- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Looks like you're using Gaia WebUI. This error is from your browser which doesn't like the TLS version being negotiated. Your browser may have a TLS configuration imposed by a GPO from your organization. You can try with Firefox instead to see if that works. For example, depending on your gateway configuration, the Gaia portal may not be able to support TLS 1.3:
https://support.checkpoint.com/results/sk/sk178505
If your GPO enforces TLS 1.3, then this may be your issue.
Can you confirm that this firewall is still running supported software? 90% of the time this error is related to ancient firewall software
What version? You can always try change web UI port and test
clish -> set web ssl-port 4434 -> save config -> test
If that fails, I would try open old school Internet explorer and see if that works
https://superuser.com/questions/1824875/where-is-internet-options-now-that-internet-explorer-is-gone
control panel -> internet options -> programs -> manage add-ons -> learn more about toolbars and extensions
Andy
What version/JHF is the device?
Older (out of support) versions may not support the ciphers mandated by current web browsers.
R81_10_JUMBO_HF_MAIN Take: 139
Did you try what we suggested?
Andy
Did you check to see if your organization enforces the use of TLS 1.3 as suggested by @Duane_Toler ?
organization enforced to use TLS 1.2 and same is configured in gateway as well.
Can you reach the gateway via other means (e.g. ssh)?
What is the network path between your client and the gateway and does it include any other firewalls?
VPN blade is not enabled, what is the process for renewal for self signed certificate in gateway ?
self signed certificate renewal fixed the issue.
Thats odd, can you send screenshot of that vpn tab? How did you renew it if blade is not even on??
CP Support did that, i am not sure about that.
Do you have commands they ran?
Andy
This is documented in https://support.checkpoint.com/results/sk/sk97792
VPN certificate is not only used for interal VPN but also for:
Ah, that sk...seen it before, though personally, I always thought there was an easier way to do this rather than enabling/disabling the blade 🙂
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
25 | |
11 | |
9 | |
9 | |
7 | |
7 | |
7 | |
5 | |
5 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY