- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Looks like you're using Gaia WebUI. This error is from your browser which doesn't like the TLS version being negotiated. Your browser may have a TLS configuration imposed by a GPO from your organization. You can try with Firefox instead to see if that works. For example, depending on your gateway configuration, the Gaia portal may not be able to support TLS 1.3:
https://support.checkpoint.com/results/sk/sk178505
If your GPO enforces TLS 1.3, then this may be your issue.
Can you confirm that this firewall is still running supported software? 90% of the time this error is related to ancient firewall software
What version? You can always try change web UI port and test
clish -> set web ssl-port 4434 -> save config -> test
If that fails, I would try open old school Internet explorer and see if that works
https://superuser.com/questions/1824875/where-is-internet-options-now-that-internet-explorer-is-gone
control panel -> internet options -> programs -> manage add-ons -> learn more about toolbars and extensions
Andy
What version/JHF is the device?
Older (out of support) versions may not support the ciphers mandated by current web browsers.
R81_10_JUMBO_HF_MAIN Take: 139
Did you try what we suggested?
Andy
Did you check to see if your organization enforces the use of TLS 1.3 as suggested by @Duane_Toler ?
organization enforced to use TLS 1.2 and same is configured in gateway as well.
Can you reach the gateway via other means (e.g. ssh)?
What is the network path between your client and the gateway and does it include any other firewalls?
VPN blade is not enabled, what is the process for renewal for self signed certificate in gateway ?
self signed certificate renewal fixed the issue.
Thats odd, can you send screenshot of that vpn tab? How did you renew it if blade is not even on??
CP Support did that, i am not sure about that.
Do you have commands they ran?
Andy
This is documented in https://support.checkpoint.com/results/sk/sk97792
VPN certificate is not only used for interal VPN but also for:
Ah, that sk...seen it before, though personally, I always thought there was an easier way to do this rather than enabling/disabling the blade 🙂
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 23 | |
| 15 | |
| 12 | |
| 12 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Tue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEATue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEAThu 13 Nov 2025 @ 10:00 AM (CET)
Cloud Architect Series - Guarding Generative AI: Next-Gen Application Security with CloudGuard WAFFri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY