Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Eden142113
Explorer

Authentication Failed with Certificate-Based IPsec VPN (Check Point Hub + FortiGate Dynamic IP Spoke

Hi everyone,

I would like to create this post to ask for help with an issue I am facing while configuring a certificate-based IPsec VPN between a Check Point gateway and a FortiGate firewall with a dynamic IP.

Currently, I am experiencing an authentication issue with a certificate-based IPsec VPN between a Check Point gateway and a FortiGate firewall.

I am using the Check Point Security Management Server (SMS) as the Internal CA. I exported the Internal CA certificate from the SMS and imported it into the FortiGate as a trusted CA. Then, I generated a CSR on the FortiGate, signed it using the Check Point Internal CA, and imported the signed certificate back into the FortiGate.

After completing the certificate configuration and configuring the IPsec VPN on both devices, the tunnel does not come up. The IKE debug shows the following error:

Auth exchange: Sending notification to peer: Authentication failed. MyAuthMethod: Certificate

Is my certificate deployment process correct for this scenario? Has anyone successfully configured a Check Point hub with a FortiGate dynamic-IP spoke using the Check Point SMS Internal CA for certificate-based authentication? Any guidance would be greatly appreciated.

 

0 Kudos
2 Replies
josi
Participant
Participant

Hi, I would review ike.elg and vpnd.elg files located in $FWDIR/log/ to obtain more detailed error messages as the authentication can fail for various reasons...

0 Kudos
_Val_
Admin
Admin

Two things to check for GW certification-based auth with S2S VPN in a DIAP setting:

1. GWs are authenticating with DN and not their IPs

2. CRL distribution point is available for DIAP GWs on a public IP address and resolvable, if DNS and not the fixed IP is used.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events