View Single Post
  #1 (permalink)  
Old 2007-09-10
Packet Packet is offline
Junior Member
 
Join Date: 2007-08-31
Posts: 3
Rep Power: 0
Packet has an average reputation (10+)
Default Resetting SIC on reboot (with Mgmt server as Vmware guest) NGX R65

This is a scenario I'm playing with and I got it working mostly.

Scenario: NGX R65 as enforcement only module with DAIP on Windows 2003 SP2.
Mgmt server NGX R65 on Windows 2003 SP2 running in a Vmware session on same machine.
Everything (except VPN) works just fine - hide nat for the mgmt server to get windows updates as needed and for another internal network to get out as hide nat, etc. so the connectivity between the mgmt server and the enforcement module is all good.

however, i've noticed that on rebooting the physical machine (and a clean/normal shutdown and reboot of the vmware session as well), SIC stays established - shows 'SIC established' but on testing SIC status, i get an unable to resolve object ip. (cant recall exact error, but basically it cant resolve the ip of the module)
so, cant push a new policy at that moment either because it cant resolve the object.
cpstop/cpstart on both vmware mgmt server and DAIP enforcement module doesnt do anything.
From trial and error, i found out that if i reset SIC status between the two and specify the current ip obtained via DHCP (on the DAIP), SIC status is good and it stays fine, can push policies, et all.
Until the next reboot...

Is there a simpler way to do this rather than having to reset SIC status each reboot?
Reply With Quote