- CheckMates
- :
- Products
- :
- General Topics
- :
- Expired VPN certificates on gateways - no VPN blad...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Expired VPN certificates on gateways - no VPN blades enabled
After installing access control policy to a active/standby gateway cluster I have been receiving alerts that the VPN certificates on the gateways has expired. I do not have the IPSec VPN or Mobile Access blades enabled on the cluster so I don't have the option to renew the cert and really don't even need it.
Is there a way I can remove the certificates to clear the message that comes up after installing policy?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pretty sure certificates need to exist even if you’re not using VPN.
Recommend enabling it, renewing/regenerating the certificate, disabling, and pushing policy.
There should be no harm in this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Enable IPSEC VPN blade, head to IPSEC VPN on the left hand side menu, either remove or renew the cert.
Then, disable IPSEC VPN and push policy.
Should clear it.. should....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Instead of enabling the IPSEC VPN blade I went into the ICA Manager on my SMS, deleted the certs in question, and the message still persists after installing policy. I even did a cpstop/cpstart on the SMS after deleting the certs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pretty sure certificates need to exist even if you’re not using VPN.
Recommend enabling it, renewing/regenerating the certificate, disabling, and pushing policy.
There should be no harm in this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Error persists
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Suggest engaging with TAC: https://help.checkpoint.com
