Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marcus_Smith
Participant

Need Help Resolving VPN Issue - "VPN-1 Server could not find any certificates to use for IKE."

Hello forum members,

I hope you're all doing well. I'm facing an issue with my VPN connection, specifically when attempting to connect using EndPoint Security after putting a new certificate in place. I've been troubleshooting this problem but unfortunately, I haven't been able to find a definitive solution. 

Error Message on Client: "VPN-1 Server could not find any certificates to use for IKE."

Error Log on Management Server REJECT Log: More Details: "Ike Main Mode I have no certificate to send." Reject Category: IKE failure.

I followed this detailed guide SSL CERTIFICATE ON CHECK POINT – QOS Technology to setup the CA and Generate the certificate.  I believe this is all correct.

0 Kudos
4 Replies
the_rock
Legend
Legend

Make sure VPN cert on the gateway object is not expired.

Andy

0 Kudos
PhoneBoy
Admin
Admin

What version/JHF?
What version of the client?
Screenshots of the relevant configuration you changed? (Blur sensitive details)

0 Kudos
Marcus_Smith
Participant

Thank you for your response.

The management appliance is running R81.10 and the Gateway (Cluster) is also running R81.10 with Jumbo Hotfix Take 95.

All I have done is: -

Add a new Trusted CA under servers along with a Subordinate CA.

Open the Gateway Cluster Properties, IPSec VPN, Generate a new certificate using the new Certificate Authority. 

Under "VPN Clients" I have changed "The gateway authenticates with this certificate" to the new one. I have also done the same under "Remote Access" Support L2TP Use this certificate. 

EndPoint Connect version E86.10.

0 Kudos
PhoneBoy
Admin
Admin

You may need a TAC case to understand what's going on here: https://help.checkpoint.com

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events