- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi,
My VPN certificate on R81.20 Gateway expires soon and I went through the usual process of deleting the existing and creating a new one, however today I got hit with this message
I have not seen this before and cant find anyway round it. Found a similar post about using GuiDBedit, but that didnt work.
Any help greatly appreciated
Happy New Year
Wayne
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I never delete and always use renew, have you tried that?
So instead of delete either add or renew?
You try it now to renew it under IPSec VPN correct?
Hi Lesley,
The renew option has never been available for certs generated by external CA (i assumed this was the case)
I cannot renew and if i try ADD i cant use the same CN details
Cheers
Wayne
Ah not self-signed.
What if you create a temp self signed cert and attach that, after that try to remove the old one.
Still no go
Can you share a little bit larger screenshot? In which menu did you get this message?
Whan you changed this cert last time, this cert was used in clientless VPN too?
Akos
Hi Akos,
My larger images seem to get removed. I always do this under IPSecVPN and have never configured Clientless VPN
Cheers
Wayne
To clarify this, so here:
You add the new one, then can't remove the old one?
Correct, at the moment I have a cert installed from an EXT CA
When i try to remove (as renew greyed out), the error message appears
I have never seen this before
Thanks
I had a try, I wanted to delete the cert which was issued by ICA
I got this error:
Maybe helps.
A
Weird, just tried in my lab and though its part of 3 commuities, does not give that error.
Andy
Make sure that if you have the temp cert active the old one is not configured in a different place.
Did you checked all the menu options in the firewall object itself? Like under VPN clients.
Hi Lesley,
Yes, i cannot see it selected anywhere else
I think we need some screenshots. Sometimes a feature is disabled and you need to enable it in order for renewal.
We haven't talk about the version. What is current version?
I found this sk, but it is not relevant, R80.20 is not supported, and the error message is totally different.
https://support.checkpoint.com/results/sk/sk108064
Akos
Saw that, but it did nothing
Thanks
Maybe it is time to open a TAC case.
Yes time for TAC
Please keep us updated. 🙂
I believe what its telling you to do is remove any references of that certificate currently, install policy and then delete option would work.
Andy
yes, I am pretty sure all refences have been removed.
Waiting for TAC
Cheers all !!
Fixed it.
First took snapshot of SM VM (in case I bust it)
Used GuiDBedit and found entry for VPN refence in the FW object
Deleted it
Saved changes
Said a prayer
Opened Smart Console
VPN reference gone
Pushed policy for good measure
Still gone
Case closed
Thanks for all your help guys !!
Great!
Thanks to share with us!
Hi Guys,
I seem to have now developed another issue, similare to post https://community.checkpoint.com/t5/Remote-Access-VPN/Remove-Access-VPN-Gateway-presenting-wrong-cer...
With the faulty Ext CA gone, I got a new one and it all installed ok, however when I inspect the SSL cert the FW presents the default one and not the Ext CA.
Very weird
Any ideas?
Thanks
Wayne
Depending on the JHF level, you might need to reboot for the change to take effect as I believe this is a known issue.
I tried a CPSTOP and CPSTART and that did the trick.
Thanks
That should work also.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY