- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hi,
My VPN certificate on R81.20 Gateway expires soon and I went through the usual process of deleting the existing and creating a new one, however today I got hit with this message
I have not seen this before and cant find anyway round it. Found a similar post about using GuiDBedit, but that didnt work.
Any help greatly appreciated
Happy New Year
Wayne
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I never delete and always use renew, have you tried that?
So instead of delete either add or renew?
You try it now to renew it under IPSec VPN correct?
Hi Lesley,
The renew option has never been available for certs generated by external CA (i assumed this was the case)
I cannot renew and if i try ADD i cant use the same CN details
Cheers
Wayne
Ah not self-signed.
What if you create a temp self signed cert and attach that, after that try to remove the old one.
Still no go
Can you share a little bit larger screenshot? In which menu did you get this message?
Whan you changed this cert last time, this cert was used in clientless VPN too?
Akos
Hi Akos,
My larger images seem to get removed. I always do this under IPSecVPN and have never configured Clientless VPN
Cheers
Wayne
To clarify this, so here:
You add the new one, then can't remove the old one?
Correct, at the moment I have a cert installed from an EXT CA
When i try to remove (as renew greyed out), the error message appears
I have never seen this before
Thanks
I had a try, I wanted to delete the cert which was issued by ICA
I got this error:
Maybe helps.
A
Weird, just tried in my lab and though its part of 3 commuities, does not give that error.
Andy
Make sure that if you have the temp cert active the old one is not configured in a different place.
Did you checked all the menu options in the firewall object itself? Like under VPN clients.
Hi Lesley,
Yes, i cannot see it selected anywhere else
I think we need some screenshots. Sometimes a feature is disabled and you need to enable it in order for renewal.
We haven't talk about the version. What is current version?
I found this sk, but it is not relevant, R80.20 is not supported, and the error message is totally different.
https://support.checkpoint.com/results/sk/sk108064
Akos
Saw that, but it did nothing
Thanks
Maybe it is time to open a TAC case.
Yes time for TAC
Please keep us updated. 🙂
I believe what its telling you to do is remove any references of that certificate currently, install policy and then delete option would work.
Andy
yes, I am pretty sure all refences have been removed.
Waiting for TAC
Cheers all !!
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Great!
Thanks to share with us!
Hi Guys,
I seem to have now developed another issue, similare to post https://community.checkpoint.com/t5/Remote-Access-VPN/Remove-Access-VPN-Gateway-presenting-wrong-cer...
With the faulty Ext CA gone, I got a new one and it all installed ok, however when I inspect the SSL cert the FW presents the default one and not the Ext CA.
Very weird
Any ideas?
Thanks
Wayne
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I tried a CPSTOP and CPSTART and that did the trick.
Thanks
That should work also.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY