I’m not sure if what i am doing below is correct? i am still trying to lab it before asking customer to do it. If you have step by step, could you share with about that?
Much respect to anyone who has adopted this configuration and shared it with me. Is it necessary to use User login and AD user? or any user is fine?
I have created a CA named mtech-lab.local and created a Trust Server CA on Check Point.
Next, I go to IPsec in Object GW and create an enroll cert, then put it in CA issue and complete on GW.
I have installed the machine and CA certificates on the local machine and in the Personal & Trusted Root Certification Authorities folders.
Next, I enabled cert authen and created a policy. I use local user created on Check Point to authenticate VPN and machine is on AD.
As a result, when VPN we still cannot connect to internal resources. When we switch Auhen Machine to Mandatory and VPN, we get an error message "Machine Certificate Is Required". This means that the Import Cert is still incorrect.