Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BG
Participant

Multi-Portal certificates does not renew

Hi all,

Mobile Access and IPSec VPN blades are enabled on firewall (R81.20 JT89). A couple of days ago certificate was expiring so we used "SmartConsole -> IPSec VPN -> Repository of Certificates Available to Gateway" section to renew certificate. From there it seems that certificate is renewed but if we access to mobile access portal page or usercheck page, these portals are still using old certificate. Also Identity Collector agents can not connect to gateway because of expired certificate. We also tried to use script provided in the https://support.checkpoint.com/results/sk/sk182070 but still old certificate is in use.

Is this a TAC case or am I missing something?

0 Kudos
7 Replies
G_W_Albrecht
Legend Legend
Legend

After the script from sk182070 was used to renew, what does ./gateway_cert_util.sh -show all show ? You did perform a policy install after renewal ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
BG
Participant

Hi,

Command output is below. After renewing certificate with the script we have installed the policy. Screenshot 2025-01-07 142407.png

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Better contact TAC (after rebooting all to be sure)...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
BG
Participant

A reboot solved the problem. Thanks.

0 Kudos
PhoneBoy
Admin
Admin

Believe this is a known issue currently that will be fixed in a future JHF.
I believe it is vpnd that needs to be restarted here (though a cprestart or reboot will also solve it).

0 Kudos
Lesley
Mentor Mentor
Mentor

There are 2 certificates, one that is used for MAB and other one for IPSec VPN. Did you renew both?

Gateway -> Mobile access -> portal settings

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Lesley
Mentor Mentor
Mentor

Extra tip

https://support.checkpoint.com/results/sk/sk177903

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events