CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-14
Junior Member
 
Join Date: 2005-09-21
Posts: 11
Rep Power: 0
sambols has an average reputation (10+)
Default SmartConsole unable to connect to the SmartCenter server

I get the following error message when trying to connect to the SmartCenter server via the SmartConsole:

1) The SmartCenter Server's clock is not setup properly.
2) The certificate's issue date is later than the date of the SmartCenter Server's clock.
3) The GUI client's clock and the SmartCenter Server's clock are not synchronized.
4) The certificate has expired.
5) The certificateis invalid.

The firewall is R60 NGX.
Reply With Quote
  #2 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

That would probably mean that you have changed the date/time and the certificate creation date hasn't "arrived" yet, which means the certificate was created in the future and of course is not valid yet. Have you double checked all time and date settings?

Last edited by MarioL; 2008-05-15 at 03:12.
Reply With Quote
  #3 (permalink)  
Old 2008-05-14
Junior Member
 
Join Date: 2005-09-21
Posts: 11
Rep Power: 0
sambols has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

The time and date on the SmartCenter server and SmartConsole are the same. How do you check whether the certificate has expired?
Reply With Quote
  #4 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2007-07-16
Posts: 628
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

Have you changed the IP address of the SmartCenter server?
Reply With Quote
  #5 (permalink)  
Old 2008-05-15
Junior Member
 
Join Date: 2005-09-21
Posts: 11
Rep Power: 0
sambols has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

I haven't changed the IP address. I have verified that the GUI client address is specified.

I did run the following commands. This completed successfully.
cpca_client revoke_cert -n "cn=cp_mgmt"
cpca_client create_cert -n "cn=cp_mgmt" -f $CPDIR/conf/sic_cert.p12

I now get the following error message:

Connection cannot be initiated.
Please make sure that the server is up and running and you are defined as a GUI Client

help?
Reply With Quote
  #6 (permalink)  
Old 2008-05-16
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

Reboot Smart Center.
Is there latest HFA on the server.
Just try to connect Smart Update, that should work. There after you can check License.

Last edited by vijayant; 2008-05-16 at 21:23.
Reply With Quote
  #7 (permalink)  
Old 2008-05-18
Junior Member
 
Join Date: 2005-09-21
Posts: 11
Rep Power: 0
sambols has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

I have run the cpstop and cpstart command and also reboot.
I get the following error message:

Connection cannot be initiated.
Please make sure that the server is up and running and you are defined as a GUI Client

This is Check Point SecurePlatform Pro NGX (R60) Build 244

any ideas?
Reply With Quote
  #8 (permalink)  
Old 2008-05-18
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartConsole unable to connect to the SmartCenter server

From expert mode:

ps -ef | grep fwm

It that's not running the SmartCenter is broken

tcpdump host <ip of the GUI client>and not port 22

See if the traffic is making it.

cat $FWDIR/conf/gui_clients

Check for your IP address.
Reply With Quote
  #9 (permalink)  
Old 2008-05-19
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 113
Rep Power: 3
Yasushi Kono has an average reputation (10+)
Default Re: SmartConsole unable to connect to the SmartCenter server

Quote:
Originally Posted by sambols View Post
I have run the cpstop and cpstart command and also reboot.
I get the following error message:

Connection cannot be initiated.
Please make sure that the server is up and running and you are defined as a GUI Client

This is Check Point SecurePlatform Pro NGX (R60) Build 244

any ideas?
Are you sure that the Certificate Authority is running? cpconfig to re-run the internal CA.
Check the GUI client table with fw tab -t gui_clients_list. You will see the list with hex ip addresses. Should you alter the list with cpconfig, you need to re-install the latest policy in order to inform your gateway of the new list.

Kind regards,
Yasushi
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:44.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0