AnsweredAssumed Answered

R80.10 can't resolve CRL distribution point address

Question asked by Anton Kazantsev on Nov 18, 2017
Latest reply on Nov 22, 2017 by Dameon Welch Abernathy

I'm trying add external CA for authentication of remote clients. When I disable CRL checking all works fine. But when I enable this check the gateway send "can't retrieve crl" message to client. 

CRL distribution point address leads to internal net resource, which does not present in internal DNS. That's why it was added in hosts file from GAIA's management portal. 

In vpn debug present "Can't resolve address". But, when I reboot gateway it starts resolving CRL distribution address and it begin works  up to 10-15 minutes.

 

On R76 and R77.30 this setting works without any problems.

Any ideas?

Outcomes