Checkpoint R80.10 site to site Mikrotik with Certificate

Hello All,

I have problem with certification and site to site connection with my device (Checkpoint <=> Mikrotik with dinamic ip addres).

  1. Do you only need to create one certificate, or I need make two (for server and client side). Ma checkpoint device have internal certificat?
  2. When I create certificat on mikrotik, I cant make certificat with flag I, In my case allways flag A. Is that a problem? (https://wiki.mikrotik.com/wiki/Manual:Create_Certificates)
  3. IPsec/Peers : When I create Peers in Exchange Mode I use “main” or “ike2”?
  4. IPsec/Peers : When I create Peers in Certificate I used certificat from mikrotik, in Remote Certificate I used certificate from Checkpoint? It is a correct?

Thanks a lot