sk180683 - Check Point Gateway is not sending the 3rd party certificate that uses OCSP it was set to send for site-2-site VPN or Remote Access VPN but instead send the defaultCert

Check Point Gateway is not sending the 3rd party certificate that uses OCSP it was set to send for site-2-site VPN or Remote Access VPN but instead send the defaultCert

Product: Endpoint Security - Remote Access VPN, IPSec VPN
Version: R80.40 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Platform: All
Last Modified: 2023-07-30

Symptoms

    [vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from Global Key Holder
    
    [vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from IKE Key Holder
    
    [vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from SSL Key Holder
    ```
- vpnd.elg or iked.elg will show one of these 3 lines:
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -949

[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -957

[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -958
```

Cause

The issue happens because after policy install Check Point is starting to check and validate its own 3rd party certs.

If there is a 3rd party cert the gateway is trying to validate but it fails for one of these 3 reasons:

    [OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -949.
    ```
- OCSP connect failed will be seen in vpnd.elg / iked.elg as
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -957
```
    [OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -958
    ```

Before the fix, the Check Point gateway would have removed that certificate from its database and will not try to use it again, which may lead to failures (as the unwanted certificate, usually the defaultCert will be sent instead while the peer expects the 3rd party certificate).

You will see the lines:
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from Global Key Holder

[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from IKE Key Holder

[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from SSL Key Holder
```

After the fix, the gateway will not remove those certificates but will attempt to validate them every 15 minutes.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.