> Source: [sk164881](https://support.checkpoint.com/results/sk/sk164881)

# sk164881 - Site to Site VPN tunnel failed to established on Phase1 (Main Mode) when using 3rd party CA

| Property | Value |
|----------|-------|
| Solution ID | sk164881 |
| Date Created | 2020-01-31 |
| Last Modified | 2020-02-04 |
| Technical Level | Advanced |

## Symptoms

- * Site to Site VPN tunnel failed to established on Phase1 (Main Mode) when using 3rd party CA.
* From *ike.elg*: INVALID CERTIFICATE
* From *vpnd* :  
  \[vpnd 10745 4083768064\]@GWA1\[26 Jan 18:59:07\]\[tunnel\] fwCert_AddCAToCertsAndGetCAObj: Expected to get certificate whose root CA is internal_ca, got certificate whose root CA is "3rd party CA"  
  \[vpnd 10745 4083768064\]@GWA1\[26 Jan 18:59:07\]\[tunnel\] \< FWIKE_MM_PACKET_6_EPILOGUE1 \> Id = 7  
  \[vpnd 10745 4083768064\]@GWA1\[26 Jan 18:59:07\] GetCommunityByID: community ID \[1\] : PSK-VPN  
  \[vpnd 10745 4083768064\]@GWA1\[26 Jan 18:59:07\]\[tunnel\] extended_log_info_build_reason_from_list: list is empty, \[vpnd 10745 4083768064\]@GWA1\[26 Jan 18:59:07\]\[tunnel\] isakmpd_log: calling isakmpd_log with original reason=(Expected to get certificate whose root CA is internal_ca, got certificate whose root CA is "3rd party CA")

## Cause

Invalid Certificate.

Incorrect configuration. Expected to receive certificate from a different CA.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
