| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We had a consultant come in to work with us on upgrading some SPlat firewalls from R55 to R60. For some reason, my SmartCenter server is now running VPN-1 Pro along with SmartCenter. It took me a while to figure this out, but resulted in me being unable to receive logs from the legit firewalls (the SmartCenter server was dropping the packets since it was now a firewall). I did a "fw unloadlocal" on the SmartCenter server and the logs started showing up again in Tracker. I have been trying to figure out how to uninstall VPN-1 Pro from this mgmt server, but have been unsuccessful thus far. I have been going into "sysconfig" and selecting "10) Products Installation". From there I see the list of products, but I can't uncheck VPN-1 Pro. The consultant recommended rebuilding the mgmt server, but I just don't want to do that. Any help is appreciated. |
| |||
| These commands are not platform-specific; they will work on Windows or Unix-based systems, including IPSO. This example is done on a windows plaform with the default installation directory. A reboot will be necessary for this to take effect. If rebooting the Management Station is not possible, unloading the policy from the Management Station should resolve any immediate issues. Verify that the Management Station is configured as a FireWall Module: c:\>cpprod_util FwIsFireWallModule The output will be 1 or 0. If it is 1, then the Management Station believes itself to be a FireWall Module, as well. Unload the policy from the Management Station **very important to make sure you do this**: c:\>fw unloadlocal Run this command to set the Management Station not to be a module: c:\>cpprod_util FwSetFireWallModule 0 Verify the setting with the first command; the output should be 0. Reboot the Management Station at the earliest convenience. |
| |||
| Thanks for the instructions--they were very helpful! Any idea why a management server install requires VPN-1 to be installed as well? When I select the management server VPN-1 is autoselected, and if you deselect vpn-1 then management server is deselected.... |
![]() |
| Thread Tools | |
| Display Modes | |
| |