- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi, from last friday we have problem with vpn configured by communities.
there are problem during IKE phase with certificate
I try to disconnect gateways from console, reinitialize certificates and reconnect.
I try also to cancel community and ricreate but all attemps don't work.
The communities are configure in star or mesh VPN Type but none work.
The error message is pretty clear: "main mode cannot complete certificate chain."
That points to an error with the Certificate Authority key you've imported.
If the CA key is not a root CA (i.e. it's signed by another CA key), you need to include the entire certificate chain in the .p12 file you import (meaning the public CA key you care about along with all the public CA keys required to validate that signature).
Gateways involved until friday work fine i don't make any change.
Our gateways are 600, 700 and 1500 series locally managed by Quantum Sparks SMP.
Where i find CA key? on SMP?
This is for the CA key that you are using to authenticate the VPN, which I believe is configured in SMP.
If it's the internal CA you're using, then you'll probably need the TAC to assist in resolving this issue.
If it's a different CA, then you'll have to see if the gateways can (among other things) reach the CRL specified as part of the public key.
As I explained in the other thread there was an event on Oct 6 that may require you to take some action, refer:
https://status.checkpoint.com/
Hi
There are a few suggested ways to handle this issue:
From the web UI: Disconnect from SMP, remove the old trusted CA, reconnect to SMP
if this doesn't work, please open a TAC case, there are more advanced ways to solve it.
Thanks
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY