CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-09-13
xavigo xavigo is offline
Junior Member
 
Join Date: 2005-09-13
Posts: 1
Rep Power: 0
xavigo has an average reputation (10+)
Default Policy installation failed after upgrading

We recently upgraded from NG R55 to NGX R60 (using the automatic procedure) in our Windows 2003 server.

Now we can't apply the security policy , it gives the error:

Operation failed, install/uninstall has been improperly terminated.

In the log the only thing I see is that all connection attempts are dropped.

TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK
TCP packet out of state: First packet isn't SYN; tcp_flags: RST-ACK
TCP packet out of state: First packet isn't SYN; tcp_flags: RST
TCP packet out of state: First packet isn't SYN; tcp_flags: ACK
TCP packet out of state: First packet isn't SYN; tcp_flags: FIN-ACK
TCP packet out of state: First packet isn't SYN; tcp_flags: FIN-PUSH-ACK

Has anyone been in this situation?. Do you know what can be happening??

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2005-11-16
ShortyICE ShortyICE is offline
Junior Member
 
Join Date: 2005-11-16
Posts: 1
Rep Power: 0
ShortyICE has an average reputation (10+)
Default Re: Policy installation failed after upgrading

Yes, I have got this even one step more all new EDGE or Firewalls cannot get the policy either after a MOVE/UPGRADE process.

Any help would be appreciated.
Reply With Quote
  #3 (permalink)  
Old 2005-11-17
jeepee jeepee is offline
Junior Member
 
Join Date: 2005-11-10
Posts: 7
Rep Power: 0
jeepee has an average reputation (10+)
Default Re: Policy installation failed after upgrading

Distributed or Standalone installation?

If distributed, does its Win2003 on Gateway And SmartCenter?

have you try "fw unloadlocal" on the gateway and then push the policy?

Last edited by jeepee; 2005-11-17 at 06:28.
Reply With Quote
  #4 (permalink)  
Old 2005-11-17
czech12 czech12 is offline
Member
 
Join Date: 2005-10-25
Location: North Brunswick, NJ
Posts: 38
Rep Power: 0
czech12 has an average reputation (10+)
Default Re: Policy installation failed after upgrading

Also, make sure your license was upgraded properly... Just a thought...
__________________
====================
Aaron Vivo
CCSE Plus, CCMSE, NSA
====================
Reply With Quote
  #5 (permalink)  
Old 2006-02-02
pabouk pabouk is offline
Junior Member
 
Join Date: 2006-02-02
Location: Czech Republic
Posts: 5
Rep Power: 0
pabouk has an average reputation (10+)
Default Re: Policy installation failed after upgrading

This problem is described in the article sk31193 in Check Point's KB. This error could be caused by changed SmartDefense licencing. HTTP application checks are now available only as a part of Web Intelligence "product" which is licensed separatedly.

Try to clear all Web Server boxes in network objects (Host Node > General Properties > Products > Configure Servers).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:07.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0