thanks for the reply.

I had to destroy the ICA and recreate the ICA with a fwm sic_reset and
that seemed to fix it

Kind regards

Josh

>>> <[EMAIL PROTECTED]> 12/08/03 10:22pm >>>
Try deleting the VPN certificate on the gateway object, and then
recreate.
I saw this on a client that upgraded from NG to NG FP2.

-Aaron

-----Original Message-----
From: Josh Fry [mailto:[EMAIL PROTECTED]
Sent: Saturday, November 29, 2003 8:33 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] secureremote hybrid auth broken- VPN-1 server could not
find
certificate use IKE


Hello,

I have recently upgraded from CPNGFP2 to CPNGAI
and it has completely broken our secure remote VPN connections.

we use Hybrid mode - with no user certificates where by people's
credentials
are held in an LDAP server.

since upgrading no-one is able to authenticatea and establish a vpn
tunnel.
the error mesasge in the logs is.

IKE:Main Mode Sent Notification to Peer : Client Encrypt Notification:
[0018] VPN-1 server could not find any certifcate to use for IKE.

this was all working in feature pack 2 - so not sure why it is
suddenly
broken.

also have checked everywhere and don't have public keys defined as an
authentication method- so i am not sure why the secremote clients and
the fw
module are trying to use certificates.

has anyone else come across this problem ?

Kind regards

Josh

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to