<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173113#M8192</link>
    <description>&lt;P&gt;I see many requests like that online. Also I am facing the similar situation - ability to export/import existing certificate is crucial for proper operational management of the devices. Once we want to swap/replace device or virtual appliance - we need to configure everything from scratch automatically (migrate doesn't work in our case) - I can do everything through API, but we NEED to export/import VPN certificates for our tunnels - otherwise we need to go through very complicated process with CSR (basically fly to another country to get it on CD as this is security requirement). How can we proceed with such feature being added?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 07:53:35 GMT</pubDate>
    <dc:creator>ivdolbnia</dc:creator>
    <dc:date>2023-03-01T07:53:35Z</dc:date>
    <item>
      <title>IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126061#M8185</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;I wanted to upload 3rd party certificate to the gateway, however the only option is to use "add" button, which in turn would generate private key, CSR and will wait for me to come back with signed certificate and do "complete".&lt;/P&gt;
&lt;P&gt;It all would be fine, however I want to upload the same certificate on multiple gateways. I see "export P12", so I assume there is a hidden way to "import P12"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 553px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12923i82416C712C84FFFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorabihsot___0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126061#M8185</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-08-09T14:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126065#M8186</link>
      <description>&lt;P&gt;Don’t believe you can or should use the same certificate on multiple gateways.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:13:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126065#M8186</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-09T15:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126074#M8187</link>
      <description>&lt;P&gt;I understand your concerns, but there might be cases where it could be beneficial.&lt;/P&gt;
&lt;P&gt;I assume "export P12" button is for making backup of certificate + private key, however what is the purpose of such backup if you can't import it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126074#M8187</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-08-09T15:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126077#M8188</link>
      <description>&lt;P&gt;I believe that is for the public Certificate Authority key, not the gateway certificate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 15:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/126077#M8188</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-09T15:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/159294#M8189</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm worndering the same as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23615"&gt;@abihsot__&lt;/a&gt;&amp;nbsp;, in my case I'm replacing old Cluster to new gateway models, so, I need to import the IPSec VPN Certificate which resides in the SMS, but there is no such option to Import the certificate to the new Cluster.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 21:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/159294#M8189</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2022-10-11T21:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/160137#M8190</link>
      <description>&lt;P&gt;Try this one.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179785&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179785&amp;amp;partition=Advanced&amp;amp;product=Mobile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 19:24:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/160137#M8190</guid>
      <dc:creator>Aaron_Vivadelli</dc:creator>
      <dc:date>2022-10-21T19:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/160143#M8191</link>
      <description>&lt;P&gt;That SK talks about exporting the certificate.&lt;BR /&gt;The question is about importing an existing certificate with a private key for IPsec VPN, which is not supported or best practice.&lt;BR /&gt;If you generate a new certificate using the same Certificate Authority as the previous certificate, it should work without difficulty.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 19:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/160143#M8191</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-21T19:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173113#M8192</link>
      <description>&lt;P&gt;I see many requests like that online. Also I am facing the similar situation - ability to export/import existing certificate is crucial for proper operational management of the devices. Once we want to swap/replace device or virtual appliance - we need to configure everything from scratch automatically (migrate doesn't work in our case) - I can do everything through API, but we NEED to export/import VPN certificates for our tunnels - otherwise we need to go through very complicated process with CSR (basically fly to another country to get it on CD as this is security requirement). How can we proceed with such feature being added?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 07:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173113#M8192</guid>
      <dc:creator>ivdolbnia</dc:creator>
      <dc:date>2023-03-01T07:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173133#M8193</link>
      <description>&lt;P&gt;Backup and restore should cover replacement in most cases. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned already, there is a reason it is hard or even impossible to extract a certificate with a private key. It is done for very serious security reasons.&lt;BR /&gt;&lt;BR /&gt;For VPN purposes, you can actually generate a new certificate from a trusted CA. That should not affect tunnel functionalities. As long as VPN peers trust certificates from the other side, you should be fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 09:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173133#M8193</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-01T09:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173186#M8194</link>
      <description>&lt;P&gt;Third-party VPN certificates have always been rather tedious on Check Point. First, you must create a Trusted CA, then a subordinate CA to get the entire chain trusted on your management server. Then you have to create the CSR based on this, get it signed, and then import and have it trusted.&lt;/P&gt;
&lt;P&gt;I don't think you can utilise the same certificate on multiple gateways, as you will have to start with a new CSR per gateway/cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This process is much easier and seamless with the Mobile Access blade enabled. In Mobile Access, you can simply import .p12 directly without jumping through all the other hoops:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/General-Portal-Settings.htm?tocpath=The%20Mobile%20Access%20Portal%7CGeneral%20Portal%20Settings%7C_____0#Portal_Server_Certificate" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/General-Portal-Settings.htm?tocpath=The%20Mobile%20Access%20Portal%7CGeneral%20Portal%20Settings%7C_____0#Portal_Server_Certificate&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I'm not entirely sure if the certificate you import into the Mobile Access portal will be available to choose as a certificate for Site-2-Site IPsec VPN. When you jump through the hoops not using Mobile Access, your certificate will be available for Site-2-Site IPsec VPN and Remote Access. Not entirely sure if that is the case when using Mobile Access or if it will be available for Remote Access only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:52:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173186#M8194</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2023-03-01T12:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173259#M8195</link>
      <description>&lt;P&gt;Pretty sure this will not impact anything for Site-to-Site VPN or Remote Access VPN clients that aren't SNX.&lt;BR /&gt;We need&amp;nbsp;the Certificate Authorities explicitly defined (the root and any subordinates) in order to correctly verify the certificates in use are still valid.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 19:27:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/173259#M8195</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-01T19:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/210312#M8196</link>
      <description>&lt;P&gt;Hello Mr. PhoneBoy,&lt;/P&gt;&lt;P&gt;Does the certificate affect for VPN Site 2 site? Or only for VPN Client Remote Access&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 04:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/210312#M8196</guid>
      <dc:creator>Fiqri_kurniawan</dc:creator>
      <dc:date>2024-04-03T04:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/210365#M8197</link>
      <description>&lt;P&gt;It would affect both client to site and site to site, however unless you have site to site VPN tunnels between 2 check point gateways you manage from the same sms, your site to site vpn is most likely using pre shared key instead of certificates.&lt;/P&gt;&lt;P&gt;If you do have site to site VPNs between Check Point gateways managed by the same sms, you just need to install policy to all the other gateways the gateway in question has a vpn to do they are aware of the new cert as well.&lt;/P&gt;&lt;P&gt;In my experience, this change usually has more of an effect on client to site, but it can have an effect if your site to site VPNs use certificates rather than PSK.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 14:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/210365#M8197</guid>
      <dc:creator>Aaron_Vivadelli</dc:creator>
      <dc:date>2024-04-03T14:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/261965#M8198</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I understand this is quite an old topic. However, I’ve been wondering if there’s any way to import an already existing SSL certificate for an IPsec VPN on R81.20 - just like it’s possible to do for the Platform Administration Web Portal, UserCheck and Mobile Access portal ?&lt;BR /&gt;Is there any supported method or workaround to achieve this?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 09:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/261965#M8198</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2025-11-06T09:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/262018#M8199</link>
      <description>&lt;P&gt;As stated previously, we do not support importing an existing certificate for VPN purpose by design.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 15:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/262018#M8199</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-11-06T15:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/262087#M8200</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;BR /&gt;thank you for your prompt response.&lt;/P&gt;&lt;P&gt;I understand that no changes have been made by Check Point regarding this.&lt;/P&gt;&lt;P&gt;Unfortunately, the current/supported procedure doesn’t apply to my scenario: I’m using a wildcard SSL certificate issued by a public CA. It would have been ideal to use it not only for other portals, but also for client VPNs.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 23:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-certificate/m-p/262087#M8200</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2025-11-06T23:02:54Z</dc:date>
    </item>
  </channel>
</rss>

