sk183123 - The Security Gateway does not load the renewed IPSec VPN Certificate which causes VPN traffic interruption

The Security Gateway does not load the renewed IPSec VPN Certificate which causes VPN traffic interruption

Product

IPSec VPN

Version

R81.20

Last Modified

2025-07-21

Symptoms

\[vpnd 15619 4092663712\]@HOSTNAME[DATETIME][tunnel] proposalListFromIkeProps: transL->translst doesn't contain elements \[vpnd 15619 4092663712\]@HOSTNAME[DATETIME][tunnel] MMProcess1: ERROR: Cannot build a proposal for GW \[vpnd 15619 4092663712\]@HOSTNAME[DATETIME] GetCommunityByID: community ID [6] : COMMUNITY_NAME

vpnd.elg:

\[vpnd 15619 4092663712\]@HOSTNAME[DATETIME] X509 Certificate Version 3 refCount: 2 Serial Number: XXXXX Issuer: O=MGMT-NAME..quwm3t Subject: CN=GW-NMAE VPN Certificate,O=MGMT-NAME..quwm3t Not valid before: Mon Jun 27 09:36:33 2022 Local Time Not valid after:  Sun Jun 27 09:36:33 2027 Local Time

Certificate status:

\[Expert@MGMT-NAME:0\]# cpca_client lscert -ser XXXXX Operation succeeded. rc=0. 1 certs found. Subject = CN=GW-NMAE VPN Certificate,O=MGMT-NAME..quwm3t Status = Revoked   Kind = IKE   Serial = XXXXX   DP = 4 Not_Before: Sun Jun 26 21:36:33 2022   Not_After: Sat Jun 26 21:36:33 2027

Cause

The Security Gateway fails to automatically update its IPSec VPN certificate following renewal, continuing to use the expired certificate.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

The immediate workaround is available:

Run the following command to restart the VPND process on the Security Gateway which will update the IPSec VPN certificate immediately.

[Expert@HOSTNAME:0] # fw kill vpnd

If the above command does not show the updated VPN certificate, a reboot is required.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.