> Source: [sk172049](https://support.checkpoint.com/results/sk/sk172049)

# sk172049 - Centrally Managed SMB appliance fetches the CRL from a previous Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk172049 |
| Date Created | 2021-02-15 |
| Last Modified | 2021-02-22 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Symptoms

- * Site-to-Site VPN Tunnel from the Centrally Managed SMB appliances fails because of a Certificate issue in IKE packet 5 or 6.
* tcpdump on the SMB appliance shows that traffic to check the CRL is sent to the TCP port 18264 to the IP address of the previous Management Server that managed this SMB appliance in the past.
* Policy installation to the SMB appliance from the current Management Server is successful.
* SMB WebUI still shows the IP address of the previous Management Server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
