Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mohit136971
Explorer

Remote access vpn with enrolment key certificate not working

Hi Team,

 

I am using 3600 and 9300 firewall for my customer. I have configured Remote access vpn with enrolment key certificate.

For 3600 firewall it is working fine but for 9300 series firewall it is not working. When I connect through vpn client it shows enrolment failed. Does anybody know why it is not connecting to 9300 series firewall. The configuration is same. Should I have to do any other steps on 9300 series firewall.

Also username + password for RAVPN is working fine but not working for Certifcate+username password.

 

Version- R81.20 JHF 118

TAC also haven't find the solution yet. It's pending from 20 days.

Please help me to resolve the issue.

0 Kudos
2 Replies
the_rock
MVP Platinum
MVP Platinum

Any other relevant messages except enrollment failed?

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

If this is related to machine certificate issue, please see what TAC sent to one of our clients last yer and this actually did work.

*****************

- Policy had not been installed on the gateways since March 15. Sessions had been published, but not pushed to the gateways. Much of the configuration has taken place since then.
- Post installation, we needed to perform sk116997 as the CSP used for the machine certificate did not allow the use of SHA256 hashing for authentication.
- While we were trying to correct the machine certificate CSP, users were unable to connect to the remote access VPN as they did not belong to the remote access community. Performed sk91844 to change "fetch_type" to "fetch_options", and disabled "ldap_fetch" to prevent LDAP lookup of group memberships, as we wanted users to match the generic* profile and not LDAP.

Following the successful installation of policy, and the changes detailed in sk116997 and sk91844, we saw machine certificate authentication was being performed during login.

*********************************

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events