> Source: [sk177049](https://support.checkpoint.com/results/sk/sk177049)

# sk177049 - VSX Gateway or Cluster with certificate-based VPN tunnel configured fails to retrieve CRL

| Property | Value |
|----------|-------|
| Solution ID | sk177049 |
| Date Created | 2021-12-28 |
| Last Modified | 2021-12-29 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * A Virtual System with a certificate-based VPN tunnel configured fails to retrieve the certificate revocation list (CRL).
* Output of the VPND debug shows:

  ```
  [vpnd 31673 4101883808]@vsx-GW[9 Feb 17:00:59][CRLCache] fwFetchCRL_cb: Entering for dp: http://crl.certificate.com/example.crl
  [vpnd 31673 4101883808]@vsx-GW[9 Feb 17:00:59][CRLCache] fwFetchCRL_cb: Fetch failed, try to find in FDB
  [vpnd 31673 4101883808]@vsx-GW[9 Feb 17:00:59][CRLCache] fwFetchCRL_cb: not found in FDB
  [vpnd 31673 4101883808]@vsx-GW[9 Feb 17:00:59][CRLCache] fwFetchCRL_cb: Fetch failed
  [vpnd 31673 4101883808]@vsx-GW[9 Feb 17:00:59][CRLCache] fwCRL_Hook_cb: Fetch Failed (error -986), and this was the last fetch. This fetch will be processed.
  ```

* After users add the DNS entry for the CA server in the */etc/hosts* file and enter the command `# curl_cli -v `, the Virtual System can resolve the the DNS name of the CA server.
* After users configure the Virtual System to resolve the DNS name of the CA server, the Virtual System cannot contact the CRL and shows the same error messages in VPN debugs.

## Cause

The Virtual System that tries to establish a VPN tunnel is not connected to the DNS server. Connecting to the DNS server from *vs0*is not sufficient.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
