> Source: [sk100731](https://support.checkpoint.com/results/sk/sk100731)

# sk100731 - VPNs go down within 24 hours after primary Security Management server goes down 

| Property | Value |
|----------|-------|
| Solution ID | sk100731 |
| Date Created | 2014-05-19 |
| Last Modified | 2023-02-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * VPNs go down within 24 hours after the primary Security Management server goes down and Secondary Management server becomes active.
* Reject log with error "`Main Mode Could not retrieve CRL`"

## Cause

The Security Gateway cannot get CRL (certificate revocation list). By default gateway caches CRL for 24 hours. After that a new CRL needs to be fetched from the Security Management server.

CRL fetch flow is as follows:

1. Gateway checks for the CRL cache. If CRL is found from cache its used.
2. If CRL is not in cache, gateway tries to fetch it from all the Management servers listed in *$FWDIR/conf/masters*.

There is no consideration of who is primary or secondary in*$FWDIR/conf/masters* file. Gateway tries to fetch the CRL from the first Security Management server that responds. By default only the IP address of the primary Security Management server is written in that file.

CRL fetching fails because the gateway tries to fetch CRL from the primary Security Management server that is down.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
