Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Maysam
Participant

VPN remote access certificate issue

Hi All,

This morning all remote access users got the below message for the VPN endpoint client.

 Clicked trust and continue and the VPN client is working fine.

We haven't renewed the VPN cert or sslvpn site certificates.

Could anyone please let me know why we are getting this message?

Thank you.

Kindest regards

Maysam

 

Check Point Endpoint Security

The following security risks were discovered:
- The site's fingerprint has changed from the original one.
- The site presents itself as cxl VPN Certificate
- The site certificate is not from a trusted certificate authority.

We strongly recommend that you contact your system administrator about
these issues. By clicking "Trust and Continue". you confirm that you are
aware of the risks and agree to continue.
Trust and Continue

 

 

 

1 Reply
Duane_Toler
MVP Silver
MVP Silver

Do you have multiple login options configured on your gateway?

If you also use SAML, make sure the SAML VPN portal certificate has not expired.  The client may be trying to switch to a different login option when it finds an expired certificate.  This is what happened to my client when I tried to connect to a customer's gateway with an expired certificate.

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events