I've been working on a site to site VPN to a Palo Alto recently, that needs to be certificate based.
We have finally made progress, but now have a very unusual situation, or at least it's unusual to me, but I'm hoping someone else has come across this before!
From the PA end, a ping brings up the tunnel, but from the Checkpoint end a ping does not bring up the tunnel, it gives an authentication failure!
I'm sure this must be related to the certificate but I don't know why.
Has anyone else seen this before I raise it with TAC?