<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reinitialize the Expired VPN Certificate in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241203#M12063</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Recently I have a problem with reinitializing the VPN Certificate on SMB Gateways. on a cloud managed (infinity portal) SMBs 1570, 1535, 1530, and so on with firmware R81.10.10 (996002945), and&amp;nbsp; R81.10.15 (996003913) the VPN certificate is expired, and as it is connected to the SMP, I cannot reinitialize the internal certificate correctly. every time I tried, I got this error: "Failed to reinitialize certificates".&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The new certificate is there, but it is not healthy, and the VPN is not working.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A Professional once told me that certificates on Cload-managed SMBs have to be managed only through SMP. I have done that, and the certificate is on the gateway, but not as a VPN certificate, as a cloud service provider certificate. At this point, the only way I can renew the certificate correctly is to disconnect the gateway from the SMP, renew the certificate, and reconnect it. But this shouldn't be the right way! Its not a solution, its just a workaround!&lt;BR /&gt;Has anyone any solution?&lt;BR /&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2025 09:31:35 GMT</pubDate>
    <dc:creator>Soroosh</dc:creator>
    <dc:date>2025-02-14T09:31:35Z</dc:date>
    <item>
      <title>Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241203#M12063</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Recently I have a problem with reinitializing the VPN Certificate on SMB Gateways. on a cloud managed (infinity portal) SMBs 1570, 1535, 1530, and so on with firmware R81.10.10 (996002945), and&amp;nbsp; R81.10.15 (996003913) the VPN certificate is expired, and as it is connected to the SMP, I cannot reinitialize the internal certificate correctly. every time I tried, I got this error: "Failed to reinitialize certificates".&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The new certificate is there, but it is not healthy, and the VPN is not working.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;A Professional once told me that certificates on Cload-managed SMBs have to be managed only through SMP. I have done that, and the certificate is on the gateway, but not as a VPN certificate, as a cloud service provider certificate. At this point, the only way I can renew the certificate correctly is to disconnect the gateway from the SMP, renew the certificate, and reconnect it. But this shouldn't be the right way! Its not a solution, its just a workaround!&lt;BR /&gt;Has anyone any solution?&lt;BR /&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 09:31:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241203#M12063</guid>
      <dc:creator>Soroosh</dc:creator>
      <dc:date>2025-02-14T09:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241212#M12064</link>
      <description>&lt;P&gt;That seems like a pretty serious issue. I would call TAC and get remote session going to fix it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 14:51:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241212#M12064</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-14T14:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241240#M12066</link>
      <description>&lt;P&gt;TAC case is probably best here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 20:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241240#M12066</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-14T20:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241400#M12068</link>
      <description>&lt;P&gt;I have a long standing TAC case open on VPN certificate problems on the SMBs.&amp;nbsp; It's really odd that we are still seeing issues with certificates on these (or any) devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case installing a .p12 certificate bundle for vpn.domain.com on the device, and renewing it had problems.&amp;nbsp; It can be re-done (remove everything, reboot box, and re-install) but this really should NOT be required IMHO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course then when the certificate is actually installed and functioning, the VPN sometimes suddenly fails to see it and stops using the certificate for VPNs causing them to fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have had this issue on newer firmware R81.10.10, R81.10.15, and has finally reached a threshold of 30% failures with one of my clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 16:42:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/241400#M12068</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2025-02-17T16:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242258#M12129</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180117" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180117&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 10:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242258#M12129</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-02-25T10:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242295#M12140</link>
      <description>&lt;P&gt;I am aware o this SK, and it is not applicable in my case as this SK was already resolved in my environment.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 15:20:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242295#M12140</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2025-02-25T15:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242352#M12143</link>
      <description>&lt;P&gt;Our customers issue was resolved by the following procedure:&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN class="uiOutputText"&gt;- In Expert mode, run:&lt;BR /&gt;pt internalCertificate&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="uiOutputText"&gt;- Look for the Cloud Services certificate (it should have a hashed name, e.g., 34a823sda183f1g4h16.crt).&lt;BR /&gt;&lt;BR /&gt;- Note the ID number associated with it.&lt;BR /&gt;&lt;BR /&gt;- Remove the certificate from the database:&lt;BR /&gt;sqlcmd “delete from internalCertificate where id=xxxx” (Replace xxxx with the actual ID number.)&lt;BR /&gt;&lt;BR /&gt;- Reinitialize certificates&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Feb 2025 08:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242352#M12143</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-02-26T08:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Reinitialize the Expired VPN Certificate</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242792#M12151</link>
      <description>&lt;P&gt;We have a final statement from CP TAC:&lt;/P&gt;
&lt;P&gt;We reviewed the internal VPN Advanced settings configuration and noticed that all gateways were set to use the last installed certificate for VPN connections.&lt;/P&gt;
&lt;P&gt;Since the Cloud certificate renews itself automatically, it will always be selected, ensuring that remote access continues to work even if the VPN certificate has expired.&lt;/P&gt;
&lt;P&gt;It's important to note that if you have already reinitialized the certificates, the VPN certificate will take priority.&lt;BR clear="none" /&gt;Since you encountered an error during this process, it may have impacted the certificate installation, making the VPN certificate the latest installed one. This could potentially affect remote access connections.&lt;/P&gt;
&lt;P&gt;Given this, we strongly recommend leaving the VPN certificate expired if your gateways are connected to SMP.&lt;/P&gt;
&lt;P&gt;However, if you experience any VPN issues where the VPN certificate has expired and the SMP portal certificate is the last installed certificate, please let CP TAC know, and we will investigate further.&lt;/P&gt;
&lt;P&gt;At this time, it appears that everything is functioning as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 08:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reinitialize-the-Expired-VPN-Certificate/m-p/242792#M12151</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-03-03T08:53:33Z</dc:date>
    </item>
  </channel>
</rss>

