- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
I have a question.
My customer is currently using a virtual GW as VPN GW, the VPN users have to authenticate themselves with a certificate.
The customer wants to replace his GW with a new one (new release), is it possible to migrate the certificate from the old GW to the the new one?
Thank you
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
Why not update the existing GW to the new release ? This would keep everything...
Because he want to restart from scratch with a new one
Not possible without TAC afaik.
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
Hi Phone Boy,
We have 2 GWs, a 3800 (R80.40) and an 1800 (R80.20.50).
According to your comment, can I use the same certificate to connect to different GW's VPN if they use the same MGMT (Same CA)?
I have tried, but in the logs (after vpn debug ikeon), I see the below in the smart logs:
It's strange, it can see the correct DN, but shows "user DN unknown" and for the key install it shows "invalid certificate".
Any ideas please?
I also tried to create a new client certificate and enroll that one to the other GW, but still fails. (i.e. one client certificate per gw per user)
Suggest involving the TAC to troubleshoot this: https://help.checkpoint.com
Please also note that R80.20.x will be EOL in Oct-23, please refer:
https://www.checkpoint.com/support-services/support-life-cycle-policy/#embedded-security
Hey @GSallin
Not sure if it is possible, but below discussion might be helpful:
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY