- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: SIC
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SIC
Hello! I have some problem with install unified policy. When I want to install policy on A-GW and B-GW, I got errors: Layer "DMZ traffic": The Intranet Community member A-GW must have a signed certificate and Policy verification failed on both gateways.
How I can fix this error?
Thank you for your helping!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need SIC to be established before you can install policy. Go to that GW object and establish SIC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did it, but it still gives an error. I reset SIC, then enter new OTP, but nothing
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your answer, but but it still gives an error. We already have trust established
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you try what @Tal_Paz-Fridman suggested? To me, it implies cert might be expired. Lets do quick remote if you are allowed and I can check it for you.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It seems that for some reason the Security Gateway in the Community does not have a certificate.
You might want to try to add or renew the VPN Certificate (or enable / disable IPsec VPN Blade):
Security Gateway object > IPsec VPN > Add or Renew
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@jus_soul, please do what @Tal_Paz-Fridman suggests. It seems A-GW does not have a VPN certificate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Note that you need vpn cert even if you do not have vpn blade enabled. If so temporarily enable vpn blade renew cert and disable blade again.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Very true!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would certainly verify what both @Tal_Paz-Fridman and @_Val_ mentioned. Dont worry about warnings, you can ommit those for now, as they never cause policy to fail, its the actual error.
Andy
