CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-09
DavidMa DavidMa is offline
Junior Member
 
Join Date: 2006-10-09
Posts: 2
Rep Power: 0
DavidMa has an average reputation (10+)
Default adding gateway to cluster problem

Hi everybody,
i'm trying to add a checkpoint gateway to a cluster, and appears the following message: "The gateway cannot be added to the cluster since it's used in places where cluster members are not allowed".
I remove all the gateway's related policy and NAT rules, but the message it's still the same.
Please, can you help me?
thanks!
Reply With Quote
  #2 (permalink)  
Old 2006-10-09
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 454
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: adding gateway to cluster problem

what does "where used" say?
is gw configured for remote access, office mode? if so remove it.
is gw part of an community? if so, remove it
in install on target, remove it


etc etc....

if its gone according to gui and doesnt work check with dbedit
Reply With Quote
  #3 (permalink)  
Old 2006-10-09
DavidMa DavidMa is offline
Junior Member
 
Join Date: 2006-10-09
Posts: 2
Rep Power: 0
DavidMa has an average reputation (10+)
Default Re: adding gateway to cluster problem

Hi Abusharif,
the "where used" command doesn't show anything, only some old backup policy...
How can I remove via dbedit? it's the only way?
thanks!
Reply With Quote
  #4 (permalink)  
Old 2006-10-09
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 810
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: adding gateway to cluster problem

Clearly "where used" is showing something, if it's referring to an old backup policy. Either it doesn't show anything, or it tells you it's used in an old policy. Can't be both. Which is it?

Check Point doesn't know that it's a backup policy, unless you've used DB revision control, which is not the case here. To Check Point it's just another policy, with a different name.

Right-click the object. Select Where Used. Note all policies it is used in. Open those policies. Run Where Used again, find out where in that policy it is used. Remove those references. Rinse and repeat until a "Where Used" query tells you the object is not used. Then add it to your cluster.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0