Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Contributor

R80.10 can't resolve CRL distribution point address

Jump to solution

I'm trying add external CA for authentication of remote clients. When I disable CRL checking all works fine. But when I enable this check the gateway send "can't retrieve crl" message to client. 

CRL distribution point address leads to internal net resource, which does not present in internal DNS. That's why it was added in hosts file from GAIA's management portal. 

In vpn debug present "Can't resolve address". But, when I reboot gateway it starts resolving CRL distribution address and it begin works  up to 10-15 minutes.

On R76 and R77.30 this setting works without any problems.

Any ideas?

0 Kudos
Reply
1 Solution

Accepted Solutions
Contributor

Adding A-recod on DNS and rebooting nodes resolved the issue

View solution in original post

0 Kudos
Reply
2 Replies
Contributor

Adding A-recod on DNS and rebooting nodes resolved the issue

View solution in original post

0 Kudos
Reply
Admin
Admin

Thanks for sharing how you resolved the issue.

0 Kudos
Reply