Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
flachance
Advisor

site-to-site VPN goes down after installing a 3rd party cert on one of the gateway

Hi,

We have two sites connected via a site-to-site vpn.

Site A has a cluster of two R81.20 open servers, Site B has a cluster of two cloudguard gateways in Azure also R81.10.

Management server is at Site A also R81.20.

Clients are connecting to Site A for Remote access VPN using personal certificate for authentication.

 

We wanted to investigate the possibility of using machine certificate authentication for client’s remote access.

 

From the Remote Access VPN Admin guide, Machine Certificate section (Machine Certificate (checkpoint.com) ), we followed the link to sk149253 on adding the root CA on the LDAP Server to the Trusted CA in Management. We successfully generated a certificate request for our internal CA server, generated a certificate and installed it on our gateway. So on Site A’s gateway we had two certs, the one from a 3rd party (our own internal CA) that we just generated and the Checkpoint internal one.

 

After installing the policy on site A cluster, everything worked well. But after installing the policy on Site B, the site-to-site VPN went down. Only after we removed the new certificate from the Site A cluster and install policy on both sites did it came back.

 

Maybe the site-to-site vpn was trying with the wrong cert? Is there a place or setting for the site-to-site to specify which cert it should use?

 

thanks

0 Kudos
3 Replies
the_rock
Legend
Legend

This is CP to CP tunnel? Either way, only thing I see in community would setting on interoperable object itself for matching criteria...

Screenshot_1.png

0 Kudos
flachance
Advisor

Yes it's CP to CP. That screenshot is from your gateway properties?

I don't see the same thing. No matching criteria option. 

 

Capture.JPG

0 Kudos
the_rock
Legend
Legend

Ok, so you wont see it then, it only shows it on interoperable object.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events