- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a question.
My customer is currently using a virtual GW as VPN GW, the VPN users have to authenticate themselves with a certificate.
The customer wants to replace his GW with a new one (new release), is it possible to migrate the certificate from the old GW to the the new one?
Thank you
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
Why not update the existing GW to the new release ? This would keep everything...
Because he want to restart from scratch with a new one
Not possible without TAC afaik.
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
Hi Phone Boy,
We have 2 GWs, a 3800 (R80.40) and an 1800 (R80.20.50).
According to your comment, can I use the same certificate to connect to different GW's VPN if they use the same MGMT (Same CA)?
I have tried, but in the logs (after vpn debug ikeon), I see the below in the smart logs:
It's strange, it can see the correct DN, but shows "user DN unknown" and for the key install it shows "invalid certificate".
Any ideas please?
I also tried to create a new client certificate and enroll that one to the other GW, but still fails. (i.e. one client certificate per gw per user)
Suggest involving the TAC to troubleshoot this: https://help.checkpoint.com
Please also note that R80.20.x will be EOL in Oct-23, please refer:
https://www.checkpoint.com/support-services/support-life-cycle-policy/#embedded-security
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY