CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-03
Junior Member
 
Join Date: 2007-11-17
Posts: 14
Rep Power: 0
d31jan has an average reputation (10+)
Default SIC communication fail

DEAR ,

I am using r60 cluster firewall , SIc communication fail often ,

what wiil the root cause of SIC ,


SIC test also fail , get error CPD NOT running TCP connectivity is fail from SmartCenter server to IP "X.X.X.X, Port 18191

Regards
d31jan
Reply With Quote
  #2 (permalink)  
Old 2008-06-04
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: SIC communication fail

hi is ur smart server center behind a nat environment or is ur smart server behind a firewall before it can reach the cluster object.

i had the same problem with when my smart server was behind a another checkpoint firewall. i had to do static nat and select for vpn-1 control connections only.

tell us more abt ur topology we will be able to help u out better.

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-06-09
Junior Member
 
Join Date: 2007-11-17
Posts: 14
Rep Power: 0
d31jan has an average reputation (10+)
Default Re: SIC communication fail

Dear ,

I am using

1) Enforcement Module 1 (Primary) : Secure Platform NGX R60 Build 269

(2) Enforcement Module 2 (Secondary) : Secure Platform NGX R60 Build 269
(3) Management Server (Windows 2003 Sever ): NGX R60_HFA_02

NO

my smart server is not behind a firewall before it can reach the cluster object.

1 To aceess management server from lan one rule is create.


Problem detail:

There is temporary disconnection between Enforcement module's and Management server during this period we are not able to ping or reach on open ports from enforcement module to Management & vice versa. However there is no communication problem during this period except the subject matter.

Towards the resolution of the problem we have even changed the switch port of the Management server but the problem persist. The problem gets resolved automatically after some time and it start to function smoothly


Observation:

During the issue if we unload the policy on the enforcement module we are able to ping the Enforcement Module from Management and vice versa.



Regards
D31jan
Reply With Quote
  #4 (permalink)  
Old 2008-08-03
Member
 
Join Date: 2007-07-27
Posts: 89
Rep Power: 2
desperado618 has an average reputation (10+)
Default Re: SIC communication fail

I had the same problem recently immediately after an upgrade. I upgraded the Secondary member of a cluster first. I wanted th ensure that it was working correctly before upgrading the Primary. I would change the CP version in the Checkpoitn cluster object to the Secondary's version and then reset SIC. It would work initially then as soon as I click the TEST button, or go to Smart Update (for the license), SIC would break. To fix the issue I had to break the cluster. The other option would have been to upgrade both members together.

In your case, if both members are running the same Checkpoint version, confirm that the version in the CLuster object is correct.
__________________
www.netleets.com
IT Security news and information in plain English.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0