- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Migrate VPN Certificate
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Migrate VPN Certificate
I have a question.
My customer is currently using a virtual GW as VPN GW, the VPN users have to authenticate themselves with a certificate.
The customer wants to replace his GW with a new one (new release), is it possible to migrate the certificate from the old GW to the the new one?
Thank you
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why not update the existing GW to the new release ? This would keep everything...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Because he want to restart from scratch with a new one
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not possible without TAC afaik.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In general, there is no way to export the private key of a gateway and import it to another.
If they use the same Certificate Authority (ie are managed by the same management), then this shouldn’t create an issue since it’s ultimately the CA that validates a certificate is valid.
Other than possibly a fingerprint message when the user connects to the new gateway for the first time, there shouldn’t be any issues authenticating.
More details about your current and proposed configuration (current version, target version, how is the gateway managed from what versions, etc) would help clarify our answers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Phone Boy,
We have 2 GWs, a 3800 (R80.40) and an 1800 (R80.20.50).
According to your comment, can I use the same certificate to connect to different GW's VPN if they use the same MGMT (Same CA)?
I have tried, but in the logs (after vpn debug ikeon), I see the below in the smart logs:
It's strange, it can see the correct DN, but shows "user DN unknown" and for the key install it shows "invalid certificate".
Any ideas please?
I also tried to create a new client certificate and enroll that one to the other GW, but still fails. (i.e. one client certificate per gw per user)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Suggest involving the TAC to troubleshoot this: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please also note that R80.20.x will be EOL in Oct-23, please refer:
https://www.checkpoint.com/support-services/support-life-cycle-policy/#embedded-security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
