- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have many 1100/1400 smart provisioned, centrally managed appliances which do CRL check with management server (fw1_ica_services port) and if check fails tunnel is dropped with default of 24h. Is there a way to disable this check i.e. sk21156 ? I don't need CRL check because if I don't want appliance to have tunnel up I will terminate the provisioned object on mgmt server. Please advice
I think the following will work on the gateway, see here
cpprod_util CPPROD_SetValue "CPshared//6.0//reserved//libCurl" crl_disable 1 1 1
I don't see why you couldn't apply the SK you referenced to solve the issue, even if you're using SmartProvisioning.
Correct. It's not really an issue, CRL check is default (by design) but I think it creates Denial of Service risk because the port has to be opened on public IP.
Thanks, killing the CRL check solved my problem. My management server is nat'd behind a firewall on a large private secondary network. Support was sending me down the path of disabling all of my implied rules. That was not going to happen.
Is anyone aware of an emergency procedure to disable this check on the gateways only? Say the primary and secondary management is down (assuming there is even a secondary). It would be great to have a way to disable the check on the gateway itself without deploying policy. This would allow the use of CRL check but just in case of that 1 big disaster that takes out management and it isn't recovered in 24 hours, you can keep your other gateways communicating through their managed VPN (certificates only work for that).
You can disable CRL verification for VPNs on the management side, but I do not think there is a way to do that on the GW side, let alone on SBM appliances.
I think the following will work on the gateway, see here
cpprod_util CPPROD_SetValue "CPshared//6.0//reserved//libCurl" crl_disable 1 1 1
Hello Timothy
I used the command you shared in order to disabling CRL checking with success.
The CRL checking was preventing to work a VPN tunnel between to Check Point CAs (SMSs). The link to the issue bellow:
Thanks for your help
Miguel
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY