CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-19
Checkpoint Newb Checkpoint Newb is offline
Junior Member
 
Join Date: 2007-07-18
Posts: 3
Rep Power: 0
Checkpoint Newb has an average reputation (10+)
Default Losing the Enterprise policy in integrity client?

We have a bunch of employees that lose their enterprise policy.

Checkpoint came back to us with a suggestion to of reinstalling the policy through replacing some of the xml files that normally go in C:\Windows\Internet Logs.

The only problem is that requires users to go into Safe Mode to do it. And having users do anything in safe mode is a little sketchy.

So far our helpdesk has just been reinstalling it for the users, but they'd like a better solution.

Any thoughts?
Reply With Quote
  #2 (permalink)  
Old 2007-07-23
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Assuming that you are using 6.5 can you identify any error messages in the windows event viewer? Look for IAMDB.RDB corruption errors. This is generally the cause of issues that require a re-install to get the enterprise policy. This corruption issue has been resolved in build 175 and will be incorperated in HFA6 for 6.5 due out early August. I have made a lot of assumptions but you didn't give us much to go on.

hth
Reply With Quote
  #3 (permalink)  
Old 2007-07-24
Checkpoint Newb Checkpoint Newb is offline
Junior Member
 
Join Date: 2007-07-18
Posts: 3
Rep Power: 0
Checkpoint Newb has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Thanks for the information, I'll see about getting information from some users' event viewer to see if that's the case.
Reply With Quote
  #4 (permalink)  
Old 2007-07-24
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

You may get by without a reinstall if you export a known good personal policy (cntl-alt double click on the personal policy) This can be cut and pasted into an new *.xml file. Then from the affected client run the command iclient -config *.xml. This may allow you to connect to the integrity server and download the correct enterprise policy, without going into safe mode or re-installing.
Reply With Quote
  #5 (permalink)  
Old 2007-07-26
Checkpoint Newb Checkpoint Newb is offline
Junior Member
 
Join Date: 2007-07-18
Posts: 3
Rep Power: 0
Checkpoint Newb has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Yeah, that's pretty much what Checkpoint gave us. As it turns out, we're not quite up to the latest version of the server, yet the clients have been updated....

We've got some fun coming up with updates this weekend.
Reply With Quote
  #6 (permalink)  
Old 2007-07-26
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

HFA06 clears up a lot of these issue and should be out in a couple of weeks.
Reply With Quote
  #7 (permalink)  
Old 2008-04-18
ffaber ffaber is offline
Junior Member
 
Join Date: 2006-12-20
Posts: 3
Rep Power: 0
ffaber has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Hello,

We have a similar issue. We have one user who is abroad all the time and connects to the company network through SecureClient VPN. After a week or 2-3 he looses the Enterprise policy in his Integrity Agent. This is no incident. The solution is to connect to the company LAN. Then he gets the Enterprise policy right away and he can work again for 2 to 3 weeks.
Is there a time-out for a Enterprise policy when working remote? Anyone who experienced the same?

Thanks
Reply With Quote
  #8 (permalink)  
Old 2008-04-21
unclerichard unclerichard is offline
Junior Member
 
Join Date: 2007-05-11
Location: Bristol, UK
Posts: 19
Rep Power: 0
unclerichard has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Hi ffaber,

Yes, I have seen this happen quite a few times and the 'reset' option that was shipped with HFA06 (v188) clears this up a treat after the subsequent restart. (CTRL-SHIFT right-click the Integrity systray icon). I can simulate this quite happily by forcing a power off of the endpoint which seems to trash the local .mdb files.

Unc
Reply With Quote
  #9 (permalink)  
Old 2008-04-28
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

This may be related to how your catalogs are setup.

Do you have a Catalog setup for the VPN gateway he is using? If not then he should technically getting a different policy than when connecting to the lan. Version number of SC and Integrity would be helpful.

What other behavior does this problem exhibit? When the enterprise policy disappears is there just the personal policy? When he connects to the VPN does the personal policy remain active? Does SC diconnect him from the vpn without the Corperate policy?
Reply With Quote
  #10 (permalink)  
Old 2008-05-07
ffaber ffaber is offline
Junior Member
 
Join Date: 2006-12-20
Posts: 3
Rep Power: 0
ffaber has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

Yes I have defined a NT-domain Catalog, only for the Integrity Firewall not for the VPN gateway. So there is no relation yet with SC (R60) and the Integrity Agent (135) except for the license.

When the enterprise policy disappears is there just the personal policy? Yes only the default Policy
When he connects to the VPN does the personal policy remain active? No, normaly the Enterprise policy should remain active.
Does SC diconnect him from the vpn without the Corperate policy? No

Is this EndpointSecurity_Agent_70843_en.msi the latest version? (HFA6)

Thanks,
Frank
Reply With Quote
  #11 (permalink)  
Old 2008-05-16
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Losing the Enterprise policy in integrity client?

The default policy is not the personal policy...unless you renamed the policy. The default policy often is the system provided enterprise policy that is attached to the enterprise when the catalog policies do not apply.

It may be that the endpoint is getting an enterprise policy...the default and that you should check you entities to see if any of them have the default policy assigned.

NO that is not a 6.5 client it is a 7.0 client.

-cs
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:08.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0