- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
The gateway VPN certificates are coming up to expire so need to renew those. I gather though that that is the certificate that is used for trust between the identity collector agent. Is there anything that needs to be done on the IA Agent server as well and would there be impact for when we do the renewal on the GW in terms of identities? We're not using third party certificate provider for this.
Normally, you would get at least one week warning, but with R81+, I believe its 60 days. There is no risk, you can easily do it in the middle of the day. I done so with customers many times before and was fine. Though, to be 100% sure, maybe better do it after normal working hours. I never even seen a single case where any VPN tunnel went down when this was done. To my recollection, there was never an issue with IA agents either.
Best,
Andy
Normally, you would get at least one week warning, but with R81+, I believe its 60 days. There is no risk, you can easily do it in the middle of the day. I done so with customers many times before and was fine. Though, to be 100% sure, maybe better do it after normal working hours. I never even seen a single case where any VPN tunnel went down when this was done. To my recollection, there was never an issue with IA agents either.
Best,
Andy
Thanks for the advice and didn't have any blips for IA or need to do anything on the collector side which is great 🙂
Good to hear 🙂
Andy
Could you please advise on how to renew this certificate or how can i check the expiration date. The gateway is only running ID blade and not any VPN blade. The ID collector says VPN certificate so where do I view or renew on the Gateway
I was referring to vpn cert, which would be there if you are running vpn blade on the fw. If not, maybe attach a screenshot, so we can verify.
Best,
Andy
You need to temporarily enable IPSEC VPN blade, then IPSec VPN then select the cert and click renew then disable VPN blade again. You don't need to push after enabling/disabling is just to get the VPN section in GW properties to appear. I did have an SK showing this but can't find it at the moment but will add if I can find it
This should give the expiry date
cpca_client lscert -stat Valid -kind IKE
That for sure makes sense to me. Just doing some Azure studying now, but will check later in the lab,
Best,
Andy
Hey bro, this one?
Was a combination of these. There was another one that said to run a tcpdump as well to see cert expiry that got me on the right track but can't locate or that SK has been updated/removed to not show that bit anymore
https://support.checkpoint.com/results/sk/sk113021
https://support.checkpoint.com/results/sk/sk105723
https://support.checkpoint.com/results/sk/sk97792
Good job!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
12 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
4 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY