CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 3 Weeks Ago
shad007 shad007 is offline
Junior Member
 
Join Date: 2008-04-21
Posts: 6
shad007 has an average reputation (10+)
Default SecureRemote IKE issue

Hi all, first time poster =) (please forgive me if this is in the wrong forum but I thought Authentication was as good a place as any..)

Scenario.
I have just finished migrating from a Windows server based NG55 system to a Crossbeam C6 based NGXR62 system. The transition went relatively smooth considering the size of our site, however in the process it seems that I managed to break Remote access.

Problem.
When Clients connect via SecureRemote client using Username/Password authentication it fails with the following IKE msg:

"Negotiation with gateway xx.xx.xx.xx at site xx.xx.xx.xx has failed. VPN-1 Server could not find any certificate to use for IKE.

An interesting thing is that when I attempt to view the defaultCert under the Checkpoint Gateway VPN tab it comes up with an error: "Failed to read certificate from database"

Does this mean that I have a corrupted cert? I understand if this is the case that I may be able to simply remove it and it would recreate? need more info as if i remove it it will potentially break at least a dozen client IPSEC vpn's
Reply With Quote
  #2 (permalink)  
Old 3 Weeks Ago
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 279
Thorpuse has an average reputation (10+)
Default Re: SecureRemote IKE issue

Did you change the IP address or hostname of the SmartCenter post-install? Sounds like your Root CA is invalid.

How did you perform the migration? If you were using the upgrade export/import tools, did the SmartCenter Server IP change for the new system?
Reply With Quote
  #3 (permalink)  
Old 2 Weeks Ago
shad007 shad007 is offline
Junior Member
 
Join Date: 2008-04-21
Posts: 6
shad007 has an average reputation (10+)
Default Re: SecureRemote IKE issue

Quote:
Originally Posted by Thorpuse View Post
Did you change the IP address or hostname of the SmartCenter post-install? Sounds like your Root CA is invalid.

How did you perform the migration? If you were using the upgrade export/import tools, did the SmartCenter Server IP change for the new system?
I didnt originally use the export tool (primarily due to the fact I wasnt aware of it's existence). Is there some way to use the tool on the old firewall to extract the correct Root CA? or am i going down the wrong path? The IP of the Smartcenter did change post-install from memory.

Also i've found some more possibly helpful info:
When viewing the Certificates list inside the checkpoint software it says that the CA is the defaultCert 'internal_ca' yet when running a cpconfig from the linux root it and selecting option 8 from the menu (Certificate Authority) it lists a different certificate? It looks to me like the linux box has the right certificate, however the checkpoint software running on the management box has the wrong one? =/

"be gentle" :)
Reply With Quote
  #4 (permalink)  
Old 2 Weeks Ago
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 324
MarioL has an average reputation (10+)
Default Re: SecureRemote IKE issue

If you created a new config from scratch you might need to either:
- Update the site on SR (don't think will work)
- Delete and re-create the site on SR

Make sure your firewall object has VPN ticked and has a certificate created under the VPN tab. (well there is more to check, but this is a start)
Reply With Quote
  #5 (permalink)  
Old 2 Weeks Ago
shad007 shad007 is offline
Junior Member
 
Join Date: 2008-04-21
Posts: 6
shad007 has an average reputation (10+)
Default Re: SecureRemote IKE issue

Quote:
Originally Posted by MarioL View Post
If you created a new config from scratch you might need to either:
- Update the site on SR (don't think will work)
- Delete and re-create the site on SR

Make sure your firewall object has VPN ticked and has a certificate created under the VPN tab. (well there is more to check, but this is a start)
When you say update the site on SR are you referring to the SecureRemote client side? if so, that's been done. The firewall does have VPN ticked, and there is a certificate under the VPN tab, however it cannot read this certificate "Failed to read certificate from database".
Reply With Quote
  #6 (permalink)  
Old 2 Weeks Ago
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 324
MarioL has an average reputation (10+)
Default Re: SecureRemote IKE issue

Sounds like you have SIC problems, try removing that cert and creating a new one. After this re-create the sites on the remote users.
Reply With Quote
  #7 (permalink)  
Old 2 Weeks Ago
shad007 shad007 is offline
Junior Member
 
Join Date: 2008-04-21
Posts: 6
shad007 has an average reputation (10+)
Default Re: SecureRemote IKE issue

Quote:
Originally Posted by MarioL View Post
Sounds like you have SIC problems, try removing that cert and creating a new one. After this re-create the sites on the remote users.
Thanks. I managed to fix it by removing the firewall object from all 7 of our IPSEC tunnels, renewing the cert (had to change it's name) then reinserting the firewall object back into the VPN sites.
Reply With Quote
  #8 (permalink)  
Old 2 Weeks Ago
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 324
MarioL has an average reputation (10+)
Default Re: SecureRemote IKE issue

Cool, glad it's sorted ;)
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:46.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0