CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-17
garrettc garrettc is offline
Junior Member
 
Join Date: 2006-08-17
Posts: 3
Rep Power: 0
garrettc has an average reputation (10+)
Default SIC help moving from standalone Solaris to Solaris gateway and Windows Console

I am migrating a standalone Solaris gateway/management machine to a distributed HA environment with 2 solaris gateways and 1 windows managment console.

I have managed to export/import the rules into the windows console ok.

I reinstalled a clean gateway and vpn express (that's the licences we have) on solaris.

I cannot push the policy to the gateway because of a SIC error. The communications button for the SIC on the gateway object is grayed out. And there is not SIC menu item in the cpconfig menu on the gateway.

How can I proceed to establish the SIC in this situation?

Any help is Much appreciated!
garrett
Reply With Quote
  #2 (permalink)  
Old 2006-08-17
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: SIC help moving from standalone Solaris to Solaris gateway and Windows Console

Did you use this guide for migrating? - https://secureknowledge.checkpoint.c...ion&id=sk25536

May be problem with it
"Important Note:
Do not import the configuration during the installation. It should be manually imported later.
If you import configuration during initial installation, you will need to repeat the installation from the beginning."
Reply With Quote
  #3 (permalink)  
Old 2006-08-18
tdvit tdvit is offline
Senior Member
 
Join Date: 2005-08-30
Posts: 139
Rep Power: 4
tdvit has an average reputation (10+)
Default Re: SIC help moving from standalone Solaris to Solaris gateway and Windows Console

and make sure you do a distributed install
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #4 (permalink)  
Old 2006-08-18
garrettc garrettc is offline
Junior Member
 
Join Date: 2006-08-17
Posts: 3
Rep Power: 0
garrettc has an average reputation (10+)
Default Re: SIC help moving from standalone Solaris to Solaris gateway and Windows Console

Q:

1) Where to you select to do a Distributed install? Or what does that mean exactly?

2) In the instruction you referred me to, it says to remove FireWall-1 from the SmartCenter object.... there is no such object as the rules were imported from the exported file. ??

Also, I learned that setting a SIC is not an option when you install Express gateway as it is when you install Pro gateway.

And, I cannot delete the gateway object (because it's primary) or edit it from the rules objects. Nor can I deselect certain functions from it.

Lastly, I will be doing this migration on a customer's machines. They have designated their fileserver to be the SmartCenter server. I cannot simply rename it to the original box name as the document suggests. Which brings up the question - is it good or bad practice to put the Management station on the fileserver? Or should it be on a completely, less vulnerable machine?

Thanks in advance for your help,
garrett
Reply With Quote
  #5 (permalink)  
Old 2006-08-18
garrettc garrettc is offline
Junior Member
 
Join Date: 2006-08-17
Posts: 3
Rep Power: 0
garrettc has an average reputation (10+)
Default Re: SIC help moving from standalone Solaris to Solaris gateway and Windows Console

One more thing - This will ultimately be a Cluster XL setup. It seems to me that Checkpoint Express is not meant for Cluster XL, as there are not the same options in the installs for Express and there are for Pro.

Is that true or am i missing something? The licensing people told us that XL will work on Express gateways.

thanks,
garrett
Reply With Quote
  #6 (permalink)  
Old 2006-08-19
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: SIC help moving from standalone Solaris to Solaris gateway and Windows Console

Quote:
Originally Posted by garrettc
2) In the instruction you referred me to, it says to remove FireWall-1 from the SmartCenter object.... there is no such object as the rules were imported from the exported file. ??
There is no SmartCenter object. It's very strange.
Describe by step what did you do?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:49.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0