- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I'm trying to establish and IPSEC (S2S) tunnel between 2 managed Check Point firewalls. I previously succeeded with the same kind of HW/version. This one throws an error I've never seen before :
Main Mode Failed to match proposal: Transform: SHA1, Certificate, Group 2 (1024 bit); Reason: unsupported encryption algorithm -1 (NA)
I've tried lowering the algorithm, still the same issue.
Any idea how to troubleshoot that ? I'm currently planning on upgrading that remote GW to the latest available firmware, and rebooting it.
Thanks !
Hi,
I actually updated the firmware to the latest version available, and it solved it.
Thanks for your help.
Regards.
I cant say 100% this is related, but just see what you have there. I changed mine, so yours would look different if you never touched it.
Andy
Hi, thanks for your answer. In my case I don't have the same screen as yours, all should be set in the Community:
And in the said community (I tried various combination):
This works for more than 10 gateways in the same community (as Satellite), but doesn't work for a new one I wanted to add. 😞
Ok, so just to make sure I get this right, apologies if I had wrong assumption. Are you saying there are multiple satellite gateways with one centre gateway? If so, is it the case that this new firewall you added is also a satellite, correct? And thats where you get the error?
Exactly, this community is used for many of our remote offices, and I just want to add a new one into it. The Centre gateway is our main cluster, and the Satellites are the remote offices' firewalls. The one that I didn't succeed in adding is a remote office, so a Satellite. That's where I get the error.
SHA1 has been deprecated for awhile now, is the new gateway perhaps running a newer version of code that is blocking the use of SHA1? DH Group 2 is pretty old but should still be supported by all code versions.
I get what @Timothy_Hall is saying...though, I had seen customer running on R81.10 use sha1 and works perfectly fine. I would definitely confirm with TAC to get official statement/answer.
Hi,
I actually updated the firmware to the latest version available, and it solved it.
Thanks for your help.
Regards.
These were SMB GWs ?
Yes it was 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 15 | |
| 13 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY