Hello,
Appreciate any assistance.
VSX R80.40 Take 154 VPN gateway with very old legacy SecureClients (R56) connecting (no office mode).
Everything was working fine until the SSL certificate under IPSec VPN section expired and had to be renewed. After renewal and policy installation, SecureClients failed to connect with "Phase1 Received Notification from Peer: invalid certificate" error message.
Recreating the profile and the site on the clients side didn't help. The error about invalid certificate disappeared, but the site couldn't be created -- no errors on the gateway side, and the client times out. We do get the thumbprint of the new certificate, there is 443/tcp and 500/udp traffic. The client is authenticated (we see successful Radius logs), so Phase 1 is fine. Then we see 264/tcp (FW1_topo) and I think this is where the clients fail, but no errors whatsoever. It looks like they timeout getting the topology, although nothing is blocked on the gateway side.
There were no changes in the configuration of the VPN settings -- only the certificate was renewed.
Thank you.