<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change the certificate for Remote Access VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-the-certificate-for-Remote-Access-VPN/m-p/141524#M7204</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have 2 clusters (ClusterXL active/standby) that we use as VPN gateways for our Remote Access users. Both are R81.10, and one of the clusters is also used as S2S VPN gateway for tunnels with various 3rd parties.&lt;/P&gt;&lt;P&gt;Now we enabled SAML authentication, we want to advertise this authentication method to all our users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, we have a certificate warning every time we login, as the IPSEC certificate on the gateways is issued by the internal_ca. I'd like to install a trusted CA, so our internal users and partners/vendors can connect without a certificate warning. So the certificate should have 'vpn.company.com' as object, and the public IP of both clusters in the SAN.&lt;/P&gt;&lt;P&gt;How can I achieve that without disrupting the existing numerous IPSEC S2S we also have with many 3rd parties ? Is there anything I need to pay attention to, to avoid possible issues ?&lt;/P&gt;&lt;P&gt;Thanks for your advices, as always.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Feb 2022 09:51:58 GMT</pubDate>
    <dc:creator>Ob1lan</dc:creator>
    <dc:date>2022-02-15T09:51:58Z</dc:date>
    <item>
      <title>Change the certificate for Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-the-certificate-for-Remote-Access-VPN/m-p/141524#M7204</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have 2 clusters (ClusterXL active/standby) that we use as VPN gateways for our Remote Access users. Both are R81.10, and one of the clusters is also used as S2S VPN gateway for tunnels with various 3rd parties.&lt;/P&gt;&lt;P&gt;Now we enabled SAML authentication, we want to advertise this authentication method to all our users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, we have a certificate warning every time we login, as the IPSEC certificate on the gateways is issued by the internal_ca. I'd like to install a trusted CA, so our internal users and partners/vendors can connect without a certificate warning. So the certificate should have 'vpn.company.com' as object, and the public IP of both clusters in the SAN.&lt;/P&gt;&lt;P&gt;How can I achieve that without disrupting the existing numerous IPSEC S2S we also have with many 3rd parties ? Is there anything I need to pay attention to, to avoid possible issues ?&lt;/P&gt;&lt;P&gt;Thanks for your advices, as always.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 09:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-the-certificate-for-Remote-Access-VPN/m-p/141524#M7204</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2022-02-15T09:51:58Z</dc:date>
    </item>
  </channel>
</rss>

