- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
My main question, how to reach Rating A on ssllabs.com? My certificate chain is broken. And i have no idea how to fix it.
Actually CheckPoint's SSL certificates are not clear for me. First of all - three location, first one - IPSec VPN (we can generate CSR with proper SSL Chain - Root/intermediate/Cert itself), second location - Mobile Access/Portal Settings, third - VPN Clients/SAML Portal.
When i installed self-signed certificate into first location (IPSec VPN) and/or Mobile Access i was getting error. Third location (SAML) i guess not alive anymore. Which one using for Endpoint VPN client? i though Mobile is for Phones and IPSec like for legacy windows VPN clients. Is it right?
My certificate expired and i have to update it, when i did it first time, two years ago, version 80.30 didnt support wild card certificates, and i generated certificate from IPSec VPN and next used openssl magic for conversion to PFX format and next installed it to Mobile access portal. But i dont remember how i did it, and checkpoint support guy said - its wrong and need two certificates. How it works in this case? for example vpn.contoso.com for IPSec and vpnssl.contoso.com for mobile? i think i will see error
same time i have DR firewall, and i generated one certificate from IPSec VPN, and it works fine, my Endpoint Client ignores Mobile Portal and use right certificate (and it has rating A, because certificate chain is ok).
Could explain how it works and how to configure it properly?
thanks
Hi @Sergo89,
Here are some tips and sk's about the certificates.
| Mobile Access Certificate |
The Security Gateway does not have a server certificate that is signed by a trusted 3rd party. Make sure that the server certificate of the Mobile Access gateway is signed by a trusted 3rd party Certification Authority (for example, EnTrust, VeriSign). The 3rd party certificate must replace the self-signed (ICA) certificate.
Note: if you receive a .pfx file, rename the file extension from .pfx to .p12
| GAIA Portal Certificate |
See sk97648:
How to create and set certificate for Gaia Portal
or sk116462 for old firewalls:
How to Install P7b format 3rd-party signed certificate on Gaia Portal without Multiportal feature
| Internal CA Certificate |
sk158096: How to renew an Internal Certificate Authority (ICA) certificate
| VPN Certificate |
See R8x.x VPN admin guide chapter PKI:
R81.10 Site to Site VPN Administration Guide - PKI
Thanks Heiko, but what do you mean "server certificate"? IPSec or Mobile, and yes i know how to create mobile certificate, but it will be two different certificates with different names. and which one Endpoint client uses? right now it shows me Mobile certificate (wildcard)
Then I still do not understand your question 100%.
>>> and which one Endpoint client uses?
With the VPN client, it depends on which one you install:
Endpoint Security VPN -> Uses the internal CA certificate (ICA) and before E80.60 + lower R80.20 the gateway certificate.
Check Point Mobile -> Uses the Mobile Access blade SSL certificate
Its Endpoint VPN, full bundle with AV.
Endpoint Security VPN -> Uses the internal CA certificate (ICA) and before E80.60 + lower R80.20 the gateway certificate.
its mean - IPSec VPN cert?
>>> Its Endpoint VPN, full bundle with AV.
For AV scanning you need an additional endpoint server and the managed client sk166428:
>>> its mean - IPSec VPN cert?
Yes - IPSec VPN uses the internal certificate (ICA) for "Endpoint Security VPN" client.
Thanks Heiko,
how to choose which type of VPN we will be using? Full Endpoint Version doesnt have options (Mobile is different story). Do i have to create two different SSL certificates for IPSec VPN and SSL VPN?
Oh! what 0 have found in the manual:
Note - The Repository of Certificates on the IPsec VPN page of the gateway object is only for self-signed certificates. It does not affect the certificate installed manually using this procedure.
Heiko,
is it possible to find somewhere Private Key when we generate certificate from GUI (IPSec VPN)?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY