CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-01
Junior Member
 
Join Date: 2006-06-28
Posts: 18
Rep Power: 0
raulico has an average reputation (10+)
Default Hfa 04 Vpn_1_r60

Hi,
due to last problem on hfa18 on secure platform, i prefer to wait until someone could do a test on a spare device.
Is there any problem upgrading to this HFA04 on nokia ip?
Is there anybody who yet did it?
Reply With Quote
  #2 (permalink)  
Old 2006-09-18
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Hi,

1- I instilled NGX R60 Hotfix R60_03 and I received the error message "Cannot find pid of vpnd".
2- I uninstalled Hotfix R60_03 and installed Hotfix R60_04 to correct the problem but still the issue exist.

I am still investigating.

Do you want to proceed with installation of Check Point NGX R60 Hotfix R60_03 for Check Point NGX R60 on this computer?

Screen shot from the installation process:

If you choose to proceed, installation will perform CPSTOP.

(y-yes, else no):y

SmartView Monitor: Management stopped

FloodGate-1 stopped

Cannot find pid of vpnd

VPN-1/FW-1 stopped

SVN Foundation: cpd stopped

SVN Foundation: cpWatchDog stopped

SVN Foundation stopped

Launching post-hotfix utility
Reply With Quote
  #3 (permalink)  
Old 2006-09-18
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 853
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

You probably don't need to worry about the message about not finding the vpnd pid.

Are you running VPNs on the module? Is it ticked on the node configuration in Smart Dashboard? If not, then vpnd won't be running, since it's not needed.

When it does the HFA install, it tries to kill off all the FW processes first. It's not clever enough to work out that you were never running vpnd, so tries to kill it off, even though it doesn't exist.

Check $FWDIR/log/vpnd.elg if you like. Look for messages like "Object doesn't support encryption".

Seems to me your HFA installation completed OK. You can also look at the HFA installation logfile.

I've done the install without problem on flash-based Nokias, but haven't had a chance to roll it into production yet.
Reply With Quote
  #4 (permalink)  
Old 2006-09-18
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Yes I am running VPN on my firewall and the VPN option is checked in smart dashboard. However, I haven't had a chance to push the policy to the firewall.
Reply With Quote
  #5 (permalink)  
Old 2006-09-18
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 853
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Just to clarify something, so you've configured it within Smart Dashboard to do VPNs, but you haven't actually pushed that out to it yet, so it's currently not running any policy?

Is this a new setup, and you're patching at install time?

In that case, vpnd will start up when you push policy. For now though, you can ignore that message
Reply With Quote
  #6 (permalink)  
Old 2006-09-18
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Yes VPN is enabled on the FW object in smart dashboard.

Yes this a new installation of IPSO 4.0build40 and NGX R60 with HFA 03.

I pushed the policy to the FW, and now I receive the following error:

"can not single a VPND process. There is no such process.

I tried to run the vpnd manually an the message was vpnd started. However the next few lines were error messages to other files.
Reply With Quote
  #7 (permalink)  
Old 2006-09-18
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

I had to reboot the FW!!! The VPN error message is gone now and the VPND process is running fine.

Thank you for you help.
Reply With Quote
  #8 (permalink)  
Old 2006-09-18
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 853
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Good to hear it's working now.
Reply With Quote
  #9 (permalink)  
Old 2006-09-20
Junior Member
 
Join Date: 2006-06-28
Posts: 18
Rep Power: 0
raulico has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

i installed the hfa 04 on ipso 4.0,did a reboot and checked packages activation ,and after a week this morning the smart console didn't reply me, the port on firewall was open and in listen mode, firewall was working perfect, ssh_ing the firewall show a correct fw stat and errors, i did a cprestart and everything go ok.
it's a strange behaviour and it never happened to my firewalls.
what can i do to investigate?
i checked the log of nokia ipso and i see a lot of:
[LOG_NOTICE] xpand[289]: root localhost t +volatile:clish:admin:13129 t
Reply With Quote
  #10 (permalink)  
Old 2007-03-29
Junior Member
 
Join Date: 2007-03-26
Posts: 6
Rep Power: 0
Steve_Martin has an average reputation (10+)
Default Re: Hfa 04 Vpn_1_r60

Hi, we've had a similar problem with SPLAT - NGX R60 - HFA 04. The communication of firewall with Smart center is lost approx once in 15 days.. once rebooted, things are fine.

This started to occur once we applied HFA04.

Anybody has any clue on this.. There seems to be no problem with time synchronization between the firewall and smart center.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0