<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How does SMB gateway CRL fetching work? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198163#M9793</link>
    <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;we are currently planning the upgrade of our management server to R81.20.&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we understand that if the management server is down for too long, IP-Sec VPN gateways will start to go offline due to beeing unable to fetch the CRL from the management CA, we are not 100% sure on the exact details of this and how we can influence it.&lt;/P&gt;&lt;P&gt;According to&amp;nbsp;&lt;SPAN&gt;sk100731 the gateways need to fetch the CRL every 24h, otherwise VPN will start to terminate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are not sure where the automatic fetching interval is configured. In the global properties of SmartConsole there is a "prefetch_crls_duration" setting that defaults to 2 hours while on the internal_ca object in the SmartConsole there is an advanced setting that states that the CRL will be cached on gateways and fetched every 120 hours.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking at the SMB gateways, there is a .crl file created at the "/pfrm2.0/config2/fw1/database/" path with the name ICA_&amp;lt;management name&amp;gt;_ &amp;lt;CA identifier&amp;gt;.crl. At first we thought according to the modify date of that file we could monitor when the last fetching of the CRL was done, however there are some modify times with &amp;gt;24h, which should not be possible since the VPN should go offline than.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone shed some light about where to configure the CRL fetching interval and how we can check at the SMB gateway when the last sucessfull CRL check was done?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2023 14:19:59 GMT</pubDate>
    <dc:creator>FXB</dc:creator>
    <dc:date>2023-11-16T14:19:59Z</dc:date>
    <item>
      <title>How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198163#M9793</link>
      <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;we are currently planning the upgrade of our management server to R81.20.&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we understand that if the management server is down for too long, IP-Sec VPN gateways will start to go offline due to beeing unable to fetch the CRL from the management CA, we are not 100% sure on the exact details of this and how we can influence it.&lt;/P&gt;&lt;P&gt;According to&amp;nbsp;&lt;SPAN&gt;sk100731 the gateways need to fetch the CRL every 24h, otherwise VPN will start to terminate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are not sure where the automatic fetching interval is configured. In the global properties of SmartConsole there is a "prefetch_crls_duration" setting that defaults to 2 hours while on the internal_ca object in the SmartConsole there is an advanced setting that states that the CRL will be cached on gateways and fetched every 120 hours.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking at the SMB gateways, there is a .crl file created at the "/pfrm2.0/config2/fw1/database/" path with the name ICA_&amp;lt;management name&amp;gt;_ &amp;lt;CA identifier&amp;gt;.crl. At first we thought according to the modify date of that file we could monitor when the last fetching of the CRL was done, however there are some modify times with &amp;gt;24h, which should not be possible since the VPN should go offline than.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone shed some light about where to configure the CRL fetching interval and how we can check at the SMB gateway when the last sucessfull CRL check was done?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:19:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198163#M9793</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2023-11-16T14:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198172#M9798</link>
      <description>&lt;P&gt;Here is a way to disable CRL fetch for the needed time: &lt;A href="https://support.checkpoint.com/results/sk/sk21156" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk21156&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Configuration: &lt;A href="https://community.checkpoint.com/t5/General-Topics/CRL-Fetching-recommendation/m-p/8011#M987" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/CRL-Fetching-recommendation/m-p/8011#M987&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 15:50:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198172#M9798</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-11-16T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198227#M9811</link>
      <description>&lt;P&gt;Thanks for your response, that seems like a good workaround for the upgrade process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still it would be nice if we get more information about the CRL fetching process.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 06:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198227#M9811</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2023-11-17T06:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198260#M9814</link>
      <description>&lt;P&gt;You can open an informational SR# with CP TAC to get it explained.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 11:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198260#M9814</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-11-17T11:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198298#M9817</link>
      <description>&lt;P&gt;not sure if applicable to SMB :&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108632" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108632&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 19:19:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198298#M9817</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-11-17T19:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198362#M9819</link>
      <description>&lt;P&gt;Thanks for mentioning this SK, the output is working on SMB gateways and we can see when the last CRL fetch and the next CRL fetch is happening.&amp;nbsp;&lt;BR /&gt;However so far I didnt not find a way to modify those values e.g. forcing the GW to fetch the CRL now. Gonna look more into this.&lt;/P&gt;&lt;P&gt;Since the upgrade is scheduled for tomorrow, we gonna fall back to the SK&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;mentioned and disable the CRL checking for the next 2 days.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 08:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/198362#M9819</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2023-11-20T08:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: How does SMB gateway CRL fetching work?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/225709#M11355</link>
      <description>&lt;P&gt;Actually, you can force the local CRL cache to clear:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk26628" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk26628&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 21:00:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-does-SMB-gateway-CRL-fetching-work/m-p/225709#M11355</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-04T21:00:53Z</dc:date>
    </item>
  </channel>
</rss>

