> Source: [sk33296](https://support.checkpoint.com/results/sk/sk33296)

# sk33296 - "Main Mode could not retrieve CRL" error in SmartLog

| Property | Value |
|----------|-------|
| Solution ID | sk33296 |
| Date Created | 2007-07-18 |
| Last Modified | 2026-09-02 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |

## Symptoms

- * "`Main mode could not retrieve CRL.CN...`" error in SmartLog.  

* "`Main Mode could not retrieve CRL`" message in $FWDIR/log/ike.elg after trying to establish a VPN connection.  

* The Security Gateway fails to retrieve the CRL / send the CRL to the client in Main mode.
* vpnd.elg may show: CCplogUtils::FillVarArg: str: Main Mode Could not retrieve CRL.CN and: \[tunnel\] isakmpd_log: calling isakmpd_log with original reason=(Could not retrieve CRL.CN....)

## Cause

IKE payloads are limited to 64000 bytes, even though IP fragmentation or IKE over TCP is allowed. Consequently, there can be a problem transmitting CRLs that are too long.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
