> Source: [sk117081](https://support.checkpoint.com/results/sk/sk117081)

# sk117081 - VPN creation fails with "Invalid Peer Certificate" error

| Property | Value |
|----------|-------|
| Solution ID | sk117081 |
| Date Created | 2017-05-08 |
| Last Modified | 2020-02-24 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * VPN Tunnel creation fails showing Error: `"Invalid Peer Certificate"` in SmartView Tracker Logs.
* Running VPN Debug (# vpn debug trunc) the following logs are shown in $FWDIR/log/vpnd.elg file:  
  `[vpnd xxxx]@Gateway-Hostname[xx Apr xx:xx:xx] fwCert_MatchAndSortCertsForVal: Peer certificate does not conform to matching criteria`  
  `
  [vpnd xxxx]@Gateway-Hostname[xx Apr xx:xx:xx] fwCert_ValPeerCertAndFindKey: Cannot construct a valid certificate chain from peer certificates`  
  `
  ...`  
  `
  received ipaddr: x.x.x.x as key, found fwobj: Gateway-Hostname`  

  Where x.x.x.x Matches the Peer IP, and Gateway-Hostname Does not match the Peer Hostname.

## Cause

The Management Database contains multiple objects with the Peer IP configured is shown either as the Primary IP address, or listed in the Topology Pane of the object.

When the VPN Daemon is matching the IP address seen to the VPN peer Object, it matches the Incorrect object, causing the connection to fail, as the Certificate is only for the specific Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
