| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hello, I'm performing an upgrade from R55 to R65 in a distributed environment. I just figured out that the VPN certificate of one of the clusters is expired since last January (I am an external in this company). However, VPN are established correctly, they only have an error message when compiling the policies. So my two little questions are : 1) does the upgrade of the SmartCenter from R55 to R65 will succeed with this certificate issue ? 2) Can I change the certificate without impacting the VPN clients ? (normally yes but I would like a confirmation) Thanks for your help guys, Laurent |
| |||
| Is it the CA cert (The one the SmartCenter) or the gateway's cert? If it's the gateway's just issue a new one. Clients will auth based on the CA cert being good. I would fix this before you try to upgrade anything. |
| |||
| This is actually the certificate of the gateway cluster. The internal CA certificate is still valid. I renewed it this morning but experienced a VPN problem (I know this may not be the right place to discuss this issue...) : no IKE negotiation possible anymore. After restoring the precedent config (with former invalid certificate) the problem persisted. The solution applied consisted in "widening" the Diffie Hellman groups and adding DH-1 and DH-5 to the default DH-2. It is important to note that those 2 added groups (DH-1 and DH5) were not activated before the certificate renewal. The logs showed errors with the following messages : - encryption fail reason: Packet is dropped because there is no valid SA - IKE: Main Mode no common authentication methods between myself and peer - encryption failure: Error occurred - IKE: Main Mode Failed to match proposal: 3DES, SHA1, Pre-shared secret, Group 2 (1024 bit) - encryption failure: Unknown SPI: 0x533871c7 for IPsec packet Does someone could help me with the following questions : - Why was it impossible to have any IKE negotiation after the certificate renewal ? - Why does the rollback (using Database Revision Control) did not work ? - Why does the DH-1 and DH-5 added group solved the problem ? |
![]() |
| Thread Tools | |
| Display Modes | |
| |