Hi everyone,
I would like to create this post to ask for help with an issue I am facing while configuring a certificate-based IPsec VPN between a Check Point gateway and a FortiGate firewall with a dynamic IP.
Currently, I am experiencing an authentication issue with a certificate-based IPsec VPN between a Check Point gateway and a FortiGate firewall.
I am using the Check Point Security Management Server (SMS) as the Internal CA. I exported the Internal CA certificate from the SMS and imported it into the FortiGate as a trusted CA. Then, I generated a CSR on the FortiGate, signed it using the Check Point Internal CA, and imported the signed certificate back into the FortiGate.
After completing the certificate configuration and configuring the IPsec VPN on both devices, the tunnel does not come up. The IKE debug shows the following error:
Auth exchange: Sending notification to peer: Authentication failed. MyAuthMethod: Certificate
Is my certificate deployment process correct for this scenario? Has anyone successfully configured a Check Point hub with a FortiGate dynamic-IP spoke using the Check Point SMS Internal CA for certificate-based authentication? Any guidance would be greatly appreciated.