- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
My VPN certificate on R81.20 Gateway expires soon and I went through the usual process of deleting the existing and creating a new one, however today I got hit with this message
I have not seen this before and cant find anyway round it. Found a similar post about using GuiDBedit, but that didnt work.
Any help greatly appreciated
Happy New Year
Wayne
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I never delete and always use renew, have you tried that?
So instead of delete either add or renew?
You try it now to renew it under IPSec VPN correct?
Hi Lesley,
The renew option has never been available for certs generated by external CA (i assumed this was the case)
I cannot renew and if i try ADD i cant use the same CN details
Cheers
Wayne
Ah not self-signed.
What if you create a temp self signed cert and attach that, after that try to remove the old one.
Still no go
Can you share a little bit larger screenshot? In which menu did you get this message?
Whan you changed this cert last time, this cert was used in clientless VPN too?
Akos
Hi Akos,
My larger images seem to get removed. I always do this under IPSecVPN and have never configured Clientless VPN
Cheers
Wayne
To clarify this, so here:
You add the new one, then can't remove the old one?
Correct, at the moment I have a cert installed from an EXT CA
When i try to remove (as renew greyed out), the error message appears
I have never seen this before
Thanks
I had a try, I wanted to delete the cert which was issued by ICA
I got this error:
Maybe helps.
A
Weird, just tried in my lab and though its part of 3 commuities, does not give that error.
Andy
Make sure that if you have the temp cert active the old one is not configured in a different place.
Did you checked all the menu options in the firewall object itself? Like under VPN clients.
Hi Lesley,
Yes, i cannot see it selected anywhere else
I think we need some screenshots. Sometimes a feature is disabled and you need to enable it in order for renewal.
We haven't talk about the version. What is current version?
I found this sk, but it is not relevant, R80.20 is not supported, and the error message is totally different.
https://support.checkpoint.com/results/sk/sk108064
Akos
Saw that, but it did nothing
Thanks
Maybe it is time to open a TAC case.
Yes time for TAC
Please keep us updated. 🙂
I believe what its telling you to do is remove any references of that certificate currently, install policy and then delete option would work.
Andy
yes, I am pretty sure all refences have been removed.
Waiting for TAC
Cheers all !!
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Great!
Thanks to share with us!
Hi Guys,
I seem to have now developed another issue, similare to post https://community.checkpoint.com/t5/Remote-Access-VPN/Remove-Access-VPN-Gateway-presenting-wrong-cer...
With the faulty Ext CA gone, I got a new one and it all installed ok, however when I inspect the SSL cert the FW presents the default one and not the Ext CA.
Very weird
Any ideas?
Thanks
Wayne
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I tried a CPSTOP and CPSTART and that did the trick.
Thanks
That should work also.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY