Hello Team,
What could be the impacts if, in the Gateway platform field, we select the wrong hardware type?
I’m asking this because I suspect that this might have been the cause of a VPN issue we faced last week.
Here are the details of the issue
-The customer has a fleet of 3600 appliances (in standalone mode) spread across 20 sites, all managed by a SmartCenter running R82.
- A VPN community has been set up with all the sites.
- 10 days ago, at one of the sites, for testing purposes, the customer replaced a 3600 with a 3900: they used the same hostname, reset the SIC, and kept the VPN certificate. However, the client forgot to change the "hardware type" (Information I received afterwards). After this operation, everything worked fine.
- 10 days later, at the site with the 3900, there was an Internet access issue. Once Internet access was restored, none of the VPNs were working at that site: Phase 1 established, but Phase 2 did not.
- A ticket was opened with CheckPoint support, debug logs were analyzed, but no conclusive data helped detect the root cause of the incident: we even had inconsistencies in the logs (for example, errors regarding the VPN community and the shared secret, even though it wasn’t being used).
- After half a day of investigation, we swapped back the 3600 appliance, but the problem remained the same.
- Since we had no leads on how to resolve the issue, support recommended several actions, including renewing the VPN certificate on the Gateway, even if the certificate wasn’t expired. This action ultimately resolved the issue.
Renewing the VPN certificate on the SmartCenter showed that the certificate was the root cause of the problem, regardless of the appliance used (3600 or 3900).
Therefore, after the issue was resolved, I am now trying to find any elements that could have caused the corruption of the certificate on the SmartCenter.
When CheckPoint support analyzed the debug logs, there were no specific logs indicating a certificate or CRL issue.
Thank for your help
Regards