cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Danny
Pearl

VPN Certificates or Pre-Shared Secret?

Check Point recommends using VPN certificates

as most secure authentication method for IPsec VPNs (sk133152).

As admins might fear that handling certificate-based VPNs could be too complicated I've created this HowTo:

HowTo Set Up Certificate Based VPNs with Check Point Appliances

But certificate based VPNs also have a downside: They are dependant on an always operational and accessible SmartCenter Server which hosts the CA that issues the VPN certificates. Certificate based VPN tunnels will go down when the CA is not reachable when the VPN certificate is checked (default: every 24 hours).

This is because of security. However, many admins / companies rely more on connectivity, which is where Pre-shared secrets are the best choice.

What are you using primarily? VPN Certificates or Pre-shared secrets?

VPN Certificates8
Pre-shared secret21
0 Kudos