- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
I have tried many times to add my gateway to IDC but still have same problem "Wrong shared secret"
I have tried difficult passwords and easy passwords with same result: "Wrong shared secret"
I run a lab environment gateway 81.10:
show version all
Product version Check Point Gaia R81.10
OS build 335
OS kernel version 3.10.0-957.21.3cpx86_64
OS edition 64-bit
IDC was downloaded from this link:
https://support.checkpoint.com/results/sk/sk134312
Identity Collector - for Windows OS
install policy and then test in IDC and then same "Wrong shared secret"
any ideas on what is wrong?
Follow this sk
https://support.checkpoint.com/results/sk/sk113021
Maybe something simple like closed port between IDC and gateway
I have now found the problem from the text of sk113021
the machine where IDC is installed "SmartConsole on my case" was not in there "Authorized Clients"
Never seen that before...I dont think version of IC would matter here. Make sure that everything is checked under authentication settings.
Best,
Andy
Let me check my lab that works.
Andy
What version is this? Is the IP you have there correct?
Andy
200.100.0.1 is the virtual IP of the cluster.
version 81.10
Are you able to ping the firewalls from IC machine?
Andy
10.0.0.2 is the active node
10.0.0.3 is standby
PS C:\Users\shanta> ping 10.0.0.2
Pinging 10.0.0.2 with 32 bytes of data:
Reply from 10.0.0.2: bytes=32 time=1ms TTL=64
Reply from 10.0.0.2: bytes=32 time=1ms TTL=64
Reply from 10.0.0.2: bytes=32 time=16ms TTL=64
Reply from 10.0.0.2: bytes=32 time=1ms TTL=64
Ping statistics for 10.0.0.2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 16ms, Average = 4ms
PS C:\Users\shanta> ping 10.0.0.3
Pinging 10.0.0.3 with 32 bytes of data:
Reply from 10.0.0.3: bytes=32 time=2ms TTL=64
Reply from 10.0.0.3: bytes=32 time=1ms TTL=64
Reply from 10.0.0.3: bytes=32 time=1ms TTL=64
Reply from 10.0.0.3: bytes=32 time<1ms TTL=64
Ping statistics for 10.0.0.3:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 2ms, Average = 1ms
Is VIP 10.0.0.4? Try that IP instead and see if it works. I mean, try that for gateway object in IC.
Andy
10.0.0.1 tested that, same problem!
Try this...remove the query pool and see if you get same issue. If so, then I would uncheck IA blade, install policy, recheck and teest.
Andy
I did both and still "Wrong shared secret"
I am very confused, I am trying this on my lab only to see if i get same problem as my production, which is that all logs are "failed log in"
but my lab environment refuses!! "Wrong shared secret"
And you are 100% positive you are typing the same secret?
Best,
Andy
very easy password: vpn123
https://www.youtube.com/watch?v=-CLuxHTewqg
check that video on 2:55, you can see that he had the same problem but found a solution that is not shown on the video
Follow this sk
https://support.checkpoint.com/results/sk/sk113021
Maybe something simple like closed port between IDC and gateway
I got Windows firewall disabled for this test sake.
Would you explain: "
"
What is the "Authrized Clients object"?
So in that case, it was just new shared secret...not sure what else to say, sorry mate : - (. Lets see if Peter Elmer responds to your youtube video comment.
Best,
Andy
I have now found the problem from the text of sk113021
the machine where IDC is installed "SmartConsole on my case" was not in there "Authorized Clients"
Ah, gotcha...good job. I just assumed machine you had there was the one where IC was installed.
Glad you got it now.
Best,
Andy
This one is:
Do you see any traffic reaching on the fw? Should be HTTPS
The 'Wrong shared secret' error message is misleading in this case. It should be replaced with a message that clearly guides users on how to fix the issue.
I agree 100%, should be more user friendly, or intutitive, if you will.
Best,
Andy
please check this new post:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
11 | |
6 | |
6 | |
6 | |
6 | |
6 | |
4 | |
3 | |
3 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY