- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have configured Certificate based authentication but we are getting message on VPN client that "User Account Expired 31 Dec 2020"
When user connect from Client to VPN, it shows user Certificate but whne he connect, it give above error message.
We have already added Root CA in Trusted CA and issuing CA in Subordinate CA.
Generated CSR and got the Certificate from Internal CA
Selected Personal Certificate in Authetication in VPN Client as well in Mobile Access.
In Mobile access, Portal setting added another internal CA certification.
Is this field set properly for the user account in question?
Actually user which we are tring to connect is on AD not locally.. We have other users where there Account was expired on 31 dec 2020 which are on locally on checkpoint.
Below is the Message in Traffic logs
Main Mode Sent Notification to Peer: Client Encrypt Notification: User account expired on 31-Dec-2020.
User account expired on 31-Dec-2020. ---This data is picked up from the checkpoint only in the backend but not sure from where?
It might be in the generic* user that you need to change the expiration on.
The only way to find this user (if it's indeed defined in your environment) is via SmartDashboard (not SmartConsole).
Otherwise, I suggest contacting TAC.
Thanks, After changing the expiration on generic* user, message has gone but getting another message now on Endpoint security client that "Main Mode Sent Notification to Peer: Client Encrypt Notification: Access denied - wrong user name or password "
Even if you are using AD for authentication, some settings are inherit from default password templates. Check following:
LDAP Account Unit -> double click on correct AU -> Authentication -> Section "Users' default values". If "use user template" checkbox is ticked, then see which user template is used.
Search for this user template in "User Templates" within object explorer. Open affected template and right in General tab you can see Expiration of this template (which is valid for all users, not just locally configured).
If inside the user template you have "According to Global Properties", head to Global Properties -> User Accounts and there you should see Expiration.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY