<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Communities certificate problem in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159475#M7567</link>
    <description>&lt;P&gt;SK about this issue:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk180117" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk180117&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2022 19:18:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-10-13T19:18:35Z</dc:date>
    <item>
      <title>VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159163#M7535</link>
      <description>&lt;P&gt;Hi, from last friday we have problem with vpn configured by communities.&lt;/P&gt;&lt;P&gt;there are problem during IKE phase with certificate&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error vpn console1_mod.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18081i723724805598B033/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error vpn console1_mod.JPG" alt="error vpn console1_mod.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error vpn console2_mod.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18082i4819109AD5B376AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error vpn console2_mod.jpg" alt="error vpn console2_mod.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I try to disconnect gateways from console, reinitialize certificates and reconnect.&lt;/P&gt;&lt;P&gt;I try also to cancel community and ricreate but all &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;attemps don't work.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The communities are configure in star or mesh VPN Type but none work.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 15:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159163#M7535</guid>
      <dc:creator>agilberti</dc:creator>
      <dc:date>2022-10-10T15:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159184#M7538</link>
      <description>&lt;P&gt;The error message is pretty clear: "main mode cannot complete certificate chain."&lt;BR /&gt;That points to an error with the Certificate Authority key you've imported.&lt;BR /&gt;If the CA key is not a root CA (i.e. it's signed by another CA key), you need to include the entire certificate chain in the .p12 file you import (meaning the public CA key you care about along with all the public CA keys required to validate that signature).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 19:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159184#M7538</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-10T19:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159199#M7540</link>
      <description>&lt;P&gt;Gateways involved until friday work fine i don't make any change.&lt;/P&gt;&lt;P&gt;Our gateways are 600, 700 and 1500 series locally managed by Quantum Sparks SMP.&lt;/P&gt;&lt;P&gt;Where i find CA key? on SMP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 22:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159199#M7540</guid>
      <dc:creator>agilberti</dc:creator>
      <dc:date>2022-10-10T22:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159276#M7549</link>
      <description>&lt;P&gt;This is for the CA key that you are using to authenticate the VPN, which I believe is configured in SMP.&lt;BR /&gt;If it's the internal CA you're using, then you'll probably need the TAC to assist in resolving this issue.&amp;nbsp;&lt;BR /&gt;If it's a different CA, then you'll have to see if the gateways can (among other things) reach the CRL specified as part of the public key.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 18:33:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159276#M7549</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-11T18:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159298#M7550</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;There are a few suggested ways to handle this issue:&lt;/P&gt;
&lt;P&gt;From the web UI: Disconnect from SMP, remove the old trusted CA, reconnect to SMP&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Connect to the GW using web UI&lt;/LI&gt;
&lt;LI&gt;Stop cloud services – This is needed because otherwise the old certificate is locked to SMP and cannot be deleted&lt;/LI&gt;
&lt;LI&gt;Remove the old SMP trusted CA (expires in 2027)&lt;/LI&gt;
&lt;LI&gt;Reconnect to cloud services&lt;/LI&gt;
&lt;LI&gt;Verify the updated SMP certificate exists (expires in 2032) and VPN tunnel is working as expected&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this doesn't work, please open a TAC case, there are more advanced ways to solve it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 22:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159298#M7550</guid>
      <dc:creator>Amir_Ayalon</dc:creator>
      <dc:date>2022-10-11T22:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159299#M7551</link>
      <description>&lt;P&gt;As I explained in the other &lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/SMP-smbmgmtservice-moving-to-AWS/td-p/156970#M7368" target="_self"&gt;thread&lt;/A&gt;&amp;nbsp;there was an event on Oct 6 that may require you to take some action, refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://status.checkpoint.com/" target="_blank" rel="noopener"&gt;https://status.checkpoint.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 23:07:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159299#M7551</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-11T23:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Communities certificate problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159475#M7567</link>
      <description>&lt;P&gt;SK about this issue:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk180117" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk180117&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 19:18:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Communities-certificate-problem/m-p/159475#M7567</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-13T19:18:35Z</dc:date>
    </item>
  </channel>
</rss>

