> Source: [sk179434](https://support.checkpoint.com/results/sk/sk179434)

# sk179434 - After installing specific Takes of the Jumbo Hotfix Accumulators for R80.40 / R81 / R81.10 / R81.20 on a Security Gateway, Certificate Validation for Site to Site VPN and Remote Access VPN stopped working

| Property | Value |
|----------|-------|
| Solution ID | sk179434 |
| Date Created | 2022-06-02 |
| Last Modified | 2026-04-27 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * After installing specific Takes of Jumbo Hotfix Accumulators for R80.40 / R81 / R81.10 / R81.20 on a Security Gateway / Cluster, Certificate Validation for Site to Site VPN and Remote Access VPN stopped working.

* Turning off CRL Checking from the trusted CA object resolves the issue.

* SmartConsole logs may show failed login attempts with this description:

  ```
  
  OCSP: could not connect to server. 
  Make sure the server is up and running.CN=example.test.com
  ```

* This issue is observed in Site to Site VPN, Mobile Access Portal, Endpoint Security VPN, Capsule VPN, Capsule Connect, Capsule Workspace.

## Cause

Starting with these Jumbo Hotfix Accumulator Takes (fix PRHF-24483), the Security Gateway uses OCSP as the default revocation validation method:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 8
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 38
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm "Jumbo Hotfix Accumulator for R81") starting from Take 60
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 158

If the Security Gateway cannot communicate with the OCSP server (cannot reach it, the server does not respond, OCSP is disabled on the server, and so on), then the certificate-based connection to the Security Gateway fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
