Firewall-1

[FW-1] secureremote hybrid auth broken- VPN-1 server could not find cert

Subject: [FW-1] secureremote hybrid auth broken- VPN-1 server could not find certificate use IKE
From: Josh Fry <jfry AT SERCO DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Sat, 29 Nov 2003 15:32:51 +0000
Hello,

I have recently upgraded from CPNGFP2 to CPNGAI
and it has completely broken our secure remote VPN connections.

we use Hybrid mode - with no user certificates where by people's
credentials are held in an LDAP server.

since upgrading no-one is able to authenticatea and establish a vpn
tunnel.
the error mesasge in the logs is.

IKE:Main Mode Sent Notification to Peer : Client Encrypt Notification:
[0018] VPN-1 server could not find any certifcate to use for IKE.

this was all working in feature pack 2 - so not sure why it is suddenly
broken.

also have checked everywhere and don't have public keys defined as an
authentication method- so i am not sure why the secremote clients and
the fw module are trying to use certificates.

has anyone else come across this problem ?

Kind regards

Josh

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] secureremote hybrid auth broken- VPN-1 server could not find certificate use IKE, Josh Fry <=