- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
I wonder why changing hostname of DMS (multi domain) will still preserve the SIC to Security gateway while changing hostname on SMS will break SIC.
is there any distinguish between this as Each DMS also store its own ICA based on mdm admin guide.
thank you.
br,
Anthony
I assume if you changed the name of a CMA/Domain, you'd experience the same issue you'd experience with an SMS.
The MDS name isn't relevant in the SIC certificates gateway objects are provisioned with, the management server name (and, by extension, the CMA/Domain) is.
Hi Dameon,
Thank you for your reply.
Sorry rephrase the question. When i performed migrate export of the CMA, i can go on to change the CMA name and performed import with the CMA export which contained previous name.
And the SIC still preserved with new CMA name after the cma import.
While i am unable to do so on normal SMS.
Just trying to understand this as i have performed this for customer and it amuses me how checkpoint ICA works.
Hope to get enlightment here ![]()
Thank you.
Best regards,
Anthony
Hm... gotta admit, I don't know that one.
That said, I think the hint is in the SIC name.
Hi Dameon,
Thank you for the reply. No worries just trying to understand better how Checkpoint infra works. ![]()
Best regards,
Anthony
When you import an export file into a newly created CMA one of the core functions that occur is a migration of the certificate authority. The name of the CMA and the ICA do not necessarily need to match in an MDS environment. If you create a domain called "Production" and import a file that was taken from a server named "Lab", your certificate authority will actually still be called "Lab". This can be confirmed in Cpconfig or by running "#cpca_client lscert -kind SIC -stat Valid". Testing SIC to a gateway will show Lab in the cert string. All certificates created going forward will still have Lab in the name.
Sometimes this needs to be changed, because the customer just wants to see the new name or because a template domain was used to create 2 or more CMAs. Duplicate ICAs in domains can cause quite a few headaches and is detailed in sk17197. The resolution to both duplicate domains and just wanting to see a new name in the cert string is a full ICA reset. Part of the procedure requires resetting SIC to all gateways and re creating all VPN certificates, no way around it. Helpful documents are sk94871, sk34887, sk42071, and sk32491.
While I believe the same concepts apply to R80 the procedures listed do not.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY