- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Checkpoint 81.10 1800 Appliance VPN clients re...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint 81.10 1800 Appliance VPN clients reconnecting
I'm having problems with my gateway 1800 R81.10. Since early this morning, VPN clients keep reconnecting. They connect, but after a short time, they restart without allowing access to anything.
I've already checked the logs on the firewall's web portal and haven't found any errors.
Forgive my inexperience, but is there any troubleshooting I can do to understand what is wrong?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the situation is stable since upgrade to 81.10 version and following these TAC instructions:
Please clear the cache files related to the certificate and make sure that the following steps are performed:
1. The hashed-name certificates found on relevant SMB appliances via this Expert Mode command:
find / -name *.crt
2. All hashed-name certificates deleted via Expert Mode command "rm":
Example:
rm /pfrm2.0/config1/f08dfji3hf9du3.crt
Once Above procedure is done, please try to reinitialize internal certificates on SMB appliance and after this try to connect via Remote Access VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
what version of FW do you have on GW?
is a specific group of users defined or a specific destination instead of Any regarding VPN?
I registered the same problem in the case when a source or destination other than Any from R81.10.10, R81.10.08 and earlier did not have this problem. If it is R81.10.10, I can try to place here a solution that helped me (at least with local management, I can't verify the central one at the moment).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @henfii
thanks for the reply
yes I was with 81.08 and VPN AD validation
the TAC advice me to upgrade to 81.10.
not solved but is better, right now we still get disconnected but it holds for a few hours.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some debugging is in order: https://support.checkpoint.com/results/sk/sk62482
TAC will probably have to analyze the output.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks, that's wat we send to TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what is running on the clients itself? Is that updated?
You see traffic drops in logs from VPN ip(office mode pool ip) and or public IP they are connecting from?
How is the load of that firewall during the day?
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the situation is stable since upgrade to 81.10 version and following these TAC instructions:
Please clear the cache files related to the certificate and make sure that the following steps are performed:
1. The hashed-name certificates found on relevant SMB appliances via this Expert Mode command:
find / -name *.crt
2. All hashed-name certificates deleted via Expert Mode command "rm":
Example:
rm /pfrm2.0/config1/f08dfji3hf9du3.crt
Once Above procedure is done, please try to reinitialize internal certificates on SMB appliance and after this try to connect via Remote Access VPN.
