> Source: [sk67420](https://support.checkpoint.com/results/sk/sk67420)

# sk67420 - "Peer does not have a certificate for SIC [error no. 111]" when clicking on 'Test SIC Status...' in Security Gateway object

| Property | Value |
|----------|-------|
| Solution ID | sk67420 |
| Date Created | 2012-03-13 |
| Last Modified | 2021-07-05 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.20, R82 |

## Symptoms

- *

  ```
  "SIC Status for Gateway_Object_Name: Not Communicating
  Peer does not have a certificate for SIC [error no. 111]
  ** Try to re-establish the trust **"
  ```

  error when clicking on '`Test SIC Status...`' in Security Gateway object.  

* Sending a ping packets with size of 1500 bytes and with enabled "Don't Fragment" flag from Security Management server to the problematic Security Gateway fails (100% loss).

## Cause

The transfer of the SIC certificate from Security Management server to the Security Gateway is performed with the MTU of the Security Management server interface facing the Security Gateway, generally 1500, and a "Don't Fragment" flag.

If an MTU on the path between the Security Management server and the Security Gateway is less than the MTU of the Security Management server's interface, the packets sent by the Security Management server will be discarded.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
