<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client behind another security gateway while connecting gives certificate not valid error in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113918#M9042</link>
    <description>&lt;P&gt;Also, if the client is running on a mobile hotspot, then everything works fine and there is no client certificate error&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 11:34:49 GMT</pubDate>
    <dc:creator>Hughes</dc:creator>
    <dc:date>2021-03-18T11:34:49Z</dc:date>
    <item>
      <title>Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113680#M9039</link>
      <description>&lt;P&gt;In my setup, I have a security gateway in a main location which handles all the remote VPN access connections. I also have a satellite office that has a security gateway that has multiple VLANs connected to it. While the administrative VLAN has site-to-site VPN defined to the main location security gateway, the other VLANs are not part of the site-to-site VPN. When users in the other VLANs try to use the Windows Capsule client to do Remote Access VPN, they get "Connection Failed: Certificate not valid" error. We use certificate based authentication. If the same users try this from any other internet connection (including their mobile hotspots), everything works fine. What could be wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clue will greatly help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 14:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113680#M9039</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-03-16T14:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113740#M9040</link>
      <description>&lt;P&gt;Is HTTPS Inspection enabled?&lt;BR /&gt;What do you see in the logs for either gateway when a client tries to access?&lt;BR /&gt;What version/JHF are the gateways?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 05:30:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113740#M9040</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-17T05:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113917#M9041</link>
      <description>&lt;P&gt;Thanks. HTTPS inspection was originally enabled. I turned it off. No change in status. On the logs of the main location, I see https packets from the satellite office GW (source IP is public IP of the satellite office GW) with the site-site community. On the logs of the remote firewall (satellite office), I see IKE_NAT_Traversal packets on UDP port 4500 and https packets destined to the central firewall. Here the source IP is the client's internal IP and the community is again site-site.&amp;nbsp; The satellite office GW is SMB 1400 running R77.20.87 (990171302) and the central firewall is running 80.30 JHF Take 219.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:34:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113917#M9041</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-03-18T11:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113918#M9042</link>
      <description>&lt;P&gt;Also, if the client is running on a mobile hotspot, then everything works fine and there is no client certificate error&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:34:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113918#M9042</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-03-18T11:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113969#M9043</link>
      <description>&lt;P&gt;A TAC case is probably in order here.&lt;BR /&gt;I have a feeling the SMB appliance is injecting it's own certificate here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 15:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113969#M9043</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T15:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113978#M9044</link>
      <description>&lt;P&gt;Can you maybe run simple zdebug on the firewall when this is about to happen and grep for specific user? For example fw ctl zdebug + drop | grep user1 (or whatever the username would be) and then do the test and observe the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/113978#M9044</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T16:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/114129#M9045</link>
      <description>&lt;P&gt;Thanks. Yes. I have opened a case with TAC. Will keep the forum posted once they find a solution&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 06:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/114129#M9045</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-03-20T06:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/114130#M9046</link>
      <description>&lt;P&gt;Thanks. I tried running the zdebug just as you have suggested. I see no drops&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 06:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/114130#M9046</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-03-20T06:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Client behind another security gateway while connecting gives certificate not valid error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/115340#M9047</link>
      <description>&lt;P&gt;Finally after opening a TAC case we resolved the issue. After doing a series of debug sessions, the TAC team identified that the SMB device was translating the IP of the client requesting for the VPN connection to its own public IP and also inserting its own certificate. This would fail the client certificate authentication. TAC suggested to add a NAT rule that keeps the original address of the client when the VPN is initiated to the central GW's public IP. This resolved the issue&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 03:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Client-behind-another-security-gateway-while-connecting-gives/m-p/115340#M9047</guid>
      <dc:creator>Hughes</dc:creator>
      <dc:date>2021-04-06T03:58:59Z</dc:date>
    </item>
  </channel>
</rss>

