Solved

default cert expires in 2 days on CheckPoint NG AI R 55 Firewall   ! PLEASE Help !

Posted on 2008-10-02
10
1,631 Views
Last Modified: 2013-11-16
Hi,
our firewall's ( Checkpoint NG AI R 55 ) default cert created while installing the firewall is going to expire in 2 days
the firewall is supporting 50 user network and 2 vpn tunnels ( site to site )
once the cert expires does the firewall stops working ?
does the vpn tunnels break ?
how do we recreate the cert with hurting the firewall ? we just have only one firewall and now this situation is scary !
Please help !!!!
0
Comment
Question by:dejones44
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 3
10 Comments
 

Author Comment

by:dejones44
ID: 22630611
Please help !!
0
 
LVL 14

Expert Comment

by:grimkin
ID: 22631844
If the certificate expires then your VPNs will certainly break but your firewalls should still pass normal traffic.

The following should renew your certificate without having to re-establish SIC:

cpca_client revoke_cert -n "CN=cp_mgmt"
cpca_client create_cert -n "CN=cp_mgmt" -f /opt/CPshrd-R55/conf/sic_cert.p12
cpstop
cpstart

(It's always good to back everything up before carrying out anything critical!)
0
 

Author Comment

by:dejones44
ID: 22637485
Thanks
does the same command hold good for a windows 2003 server ? sorry i am newbie.
also can you please let me know how do i backup the firewall before I run these commands.
Thanks again
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:dejones44
ID: 22637498
sorry
does the site to site vpn will also break ?
0
 

Author Comment

by:dejones44
ID: 22637650
sorry once again
is it okay to do this from the gui tool ?
if i go to firewall object property sheet and then click on vpn , it shows me the vpn domains as well as the current certificate .
i have options to add , edit , remove the certificate .
Please advise !
0
 
LVL 14

Accepted Solution

by:
grimkin earned 500 total points
ID: 22638285
Ok:

The same commands will work for a windows server but you need to modify the path to your p12 certificate file, should be something like the following (but please check by doing a search for sic_cert.p12):

cpca_client revoke_cert -n "CN=cp_mgmt"
cpca_client create_cert -n "CN=cp_mgmt" -f C:\Program Files\CheckPoint\CPShared\R55\conf\sic_cert.p12
cpstop
cpstart

The options in your GUI tool are to do with the VPN cert but I'm assuming the one which is expiring is your internal CA certificate upon which your VPN cert is based.  The commands above should renew your current certificate meaning that there will be no disruption to the VPNs.
0
 

Author Comment

by:dejones44
ID: 22652635
Apologies again for being a pain on this. sorry i am newbie.

InternalCA.p12 is located at F:\FW1\R55\conf
In the vpn properties sheet I see the following details. this one is expiring and have to run this command now.
Under certificate lists
Nickname : defaultCert
Certificate Authority : Internal_ca
Status   :  Signed  
Location : management_server
the internal_CA is installed on the management server (management server is also installed on the same box)
looks like I need to renew this cert but please advise.
the following command i plan to run please correct .thanks
cpca_client revoke_cert -n "CN=cp_mgmt"
cpca_client create_cert -n "CN=cp_mgmt" -f F:\FW\\R55\conf\internal_CA.p12
cpstop
cpstart
Any tips on backup of firewall before I run the commands ?
PS : sic_cert.p12 is located at C:\Program Files\CheckPoint\CPShared\R55\conf
0
 

Author Comment

by:dejones44
ID: 22653170
Please help
0
 
LVL 14

Expert Comment

by:grimkin
ID: 22657358
cpca_client revoke_cert -n "CN=cp_mgmt"
cpca_client create_cert -n "CN=cp_mgmt" -f C:\Program Files\CheckPoint\CPShared\R55\conf\sic_cert.p12
cpstop
cpstart

To backup your management server you can back up your windows box. To backup just the Checkpoint config, you can search for the upgrade_export.exe, get a command prompt in that directory and issue the command: "upgrade_export my_export" which will create the file my_export.tgz - move this off the server to a safe place.
0
 

Author Comment

by:dejones44
ID: 22664470
I did the follow steps

1. removed the vpn domains from the vpn community in the vpn property page.

2. removed the defaultCert from the certificates list.

3. Added the new defaultCert and clicked on the generate button .

it created the new cert which is good for next 5 years.


after that i pinged the servers in the site to site tunnel and got a reply.

from home network also the users were able to connect to the vpn server.

i still  not restarted the services or the server.

i thank you for the help offered and in future if sic_cert needs to be reinitialized i follow the steps from you
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AWS VPS as AD Server 2 87
ASA 5505 latency problem 8 64
Resource timeout across a VPN 9 31
auto connect vpn 17 59
When you connect to your workplace's VPN, you may not notice that you are using your workplace's servers to serve up webpages.  This might be undesirable since the workplace can log all the places you've been.  It also might be very slow to load pag…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question