- For individual users
- Instant access to solutions
- Ask your tech questions
- Start your 30-day Free Trial
Main Topics
Browse All Topicshi , I have checkpoint firewall NG R54, when logging to smartdash board , it gives following error ,the connection has been refused due to one of the following smartCenter server certificate problem
1. The SmartCenter server's clock is not setup properly
2.The cerificates issue date is later then the date of smartCenter server clock.
3. The GUI clients clock and SmartCenter server clock are not syncronised.
4. Certificate has expired , 5) Cerificate is invalid
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: deimarkPosted on 2009-03-20 at 01:40:48ID: 23937673
FIrst of all, I would get rid of R54 bud, upgrade to R65, cos it is well out of date and out of support.
Secondly the issues you see are related to dodgy clock settings, out of date certificates and no new cert creations.
I would do the following:
1. Correct the time on the smartcentre and reboot
2. Make sure that all the times on any managed firewalls are also the same
3. Reset the ICA which will revoke all existing certs and allow you to create new certs.
4. Reset SIC on each firewall and then re establish SIC.
5. Push policy and test
Now, resetting the ICA is a HUGE deal and WILL affect ALL managed firewalls, ALL VPNs and any users that require a certificate for authentication.
Yes, I know its a big hammer, but you are running something that went out of support 2 years ago, and if but has been running for any length of time, a full reset would be good thing to do to clear out any old rubbish that has not been cleared out of the system.