- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
We have a large number of IPSEC VPN tunnels between our R77.30 gateway clusters.
Yesterday we upgraded one of the remote clusters to R80.20. After the upgrade the tunnel was still working fine, until we pushed policy to the R77.30 cluster late last night.
Now the tunnel will not stay up. If I push the R80.20 cluster it comes up briefly, then fails again.
The error message is
Auth exchange: Sending notification to peer: Authentication failed MyAuthMethod: Certificates
I have support ticket open, but is there something simple and obvious I am missing?
Thanks
it turned out to be an unrelated issue. The Remote gateways were not able to reach the management server to check the validity of the certs. Once that was resolved the tunnels came up
Thanks
I removed the R80.20 gateway from the VPN, pushed to both gateways, added it back in and pushed again, and now the tunnel is up.
Checkpoint recommendation is to renew the cert, but each of our gateways is involved in multiple VPNs, so we will end up pushing to the whole estate eventually.
@Scott_Paisley did you find the root cause of this? Could it have been that after upgrade that PFS was turned off?
I just saw similar behaviour going from R80.10 to R80.30. Im pretty sure I had PFS enabled before upgrade. It was disabled after upgrade I think. I reenabled, and it looks more stable.
it turned out to be an unrelated issue. The Remote gateways were not able to reach the management server to check the validity of the certs. Once that was resolved the tunnels came up
I know this post is a little bit old, but this worked for me. Thanks!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY