- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
I'm trying to establish and IPSEC (S2S) tunnel between 2 managed Check Point firewalls. I previously succeeded with the same kind of HW/version. This one throws an error I've never seen before :
Main Mode Failed to match proposal: Transform: SHA1, Certificate, Group 2 (1024 bit); Reason: unsupported encryption algorithm -1 (NA)
I've tried lowering the algorithm, still the same issue.
Any idea how to troubleshoot that ? I'm currently planning on upgrading that remote GW to the latest available firmware, and rebooting it.
Thanks !
Hi,
I actually updated the firmware to the latest version available, and it solved it.
Thanks for your help.
Regards.
I cant say 100% this is related, but just see what you have there. I changed mine, so yours would look different if you never touched it.
Andy
Hi, thanks for your answer. In my case I don't have the same screen as yours, all should be set in the Community:
And in the said community (I tried various combination):
This works for more than 10 gateways in the same community (as Satellite), but doesn't work for a new one I wanted to add. 😞
Ok, so just to make sure I get this right, apologies if I had wrong assumption. Are you saying there are multiple satellite gateways with one centre gateway? If so, is it the case that this new firewall you added is also a satellite, correct? And thats where you get the error?
Exactly, this community is used for many of our remote offices, and I just want to add a new one into it. The Centre gateway is our main cluster, and the Satellites are the remote offices' firewalls. The one that I didn't succeed in adding is a remote office, so a Satellite. That's where I get the error.
SHA1 has been deprecated for awhile now, is the new gateway perhaps running a newer version of code that is blocking the use of SHA1? DH Group 2 is pretty old but should still be supported by all code versions.
I get what @Timothy_Hall is saying...though, I had seen customer running on R81.10 use sha1 and works perfectly fine. I would definitely confirm with TAC to get official statement/answer.
Hi,
I actually updated the firmware to the latest version available, and it solved it.
Thanks for your help.
Regards.
These were SMB GWs ?
Yes it was 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 41 | |
| 26 | |
| 14 | |
| 13 | |
| 11 | |
| 11 | |
| 10 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY