Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
khanhhv_1509
Explorer

Hi everyone, I'm learning about the components of firewall checkpoint and found out that Cert between SMS and GW will expire in 5 years from the date of creation. I want to ask what will happen when Cert expires and is there a way to re-initialize Cer for one or more GWs?

0 Kudos
3 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

SIC should handle this on it's own unless there's a connectivity issue between the SMS and Gateway,.
https://support.checkpoint.com/results/sk/sk164255

View solution in original post

the_rock
Legend
Legend

Its all automatically done.

Andy

View solution in original post

0 Kudos
Jim_Oqvist
Employee
Employee

Hi, SIC is documented in R82 Quantum Security Management Administration Guide and the process for renewal is documented in here: Certificate Longevity and Statuses

Automatic renewal of SIC certificates ensuring continuous SIC connectivity

SIC certificates are renewed automatically after 75% of the validity time of the certificate has passed. If, for example, the SIC certificate is valid for five years. After 3.75 years, a new certificate is created and downloaded automatically to the SIC entity. This automatic renewal ensures that the SIC connectivity of the Security Gateway is continuous. The administrator can revoke the old certificate automatically or after a set period of time. By default, the old certificate is revoked one week after certificate renewal.

View solution in original post

6 Replies
PhoneBoy
Admin
Admin

SIC should handle this on it's own unless there's a connectivity issue between the SMS and Gateway,.
https://support.checkpoint.com/results/sk/sk164255

khanhhv_1509
Explorer

i still don't understand, how does it work can you explain it to me

 

0 Kudos
the_rock
Legend
Legend

Do you have access to the sk? Its explained in the solution part.

Andy

0 Kudos
PhoneBoy
Admin
Admin

When the expiration date is less than a certain value (don't recall offhand what it is), the SIC certificates are automatically renewed.
If you've blocked the necessary ports for this to occur (in the SK I linked), then this process will fail.

0 Kudos
the_rock
Legend
Legend

Its all automatically done.

Andy

0 Kudos
Jim_Oqvist
Employee
Employee

Hi, SIC is documented in R82 Quantum Security Management Administration Guide and the process for renewal is documented in here: Certificate Longevity and Statuses

Automatic renewal of SIC certificates ensuring continuous SIC connectivity

SIC certificates are renewed automatically after 75% of the validity time of the certificate has passed. If, for example, the SIC certificate is valid for five years. After 3.75 years, a new certificate is created and downloaded automatically to the SIC entity. This automatic renewal ensures that the SIC connectivity of the Security Gateway is continuous. The administrator can revoke the old certificate automatically or after a set period of time. By default, the old certificate is revoked one week after certificate renewal.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events