> Source: [sk104739](https://support.checkpoint.com/results/sk/sk104739)

# sk104739 - IPSec VPN tunnel down with VPN Client message: "VPN-1 server can't find any certificate to use for IKE"

| Property | Value |
|----------|-------|
| Solution ID | sk104739 |
| Date Created | 2015-02-18 |
| Last Modified | 2023-01-03 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * VPN Site to Site and Remote Users report VPN down.

* SmartLog message: "`IKE: Main Mode I have no certificate to send`".

## Solution

Show the Entire Article

### Scenario 1 {#Scenario 1}

**Additional Symptoms:**

* VPN Client message: "`VPN-1 server can't find any certificate to use for IKE`"
* VPN debugs show:  
  `[PID][DATE TIME][] get_dpd_initiator_peers_hash: search for peer [IP Address]`  
  `[PID][DATE TIME][] get_dpd_initiator_peers_hash: peer [IP Address] doesn't appear in dpd_initiator_peers hash`  
  `[PID][DATE TIME][] fwCert_FindCertreqList: Entering`  
  `[PID][DATE TIME][] fwCert_FindCertreqList: Main Mode I have no certificate to use for IKE.`  
  `[PID][DATE TIME][] fwCert_FindCertreqList: no cert request has been prepared`  
  `[PID][DATE TIME][] MMCreate4: can't create cert request`  
  `[PID][DATE TIME][] GetDAGIP: ID 32ce2163 not in DAIP range`  
  `[PID][DATE TIME][CPLOG_BIN_OBJ] CBinObjCommon::PackLogData: Start`  
  `[PID][DATE TIME][CPLOG_BIN_OBJ] CBinObjCommon::PackLogData: Field number:1, Data offset:21, Type:int32 Number, Value:852369763`  
  `[PID][DATE TIME][CPLOG_BIN_OBJ] CBinObjCommon::PackLogData: Field number:2, Data offset:21, Type:int32 Number, Value:167904005`  
  `[PID][DATE TIME][CPLOG_BIN_OBJ] CBinObjCommon::PackLogData: Field number:2, Data offset:21, Type:eFtCstring, Value:`  
  `...`

Show / Hide solution  
**Cause:** The problem is with the Security Gateway proposal for the client.  
VPN certificate for the Security Gateway is no longer valid or has expired, or Client side does not support SHA256 and therefore IKE negotiation fails.

**Solution:**

Implement [sk59510](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk59510) and follow the procedures below.   
Proceed as follows:

1. In SmartConsole, open the Security Gateway object responsible for the tunnel.
2. Navigate to "IPSec VPN" tab.
3. Select the certificate in the repository.
4. Confirm the certificate has expired with the "View..." button.
5. Renew the certificate with the "Renew..." button.
6. Install Policy to the Security Gateway.

### Scenario 2 {#Scenario 2}

**Additional Symptoms:**

* Security Gateway hardware was replaced, or an upgraded was performed from pre-R80

Show / Hide solution  
**Cause:** There is at least one Trusted CA object configured in SmartConsole that does not contain a valid certificate.

**Solution:**

To resolve the problem, perform:

1. In SmartConsole, navigate to Servers \> Trusted CA
2. Edit each CA object, and view it's certificate. If the certificate can not be viewed due to some error message, then it is corrupted in some way.
3. In case the CA object is corrupted, either reimport the CA object's certificate or delete the CA object if it is no longer in use.

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
