FAQs


What is Check Point VPN Appliance and How to generate CSR and install a certificate using it?
What is Check Point VPN Appliance and How to generate CSR and install a certificate using it?
Overview
This article outlines the step-by-step process to:
- Generate a Certificate Signing Request (CSR) for VPN
- Add an Intermediate CA to Check Point Smart Dashboard
- Install the signed certificate
- Enable VPN client login using the SSL certificate
Part 1: Creating the CSR (Certificate Signing Request)
- In Smart Dashboard, open the Device Properties for your VPN gateway.
- Navigate to IPSec VPN > Click Add under certificates.
- In the Certificate Properties window:
- Certificate Nickname: e.g., VPN.exampledomain.com
- CA to Enroll From: Select the Intermediate CA you just added.
- Click Generate.
- A prompt will ask to generate the certificate — select Yes.
- In the Generate Certificate Request dialog:
- Fill in the Distinguished Name (DN) as:
CN=Domain Name, OU=Department, O=Organization, L=Locality ,ST=State, C=Country
- Optional: Click Define Alternate Names to specify SANs (Subject Alternative Names), if applicable.
- Click OK.
Part 2: Adding the Intermediate Certificate
- Right-click Trusted CAs again > New CA > Subordinate.
- In the Certificate Authority Properties window:
- Under the General tab, enter a name (e.g., Sectigo_Intermediate).
- Under the OPSEC PKI tab:
- Click Get and select the IntermediateCA.crt file provided by the CA.
- Click OK to complete the import.
Part 3: Retrieving the CSR
- After generation, click View to open the Certificate Request View.
- Click Copy to Clipboard to copy the CSR.
- Also click Save to File to save the CSR locally.
- Use any text editor to open the .csr file and copy the entire content, including:
-----BEGIN CERTIFICATE REQUEST-----
... (CSR content) ...
-----END CERTIFICATE REQUEST-----
- Paste this content into the Sectigo portal.
- Once the validation is completed. Certificate will be issued.
Part 4: Installing the Signed Certificate
Once you receive your signed SSL certificate (example_domain_com.cert) from the CA:
- Open the VPN Gateway’s Device Properties in Smart Dashboard.
- Go to IPSec VPN > Click Complete next to your certificate.
- Upload the .crt file received from the CA.
- Click OK to finish the installation.
Part 5: Enabling VPN Client Login (Optional)
To allow users to connect via SSL Network Extender (SNX):
- In IPSec VPN settings, check VPN Client Login.
- Under SSL Network Extender, choose the installed certificate via Select by Nickname.
- Click OK.
Part 6: Install Policy
To apply the changes:
- Click Install Policy in SmartDashboard.
- Define your Installation Targets (e.g., Gateway, Cluster Members).
- Click Install to push the new certificate and configuration.
Points to Note:
- Ensure the CN or SAN matches the domain users will connect to.
- If the CA sends the certificate in .p7b format, convert it to .pem or .cer using tools like OpenSSL.
- Always back up the private key and CSR before submitting.
RELATED ARTICLES:
TAGS:
Need help?
Need help making a purchase? Contact us today to get your certificate issued right away.
Live chat
Click the button below or click "Chat with an Expert" to start chatting with us now!