> Source: [sk111751](https://support.checkpoint.com/results/sk/sk111751)

# sk111751 - Site to Site VPN between centrally managed gateway and SMB appliance fails with "Invalid Certificate"

| Property | Value |
|----------|-------|
| Solution ID | sk111751 |
| Date Created | 2016-05-31 |
| Last Modified | 2025-03-17 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| OS | Gaia |

## Symptoms

- * When trying to establish Site to site VPN between centrally managed gateway and a SMB appliance, using an internal certificate, you receive a Security log stating: "invalid certificate" error.
* IKE: Main Mode Sent Notification to Peer: invalid certificate
* Unable to fetch the policy on SMB appliance, it gives below warning.  
  Warning: "Attemped to fetch policy from an IP address that is different than the one used to fetch the certificate. Please check the management object's IP address in the SmartDashboard"

## Cause

**Environment:** All the appliances are managed by a centralized Security Management server. The Security Management server and all the appliances are configured with private IP addresses and then NATed.

VPN is negotiated with the External IP address of the Router, behind which the locally managed appliance is hidden (NATed).

**However, the certificate of the locally managed appliance is attached to its Internal non-routable IP address and therefore causes a conflict on the main gateway.**

This issue is observed when each gateway instance performs certificate revocation checking, in order to make sure that the certificate is still valid.

The Security Gateway (appliance) still fetches policy/logs to the real IP address of the Security Management Server instead of to the NAT address.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
