> Source: [sk177903](https://support.checkpoint.com/results/sk/sk177903)

# sk177903 - Certificate Security Alert shows when connecting with SNX to the Mobile Access Portal

| Property | Value |
|----------|-------|
| Solution ID | sk177903 |
| Date Created | 2022-02-23 |
| Last Modified | 2022-02-27 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Certificate Security Alert shows when connecting with SNX to the Mobile Access Portal after an import of a new 3rd-party SSL certificate for the Mobile Access Portal.

* Clicking "View Certificate" displays the default VPN certificate:

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk177903/Security_Alert202202111851451.png)
* On Internet Exploer \> Developer Tools (F12) \> Network, the last requested URL is: `https://mab_portal_fqdn/SNX/GetSnxBookmarks`.

* The SNX is connected when this alert occurs, and it is possible to access internal resources.

* Following the solution in [sk131212- Security gateway portals on port 443 receive incorrect certificate](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk131212) does not resolve the issue.

* VPND daemon debug (# vpn debug on TDERROR_ALL_ALL=5) shows that the client is trying to access the main address on port 443 and the default VPN Certificate is presented, for example:  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] getRenegParams: lookup for key : <10.10.10.172, 51998, 10.10.10.192, 443, 6>`  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] getRenegParams: Params not found`  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] storeRenegParams: storing key : <10.10.10.172, 51998, 10.10.10.192, 443, 6>`  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] storeRenegParams: added.`  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] cptls_handle_trap: done. msg=HS_NEW`  
  `
  [vpnd PID]@gw-81[DATE TIME][CPTLS] SRV_Create_certificate: using certificate with DN 'CN=vpngw VPN Certificate,O=CheckPointxxx..xxxxai'`

## Cause

The new imported SSL certificate is not distributed to all other portals automatically. The Security Gateway presents the default VPN Certificate, when the client requests other resources, such as the UserCheck Portal. The DNS server obtained by the client after SNX is connected, resolve the Mobile Access Portal FQDN to the Gateway's main IP address (private IP).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
