<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Central management and certificate based VPNs in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224375#M11264</link>
    <description>&lt;P&gt;VPN certificates are validated against the CA on rekey, whether it be the internal CA or an external one (depending on configuration).&lt;BR /&gt;Extended outages of management when ICA is used for VPN certificates will cause VPN issues like you experienced.&lt;/P&gt;
&lt;P&gt;Having said that, this usually doesn’t happen for about 24 hours (not just a few, as you experienced).&lt;BR /&gt;The CRL should be cached, in fact, and you may want to check this sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk116340" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk116340&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can disable CRL checking, of course, but checking the CRL is an important security feature that should not be disabled.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250#M17515" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250#M17515&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 12:51:34 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-08-23T12:51:34Z</dc:date>
    <item>
      <title>Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224367#M11263</link>
      <description>&lt;P&gt;I have a Star IPSEC VPN setup with all gateways managed centrally. Recently, I encountered a problem when the management server was offline for a few hours. During that time, all of the VPNs dropped when they re-keyed, even though the certificates still had years left before expiration. This behavior was unexpected and quite concerning, as it seems to present a single point of failure.&lt;/P&gt;&lt;P&gt;Does anyone know why this happened? I couldn't find any information about this in the documentation.&lt;/P&gt;&lt;P&gt;My understanding was that central management would only be an issue if a VPN certificate expired, as we wouldn't be able to generate a new certificate with the management server down.&lt;/P&gt;&lt;P&gt;I'm going to take a guess and assume that maybe when the VPN re-keys, it checks with the CA to see if the certificate is still valid. Is there any way around this? It's pretty bad if the management server is so critical to VPN re-keying.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224367#M11263</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2024-08-23T10:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224375#M11264</link>
      <description>&lt;P&gt;VPN certificates are validated against the CA on rekey, whether it be the internal CA or an external one (depending on configuration).&lt;BR /&gt;Extended outages of management when ICA is used for VPN certificates will cause VPN issues like you experienced.&lt;/P&gt;
&lt;P&gt;Having said that, this usually doesn’t happen for about 24 hours (not just a few, as you experienced).&lt;BR /&gt;The CRL should be cached, in fact, and you may want to check this sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk116340" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk116340&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can disable CRL checking, of course, but checking the CRL is an important security feature that should not be disabled.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250#M17515" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250#M17515&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 12:51:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224375#M11264</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-23T12:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224382#M11265</link>
      <description>&lt;P&gt;Thank you for the response. I had a suspicion it might be something like that.&lt;/P&gt;&lt;P&gt;Where do I need to check the settings listed in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk116340" target="_blank" rel="noopener noreferrer"&gt;sk116340&lt;/A&gt;? I can't see that section in Smart Console.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224382#M11265</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2024-08-23T13:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224401#M11269</link>
      <description>&lt;P&gt;In the object list, you find it under Servers &amp;gt; Trusted CA &amp;gt; internal_ca&lt;BR /&gt;This was taken from R82, but it should be the same in previous releases.&amp;nbsp;&lt;BR /&gt;I've submitted feedback on the SK to ensure instructions for finding in R8x are included.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 955px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27324i310A55A595465F1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:30:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224401#M11269</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-23T17:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224624#M11274</link>
      <description>&lt;P&gt;Thanks for that, I found it now and it's 24 hours. Appreciate the info.&lt;/P&gt;&lt;P&gt;It explains things nicely except the management server was down for less than 24 hours, it might have even been only a few hours before the issues started. Do you know if these cache changes will apply to SMB Quantum Gateways also? That is the difference, they were Quantum Gateways (1500s) The central gateway was a normal Checkpoint 6200.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 10:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224624#M11274</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2024-08-27T10:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224639#M11280</link>
      <description>&lt;P&gt;As far as I know, SMB gateways should also cache the CRL.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/224639#M11280</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-27T12:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/225448#M11334</link>
      <description>&lt;P&gt;I've looked at this SK article and see it shows how to check the last and next CRL update.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108632" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk108632&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My output shows that the CRL cache is 7 days.&lt;/P&gt;&lt;P&gt;This update: Mon Sep 2 19:10:04 2024 Local Time&lt;BR /&gt;Next update: Mon Sep 9 19:10:04 2024 Local Time&lt;/P&gt;&lt;P&gt;But when I follow your SK article above, my internal_ca cache is set to 24 hours.&amp;nbsp;&lt;/P&gt;&lt;P&gt;These two don't tie up. Any idea why this is the case?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 12:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/225448#M11334</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2024-09-03T12:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Central management and certificate based VPNs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/225497#M11350</link>
      <description>&lt;P&gt;Offhand, I do not.&lt;BR /&gt;Recommend engaging with TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 14:16:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Central-management-and-certificate-based-VPNs/m-p/225497#M11350</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-03T14:16:11Z</dc:date>
    </item>
  </channel>
</rss>

