- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Gateway certificate has expired
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gateway certificate has expired
Hi Guys,
While accessing the remote VPN, getting gateway certificate expired alert.
Error:Connection Failed
"Gateway certificate has expired. Please check your's computer time and date settings"
I have checked the VPN expiry date but it is 14th may 2021.
Can you please help me on this.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To renew the certificate:
- Edit the Check Point Gateway Object Properties in SmartDashboard.
- Go to the IPSec VPN tab.
- Under the Repository of Certificates section, click the "Renew" button.
- Click "Yes" to continue.
- Click "OK" to generate Keys and get Internal CA Certificate.
- Click "OK" on the Gateway Properties.
- Install Policy on the gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Have you checked times on your computer and your gateway/management? Are you using NTP ?
Did you check defaultCert certificate inside IPsec VPN tab of the affected gateway ?
What warning you are getting once you install policy on affected gateway ? Or, are you even able to install policy on affected gateway ?
Do you have valid license? did you use eval lic in the past which may expire ?
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thanks for the reply.
i have checked the IPSEC VPN tab under the activie gateway. In the tab default certificate is expired.
Can you please help me how to renew the default certificate in the IPSEC vpn.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You should see "Renew" button there, please try selecting the option.
Regards, Prabu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To renew the certificate:
- Edit the Check Point Gateway Object Properties in SmartDashboard.
- Go to the IPSec VPN tab.
- Under the Repository of Certificates section, click the "Renew" button.
- Click "Yes" to continue.
- Click "OK" to generate Keys and get Internal CA Certificate.
- Click "OK" on the Gateway Properties.
- Install Policy on the gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi _Val_,
I'm just wondering maybe the VPN certificate renew can be done with mgmt_cli?
I haven't found any related topic in the guide.
What is your opinion?
BR
A
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Kindly confirm if certificate to be export and share with users after renewal or it will automatically get synced ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I do not think so, the procedure is already described above
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Valerie,
Does the VPN connection get disrupted or glitched during the cert renewal?
Should I schedule a planned outage, even for a minute, prior to certificate generation?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Who's Valerie?
It is always a good idea to plan for downtime. Plan for a short interruption around policy installation time
