> Source: [sk173883](https://support.checkpoint.com/results/sk/sk173883)

# sk173883 - VPN Process not using changed host entry to fetch CRL although Security Gateway is able to resolve address

| Property | Value |
|----------|-------|
| Solution ID | sk173883 |
| Date Created | 2021-06-14 |
| Last Modified | 2022-04-05 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * vpnd.elg shows: Snatcher: Failed to resolve host name. Snatcher: CleanUp started. Snatcher:CleanUpHttps Snatcher: put FU_UNEXPECTED from line 726. Snatcher: Calling Callback function... fwCRL_http_cb: status = 0 fwCRL_http_cb: status: 0 - Unknown status fwCRL_http_cb: can't get can't get CRL: status: 0 - Unknown status
* Manually changing the host entry in clish does not help to resolve an issue
* VPN Authentication fails with "Could not retrieve CRL"
* VPND fails to fetch CRL even if the Security Gateway is able to resolve the address.

## Cause

Incorrect host entry is added using clish. VPN process needs to be restarted after changing the host entry. The host entry is case sensitive to the CRL Domain.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
