<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to renew the defaultcert on firewall in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115798#M8877</link>
    <description>&lt;P&gt;This is entirely in the domain of the ICA.&lt;BR /&gt;It's possible TAC may have a more surgical answer than "reset the ICA."&lt;BR /&gt;The only thing that occurs to me to try (which may not work and involve downtime) is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Change the gateway name and object main IP to something else.&lt;/LI&gt;
&lt;LI&gt;Create a new gateway object for the gateway in question, migrating all the relevant settings.&lt;/LI&gt;
&lt;LI&gt;Use "where used" to find occurrences of old gateway object and replace with new.&lt;/LI&gt;
&lt;LI&gt;Reset SIC on the impacted gateway:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86521" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86521&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Push policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Assuming that works, you can then delete the old object (hopefully).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, like I said, I recommend engaging with the TAC.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Apr 2021 03:46:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-04-12T03:46:31Z</dc:date>
    <item>
      <title>Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115744#M8872</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not able to renew/ view the defaultcert on the firewall .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we are going to view the default cert we are getting attached error :&lt;/P&gt;&lt;P&gt;Gateway object &amp;gt;&amp;gt; IPsec VPN &amp;gt;&amp;gt; click on the defaultcert &amp;gt;&amp;gt; view&lt;/P&gt;&lt;P&gt;error message : Failed to read the certificate from database&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we are going to renew the default cert we are getting attached error :&lt;/P&gt;&lt;P&gt;Gateway object &amp;gt;&amp;gt; IPsec VPN &amp;gt;&amp;gt; click on the defaultcert &amp;gt;&amp;gt; renew &amp;gt;&amp;gt; generated keys and get internal certificate &amp;gt;&amp;gt; OK&lt;/P&gt;&lt;P&gt;error message : generated keys not found in the database .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We come to know this issue when tunnel was not forming between two checkpoint gateways connected on the same management server . In the logs , We were able to see that due to certificate error&amp;nbsp; phase1 key not installed .&lt;/P&gt;&lt;P&gt;Please note that SIC is established with mgmt server and ntp working porperly .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone assist me on this !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ipsec phase1 error message.JPG" style="width: 788px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11336i20A7F09A0666A700/image-size/large?v=v2&amp;amp;px=999" role="button" title="ipsec phase1 error message.JPG" alt="ipsec phase1 error message.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="defaultcert view error message.JPG" style="width: 450px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11334i7A63DABD8FDDCA25/image-size/large?v=v2&amp;amp;px=999" role="button" title="defaultcert view error message.JPG" alt="defaultcert view error message.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="defaultcert renewal error message.JPG" style="width: 518px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11335iF6E801F6F4E1FDF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="defaultcert renewal error message.JPG" alt="defaultcert renewal error message.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 12:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115744#M8872</guid>
      <dc:creator>socteam_gsi</dc:creator>
      <dc:date>2021-04-10T12:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115745#M8873</link>
      <description>&lt;P&gt;Check&amp;nbsp;&lt;SPAN&gt;sk108966, sounds like a corruption in the ICA.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 13:06:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115745#M8873</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-10T13:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115751#M8874</link>
      <description>&lt;P&gt;That sounds like ICA corruption and I’d get the TAC to assist here.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 16:48:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115751#M8874</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-10T16:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115757#M8875</link>
      <description>&lt;P&gt;Definitely looks like ICA corruption...I cant say for sure if sk genesis provided is any better than doing fwm sic_reset, but looks to me its what you sadly have to follow. I cant see any better options here mate, sorry...&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 04:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115757#M8875</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-04-11T04:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115784#M8876</link>
      <description>&lt;P&gt;could you please assist us on how to proceed this issue .&lt;/P&gt;&lt;P&gt;Since , there are 18 firewalls which are connected to same management server but we are facing only issue to single firewall hence we are suspecting this issue is more related to firewall end or certificate related issue .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 13:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115784#M8876</guid>
      <dc:creator>socteam_gsi</dc:creator>
      <dc:date>2021-04-11T13:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to renew the defaultcert on firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115798#M8877</link>
      <description>&lt;P&gt;This is entirely in the domain of the ICA.&lt;BR /&gt;It's possible TAC may have a more surgical answer than "reset the ICA."&lt;BR /&gt;The only thing that occurs to me to try (which may not work and involve downtime) is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Change the gateway name and object main IP to something else.&lt;/LI&gt;
&lt;LI&gt;Create a new gateway object for the gateway in question, migrating all the relevant settings.&lt;/LI&gt;
&lt;LI&gt;Use "where used" to find occurrences of old gateway object and replace with new.&lt;/LI&gt;
&lt;LI&gt;Reset SIC on the impacted gateway:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86521" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86521&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Push policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Assuming that works, you can then delete the old object (hopefully).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, like I said, I recommend engaging with the TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 03:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-renew-the-defaultcert-on-firewall/m-p/115798#M8877</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-12T03:46:31Z</dc:date>
    </item>
  </channel>
</rss>

