Dear Checkmates,
we are currently planning the upgrade of our management server to R81.20.
While we understand that if the management server is down for too long, IP-Sec VPN gateways will start to go offline due to beeing unable to fetch the CRL from the management CA, we are not 100% sure on the exact details of this and how we can influence it.
According to sk100731 the gateways need to fetch the CRL every 24h, otherwise VPN will start to terminate.
We are not sure where the automatic fetching interval is configured. In the global properties of SmartConsole there is a "prefetch_crls_duration" setting that defaults to 2 hours while on the internal_ca object in the SmartConsole there is an advanced setting that states that the CRL will be cached on gateways and fetched every 120 hours.
Looking at the SMB gateways, there is a .crl file created at the "/pfrm2.0/config2/fw1/database/" path with the name ICA_<management name>_ <CA identifier>.crl. At first we thought according to the modify date of that file we could monitor when the last fetching of the CRL was done, however there are some modify times with >24h, which should not be possible since the VPN should go offline than.
Can anyone shed some light about where to configure the CRL fetching interval and how we can check at the SMB gateway when the last sucessfull CRL check was done?
Thanks for your help.