CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-23
Junior Member
 
Join Date: 2005-12-08
Posts: 19
Rep Power: 0
jemma_noor has an average reputation (10+)
Default VPN and Interna_ca

Hello CPUG users,

I have inherited Checkpoint Nokia IPSO 330 (ng fp3) environment, and am now trying configure Securemote vpn.

In the properties of our firewall object (>smartdashboard >Checkpoint objects >Firewall Properties >VPN tab >Certificate List) under certificates box, there is a default interna_ca certificate without any DN description. I'm assuming my predecessor created this by mistake and I would now like remove it in order to configure a vpn.

When I try removing it via the Checkpoint Properties window (remove button beneath the certs list table), I receive an error message of "unable to delete ca cert, please contact your support dept."

I have also tried reseting the CA through CPconfig although it resets ca, it fails to remove the default Interna_ca cert.

Are there any other way's of removing the internal_ca without having to rebuild the entire firewall?

Thank you for any suggestions.

Regads,
Jemma
X

ps, we don't have support with checkpoint.
Reply With Quote
  #2 (permalink)  
Old 2006-02-26
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VPN and Interna_ca

The internal cert cannot just be removed. You can unckeck "VPN" from the products list of the gateway and click "OK" that will remove the cert and it will regenerate when you check VPN again.
Reply With Quote
  #3 (permalink)  
Old 2006-03-08
Junior Member
 
Join Date: 2005-09-13
Posts: 5
Rep Power: 0
DJ_SL has an average reputation (10+)
Default Re: VPN and Interna_ca

Quote:
Originally Posted by chillyjim
The internal cert cannot just be removed. You can unckeck "VPN" from the products list of the gateway and click "OK" that will remove the cert and it will regenerate when you check VPN again.
Many thanks this sorted my issue (IKE: phase 1, cert unavailable etc...).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:33.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0