_connection (false)&lt;BR /&gt;:dmz_internal_interfaces (false)&lt;BR /&gt;:portal_access (all_interfaces)&lt;BR /&gt;:is_any_host (false)&lt;BR /&gt;:ip_address (0.0.0.0)&lt;BR /&gt;:allow_additional_clear_port (false)&lt;BR /&gt;:main_url ("&lt;A href="https://0.0.0.0/" target="_blank" rel="noopener"&gt;https://0.0.0.0/&lt;/A&gt;")&lt;BR /&gt;:undefined_internal_interfaces (false)&lt;BR /&gt;:certificate_mode (all_with_same_ip)&lt;BR /&gt;:is_encrypted (true)&lt;BR /&gt;:path_prefix ("/")&lt;BR /&gt;:hostname (0.0.0.0)&lt;BR /&gt;:external_port (443)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 09:07:09 GMT</pubDate>
    <dc:creator>TonyStark</dc:creator>
    <dc:date>2022-05-23T09:07:09Z</dc:date>
    <item>
      <title>SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148886#M6792</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We recently changed the SSL Certificates for VPN on our Gateway. We use two certificate. One for internal use only issued by an internal CA and one for external use issued by&amp;nbsp; EuropeanSSL. Our configuration looks correct on the first glimpse but if we connect to our SNX it shows the internal certificate which it should not use.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSL1.PNG" style="width: 356px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16609i2B3793238CBEE8F3/image-dimensions/356x340?v=v2" width="356" height="340" role="button" title="SSL1.PNG" alt="SSL1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="SSL2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16610iAF872FBEFA30A691/image-dimensions/400x351?v=v2" width="400" height="351" role="button" title="SSL2.PNG" alt="SSL2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSLVPN-2022 is our EuropeanSSL Certificate the internal one would be InternalCP&lt;/P&gt;&lt;P&gt;Is there any kind of database entry that did not override or did i miss anything?&lt;/P&gt;&lt;P&gt;Thanks in advance for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 10:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148886#M6792</guid>
      <dc:creator>TonyStark</dc:creator>
      <dc:date>2022-05-18T10:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148975#M6793</link>
      <description>&lt;P&gt;Silly question, did you push policy?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148975#M6793</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-05-19T08:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148977#M6794</link>
      <description>&lt;P&gt;Sure! Its running since 2 weeks or so...&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:41:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148977#M6794</guid>
      <dc:creator>TonyStark</dc:creator>
      <dc:date>2022-05-19T08:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148978#M6795</link>
      <description>&lt;P&gt;Got it. Look into&amp;nbsp;&lt;SPAN&gt;sk177903 and let me know if it fixes things or not.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/148978#M6795</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-05-19T08:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149219#M6796</link>
      <description>&lt;P&gt;I dont think this is the right solution... The UserCheck Portal should use the internal CA Cert but when we want to access the SNX Web-Page (for example) from the public domain it should use the EuropeanSSL but it does'nt...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SNX Homepage.PNG" style="width: 555px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16658iD93C06D474EFEC3B/image-dimensions/555x243?v=v2" width="555" height="243" role="button" title="SNX Homepage.PNG" alt="SNX Homepage.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This page is accessed via the public domain name so it should use the EuropeanSSL cert but internally it shouldnt&lt;/P&gt;&lt;P&gt;I hope you understand what I mean&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 07:42:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149219#M6796</guid>
      <dc:creator>TonyStark</dc:creator>
      <dc:date>2022-05-23T07:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149220#M6797</link>
      <description>&lt;P&gt;UserCheck and SNX are using the same certificate, which is different from VPN certificate. What is the issue for UserCheck to show your EuropeanSSL?&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 07:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149220#M6797</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-05-23T07:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149222#M6798</link>
      <description>&lt;P&gt;Also, to make sure which certificate is used where, you can look into&amp;nbsp;$FWDIR/database/myself_objects.C file of your Security Gateway&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 07:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149222#M6798</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-05-23T07:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149228#M6799</link>
      <description>&lt;P&gt;Okay so i checked the File....&lt;/P&gt;&lt;P&gt;The UserCheck Portal is running following settings:&lt;/P&gt;&lt;P&gt;: (&lt;BR /&gt;:type (portal_settings)&lt;BR /&gt;:portal_name (UserCheck)&lt;BR /&gt;:ssl_certificate (ReferenceObject&lt;BR /&gt;:Uid ("{BE6C0102-E935-4917-8B3E-A81DEE2577D3}")&lt;BR /&gt;:Name (cert_9)&lt;BR /&gt;:Table (ssl_certificates)&lt;BR /&gt;)&lt;BR /&gt;:internal_port (8887)&lt;BR /&gt;:is_enabled (true)&lt;BR /&gt;:priority (1000)&lt;BR /&gt;:encrypted_connection (true)&lt;BR /&gt;:dmz_internal_interfaces (false)&lt;BR /&gt;:portal_access (internal_interfaces)&lt;BR /&gt;:is_any_host (false)&lt;BR /&gt;:ip_address (w.x.y.z)&lt;BR /&gt;:allow_additional_clear_port (false)&lt;BR /&gt;:main_url ("&lt;A href="https://server.domain.net/UserCheck" target="_blank" rel="noopener"&gt;https://server.domain.net/UserCheck&lt;/A&gt;")&lt;BR /&gt;:undefined_internal_interfaces (false)&lt;BR /&gt;:certificate_mode (all_with_same_ip)&lt;BR /&gt;:is_encrypted (true)&lt;BR /&gt;:path_prefix ("/UserCheck")&lt;BR /&gt;:hostname (server.domain.com)&lt;BR /&gt;:external_port (443)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It references to the ceretificate cert-9 but in the certificates section there is only the certs EuropeanSSL_Intermediate-2 and internal_ca... could that be related? and am i allowed to add a certificate to the config of the snx portal?&lt;/P&gt;&lt;P&gt;: (&lt;BR /&gt;:type (portal_settings)&lt;BR /&gt;:portal_name (VPN_SNX)&lt;BR /&gt;:internal_port (444)&lt;BR /&gt;:is_enabled (true)&lt;BR /&gt;:priority (1000)&lt;BR /&gt;:encrypted_connection (false)&lt;BR /&gt;:dmz_internal_interfaces (false)&lt;BR /&gt;:portal_access (all_interfaces)&lt;BR /&gt;:is_any_host (false)&lt;BR /&gt;:ip_address (0.0.0.0)&lt;BR /&gt;:allow_additional_clear_port (false)&lt;BR /&gt;:main_url ("&lt;A href="https://0.0.0.0/" target="_blank" rel="noopener"&gt;https://0.0.0.0/&lt;/A&gt;")&lt;BR /&gt;:undefined_internal_interfaces (false)&lt;BR /&gt;:certificate_mode (all_with_same_ip)&lt;BR /&gt;:is_encrypted (true)&lt;BR /&gt;:path_prefix ("/")&lt;BR /&gt;:hostname (0.0.0.0)&lt;BR /&gt;:external_port (443)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 09:07:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149228#M6799</guid>
      <dc:creator>TonyStark</dc:creator>
      <dc:date>2022-05-23T09:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL network extender uses wrong certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149235#M6800</link>
      <description>&lt;P&gt;As I said, SNX uses the same infrastructure as UserCheck, so no, you cannot manually assign a different certificate to it by editing the file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 09:56:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-network-extender-uses-wrong-certificate/m-p/149235#M6800</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-05-23T09:56:12Z</dc:date>
    </item>
  </channel>
</rss>

