> Source: [sk178304](https://support.checkpoint.com/results/sk/sk178304)

# sk178304 - SmartConsole shows a warning or error icon near the Security Gateway / Cluster object about an expiring VPN certificate

| Property | Value |
|----------|-------|
| Solution ID | sk178304 |
| Date Created | 2022-03-09 |
| Last Modified | 2026-06-22 |
| Technical Level | General |
| Products | Security Gateway, SmartConsole |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |

## Symptoms

- * SmartConsole \> **Gateways \& Servers** view shows a warning or error icon near the Security Gateway / Cluster object about an expiring VPN certificate.

  Example of a warning:

  `Error: The VPN Certificate "CN=XXX VPN Certificate,O=XXX;" will expire on XXX. To renew it, follow sk178304`

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk178304/Untitled202211241802181.png)
* SmartConsole \> **Gateways \& Servers** view \> **Device Status** pane shows a warning or error icon for the Security Gateway / Cluster object about an expiring VPN certificate.

  Example of an error:

  `Error: The VPN Certificate "CN=XXX VPN Certificate,O=XXX;" expired on XXX. To renew it, follow sk178304`

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk178304/Untitled2202211241802442.png)

## Cause

This feature alerts the administrator about the expiration of the VPN IKE certificate this Security Gateway or Cluster uses:

**Best Practice** - Renew the certificate as soon as possible.

|-------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Status**  | **Description**                                                                                                                                                |
| **Warning** | The Management Server begins to show this status starting 60 days before the certificate expiration date. This status remains until it changes to "Error".     |
| **Error**   | The Management Server begins to show this status starting 14 days before the certificate expiration date. This status remains until you renew the certificate. |

**Notes:**

* After you renew the certificate, the status changes to "OK" (it takes a maximum of 5 minutes for SmartConsole to update the status).

* Security Gateways and Clusters use the VPN IKE certificate for:

  * VPN products.
  * Multi-Portals (Mobile Access Portal, Identity Awareness Captive Portal, User Check Portal, and so on).
  * Identity Collector
  * [Gaia Portal with enabled Multi-Portal feature.](https://support.checkpoint.com/results/sk/sk97648)

## Solution

Use one of the available options below.

### Option 1 - Use a shell script on the Management Server (recommended)

> Follow [sk182070 - How to renew IKE certificates for VPN, Multi-Portal, and Identity Broker on all managed Security Gateways](https://support.checkpoint.com/results/sk/sk182070) to renew the VPN certificate.

### Option 2 - Renew the IKE certificate in SmartConsole

1. Connect with SmartConsole to the Security Management Server / Domain Management Server that manages the Security Gateway / Cluster.

2. From the left navigation panel, click **Gateways \& Servers**.

3. Open the Security Gateway / Cluster object.

4. Make sure the **IPSec VPN** Software Blade is enabled:

   1. From the left tree, click the **General Properties** page.

   2. On the **Network Security** tab, select the checkbox **IPSec VPN** - even if you do not use it in this Security Gateway / Cluster (you disable it later).

5. From the left tree, click the **IPSec VPN** page.

6. Examine the current expiration date:

   1. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

   2. Click the "**View**" button.

   3. In the line "**Not Valid After**", examine the date.

   4. Click the "**OK**" button.

7. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

8. Click the "**Renew**" button.

9. Click the "**Yes**" button to confirm.

10. In the "**Generate Keys and Get Internal CA Certificate** " window, click "**OK**".

11. Click "**OK**" to close the Security Gateway / Cluster object.

12. Open the Security Gateway / Cluster object.
13. From the left tree, click the **IPSec VPN** pane.

14. Examine the current expiration date:

    1. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

    2. Click the "**View**" button.

    3. In the line "**Not Valid After**", examine the date.

    4. Click the "**OK**" button.

15. If you do **not** use the **IPSec VPN** Software Blade in this Security Gateway / Cluster, then disable it:

    1. From the left tree, click the **General Properties** page.

    2. On the **Network Security** tab, clear the checkbox **IPSec VPN**.

16. Click "**OK**" to close the Security Gateway / Cluster object.

17. Install the Access Control Policy on this Security Gateway / Cluster object.

18. Install the Access Control Policy on all other Security Gateway / Cluster objects that participate in a VPN community with this Security Gateway / Cluster object.

**Note** - It takes a maximum of 5 minutes for SmartConsole to update the status to "OK".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
