CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-11
maurox maurox is offline
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 3
maurox has an average reputation (10+)
Default download policy

Hi all,
I don't understand why the VPN-1 edge appliances lose the policy ( downloaded previusly from the smartcenter / not the local policy ) when the smartcenter is unavailable ( this may happen for example during the upgrade of the smartcenter)....
I think this happen after some download failed ...but I'm not sure ...
does anyone note these problems ?
Regards,
Maurox
Reply With Quote
  #2 (permalink)  
Old 2006-08-11
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: downloadi policy

Why do you think that your Edge lose policy?
What status Internet and Service Center connections do you have?
Which Security Level on Security - Firewall page?
Reply With Quote
  #3 (permalink)  
Old 2006-08-11
maurox maurox is offline
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 3
maurox has an average reputation (10+)
Default Re: download policy

I think this because during the upgrade we lost the VPN connectivity .
All the Vpn1-edge have the High level of security .
Now the appliance are working so the status is connected ....
Maurox
Reply With Quote
  #4 (permalink)  
Old 2006-08-11
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: downloadi policy

Check logs (SmartView Tracker's VPN section, Edge's Event Log). Do you see error's on it?
Reply With Quote
  #5 (permalink)  
Old 2006-08-19
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: downloadi policy

what version of the firmware are you running?
Reply With Quote
  #6 (permalink)  
Old 2006-08-21
maurox maurox is offline
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 3
maurox has an average reputation (10+)
Default Re: download policy

The problems were on all Vpn-1 edge appliances ( some of them had the 5.x and some others 6.x) and I had these problems during the Smartcenter upgrade from version R55 to R60.
I'm wondering if this is a normal feature ( after some failed download attempts the appliance start to work only with the local polic) or a missconfiguration...
Reply With Quote
  #7 (permalink)  
Old 2006-08-21
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: download policy

Quote:
Originally Posted by maurox
The problems were on all Vpn-1 edge appliances ( some of them had the 5.x and some others 6.x) and I had these problems during the Smartcenter upgrade from version R55 to R60.
I'm wondering if this is a normal feature ( after some failed download attempts the appliance start to work only with the local polic) or a missconfiguration...

Different versions of libsw after upgrade? Wrong libsw version (in compare to edge firmware) will make your edge puke over smartcenter policy. This is always visible in Edge logfiles tho.
Reply With Quote
  #8 (permalink)  
Old 2006-08-21
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: download policy

Quote:
Originally Posted by maurox
I'm wondering if this is a normal feature ( after some failed download attempts the appliance start to work only with the local polic) or a missconfiguration...
No its not normal. As abusharif said make sure you update your libsw. I'd also sugest you run 6.0.76 for your firmware.
Reply With Quote
  #9 (permalink)  
Old 2006-08-23
maurox maurox is offline
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 3
maurox has an average reputation (10+)
Default Re: download policy

Hi all,
now all the appliances are working with the new firmware ( and there aren't any problems) but I don't understand why I have to update the libsw during the smartcenter migration if:
-Before the upgrade all the VPN1-edge were working without any problems ( so the libsw is updfated)
-I think that the r61/r60 libsw is newer than the last R55 libsw

What do you think ?
Best regards,
Maurox
Reply With Quote
  #10 (permalink)  
Old 2006-08-23
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: download policy

Quote:
Originally Posted by maurox
Hi all,
now all the appliances are working with the new firmware ( and there aren't any problems) but I don't understand why I have to update the libsw during the smartcenter migration if:
-Before the upgrade all the VPN1-edge were working without any problems ( so the libsw is updfated)
-I think that the r61/r60 libsw is newer than the last R55 libsw

What do you think ?
Best regards,
Maurox
not sure but it could be that libsw is not same for r60/61 and r55 versions, meaning when you upgraded to ngx it got overwritten by older libsw version suited for ngx.
Reply With Quote
  #11 (permalink)  
Old 2006-08-25
maurox maurox is offline
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 3
maurox has an average reputation (10+)
Default Re: download policy

It could be...I think I'm going to thest it when possible...
thanks,
Maurox
Reply With Quote
  #12 (permalink)  
Old 2006-08-26
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: download policy

Quote:
Originally Posted by maurox View Post
Hi all,
now all the appliances are working with the new firmware ( and there aren't any problems) but I don't understand why I have to update the libsw during the smartcenter migration if:
-Before the upgrade all the VPN1-edge were working without any problems ( so the libsw is updfated)
-I think that the r61/r60 libsw is newer than the last R55 libsw

What do you think ?
Best regards,
Maurox
R55 didn't support SmartDefense Updates to Edge boxes, R60A/R61 does. Most of the libsw changes are for SMDF. So R55 was more forgiving because it doesn't support these features.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0