View Single Post
  #1 (permalink)  
Old 2005-11-03
skperez skperez is offline
Junior Member
 
Join Date: 2005-11-03
Posts: 9
Rep Power: 0
skperez has an average reputation (10+)
Default SIC Reset issue on Solaris

When I try to run the Policy Editor for my checkpoint NG server it says “Connection cannot be initiated. Make sure …” I get the same message when I try to run the SmartDashBoard from a client. Everything was working before and I don’t think anything has changed but I can’t get to the firewall dashboard. I have been reading the FAQs and it says I need to reset my SIC. The FAQs are mainly based towards Windows and I am running Solaris 8. Can someone help me on how to reset the SIC?

I tried to work off of the windows way and here is what I have done.

% fwm sic_reset
***************** Warning: ****************
This operation will reset the Secure Internal Communication (SIC).
The internal Certificate Authority will be destroyed and Check Point Components will not be able to communicate.
You will have to perform the following operations to enable communication:
1. Re-initialize the internal Certificate Authority (use cpconfig).
2. Restart Check Point Services (cpstart, cpridstart).
3. Reset SIC on each Station that is managed by this SmartCenter Server.
4. Re-establish Trust with each Station that is managed by
this SmartCenter Server.
*******************************************
This operation will stop all Check Point Services (cpstop)
Are you sure you want to reset? (y/n) [n] ? y

*** Checking IKE Certificates ***
There are IKE Certificates that were generated by the
internal Certificate Authority.
Please remove them (using the Policy Editor) so that
the internal Certificate Authority can be destroyed.

SIC Reset operation could not be completed


It fails and it says to remove the IKE Certificates using the Policy Editor but I am back to the part where I cannot use the policy editor.

Anyone have any hints on how to remove the IKE certs without going through Policy Editor? Am I going at it the right way?
Reply With Quote