CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-24
lobotiger lobotiger is offline
Junior Member
 
Join Date: 2007-03-23
Posts: 6
Rep Power: 0
lobotiger has an average reputation (10+)
Default SIC not available in cpconfig menu

Hi everyone. This is my first post so I hope that it's in the right section. I've tried searching for an answer on here for this problem but only one other thread had the same thing and no one really responded to that one...

So I've just installed SPLAT on a PC and VPN-1 Power and SmartCenter as well on the same PC. I've gone through all the necessary configuations as per the user guides but I have noticed that nowhere has it given me an option for entering the SIC code. I know that it's normally supposed to show with a cpconfig after doing the Certificate of Authority option. Have I done or missed something to warrant the menu option not being there? Right now I'm prevented from creating a new gateway because I cannot secure the internal communication.

Any advice would be appreaciated.

Thanks.

LoboTiger

P.S. This install is with the 15 day trial period for now.
Reply With Quote
  #2 (permalink)  
Old 2007-03-24
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

What menu options show when you type cpconfig <Enter> from a command prompt?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-03-24
lobotiger lobotiger is offline
Junior Member
 
Join Date: 2007-03-23
Posts: 6
Rep Power: 0
lobotiger has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

I only have the following:

1) Licenses
2) Administrator
3) GUI Clients
4) SNMP Extension
5) PKCS#11 Token
6) Random Pool
7) Certificate Authority
8) Certificate's Fingerprint
9) Disable Advanced Routing
10) Automatic start of Checkpoint Products
11) Exit

LoboTiger
Reply With Quote
  #4 (permalink)  
Old 2007-03-24
lobotiger lobotiger is offline
Junior Member
 
Join Date: 2007-03-23
Posts: 6
Rep Power: 0
lobotiger has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Oh I thought I would add that this is NGX R62.

LoboTiger
Reply With Quote
  #5 (permalink)  
Old 2007-03-25
inetd inetd is offline
Member
 
Join Date: 2006-11-03
Posts: 34
Rep Power: 0
inetd has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Are you running in standalone mode? The gateway should have been created automatically, if so. There shouldn't even really be a need to establish SIC in a standalone environment.
Reply With Quote
  #6 (permalink)  
Old 2007-03-25
lobotiger lobotiger is offline
Junior Member
 
Join Date: 2007-03-23
Posts: 6
Rep Power: 0
lobotiger has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Yes I guess it is in standalone mode in that both the SmartCenter and FW module are on the same machine with SPLAT. I would think the same way as you but the problem comes in when I try and create a new VPN-1 gateway and it wants me to establish SIC. It prompts me for the key even though I've never had to input a key on the server. ????

LoboTiger
Reply With Quote
  #7 (permalink)  
Old 2007-03-26
lobotiger lobotiger is offline
Junior Member
 
Join Date: 2007-03-23
Posts: 6
Rep Power: 0
lobotiger has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Just thought I'd post an update as I got an answer from a guy at my work who knows some things about Checkpoint. Turns out that inetd was kinda right in that you don't have to create a SIC if both the fw module and smartcenter are on the same box:

The SIC question only gets asked (and is only necessary) if you are installing a Firewall without SmartCenter on the same host. If SmartCenter is on the same host, you don’t need SIC (and you don’t need two different objects in your database, because it’s all on one host), because all the traffic between them is local and never travels out to the network where SIC is necessary. If you were to now add another VPN-1 Power host somewhere else, that install would prompt you for a SIC activation key, and you would need to create a separate object for that in your database to establish SIC.

LoboTiger
Reply With Quote
  #8 (permalink)  
Old 2008-05-13
srahman srahman is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 13
Rep Power: 0
srahman has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Hello,

Can you please help. I have recently installed CheckPoint NGX (R60) on a Windows server and have two nokia's (IP560) with build 4.2 (R65). I have installed the CheckPoint Configuration program with Standalone mode and now realised this prevent me from running SIC. Can someone please tell me how I can reset the Nokia boxes back to Configuration mode, but leaving the interface details alone.

Also can you have the Management station on R60 and the nokia boxes on R65?

Look forward to your reply.

Thank you kindly.
Shaz
Reply With Quote
  #9 (permalink)  
Old 2008-05-15
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Your SMARTCenter needs to be the same version or newer then your gateways, you cannot run an R60 SMARTCenter and R65 gateways. You need to downgrade the gateways or upgrade the SMARTCenter.

Resetting the Nokia config will not reset the Check Point packages configuration. I would uninstall and do a clean CHeck Point install afterwards.
Reply With Quote
  #10 (permalink)  
Old 2008-05-17
srahman srahman is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 13
Rep Power: 0
srahman has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Hello,

Thank you for your reply.

Please can you describe the step on how to do a clean install of CheckPoint? Would installing a newer build ie from Build 69 to Build 78 work?
I have tried to uninstall the packages and this fails to work.

Please help.
Thank you.
Shaz
Reply With Quote
  #11 (permalink)  
Old 2008-05-17
srahman srahman is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 13
Rep Power: 0
srahman has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Hello,

Where can I download IPSO 4.2 BUILD 78 from?

Thanks
Reply With Quote
  #12 (permalink)  
Old 2008-05-19
Yasushi Kono Yasushi Kono is offline
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 104
Rep Power: 2
Yasushi Kono has an average reputation (10+)
Default Re: SIC not available in cpconfig menu

Quote:
Originally Posted by srahman View Post
Hello,

Thank you for your reply.

Please can you describe the step on how to do a clean install of CheckPoint? Would installing a newer build ie from Build 69 to Build 78 work?
I have tried to uninstall the packages and this fails to work.

Please help.
Thank you.
Shaz
What you have to do is a clean installation of IPSO. The Nokia appliance comes with the original Nokia IPSO CDROM. As far as you have Software Download Support contract, you can download ipso.tgz from the download pages of Nokia. This image should be transferred to an FTP Server. Then, you reboot your machine and wait until the following message appears:

Type any character to enter command mode


Upon typing any character, you will get the BOOTMGR prompt. There, you have to type

install


From now on, the installation is interactive (I have described all the steps in my book "Check Point VPN-1 Power" (ISBN 978-3898428972), but in German language.

What you need before is:

ipso.tgz and IPSO_wrapper_NGX_R6x.tgz in a directory of an FTP Server.

If you have to know IPSO, visit a 5-day course ("Check Point NGX Security Administration I on Nokia IO Security Platforms"). I am also one of the contributors of this courseware! These five days will change your life!

Kind regards,

Yasushi
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0