CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-04
Junior Member
 
Join Date: 2005-10-04
Posts: 2
Rep Power: 0
ahreece has an average reputation (10+)
Default CheckPoint FW-1 NG AI Install Failing

I have run into an exaperating problem involving a CheckPoint Enterprise install. The envrionment is a Sun Enterprise 450 multiprocessor with 3 Gigs of memory and running Solaris 8 (02/04 Edition). There are 7 quad ethernets (not my idea). There are two 36 gig hard drives that are mirrored using DiskSuite4.2.1. It is a locked down Solaris install using minimum packages based on Lance Spitzner's guidelines. I also installed the latest Sun Cluster patch (and yes, I have been burnt by that silly 110934 patch issue, but rolling it out doesn't seem to solve the problem).

I have tried to install the following versions of CheckPoint, all with no sucess:
- NG with AI R54 (this is the primary one)
- NG with AI R55 + HFA 14
- NG with AI R55 + HFA 15
- A manually modified version of R55 that included HFA16.
I have tried installing both the enforcement module and the enforcement module + logging module and it hangs at the same spot.

The SVN foundation installs fine, but when the install script attempts to install VPN-1 & Firewall-1, it gets so far then hangs. Specifically, it installs everything and then it tries to register the new compents into the CheckPoint registry. After a couple of minutes, the CPRegSvr process will hit 100% on one of the CPUs and just stay there. It's a good thing the box has four processors or I'd never be able to get on remotely.

I've sending hangup signals (HUP) to the process, but that just kills it. The funny thing is the script seems to continue after that. The R55 installs finish installing, but R54 hangs on the fw1 process while trying to generate the default filters. However, once the install completes, everything seems like it might work, but when I run the cpinfo script, it tells me that there are NO CheckPoint componets registered, so I don't really trust it, and this box eventually has to go into production.

There appears to be nothing in the CheckPoint knowledgebase about the CPRegSvr process and who thought it was a good idea to duplicate the Windows registry on Solaris anyway? (Sorry, *NIX-biased rant.) Or more accurately, why isn't it working on my system? Has anyone else seen this or a similar problem?

Adam.
Reply With Quote
  #2 (permalink)  
Old 2005-10-05
Junior Member
 
Join Date: 2005-10-04
Posts: 2
Rep Power: 0
Tenchi-Man has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

The latest Solaris patch cluster caused the problem.

By experience, the following patches should be removed.

Solaris 8:
- 109147-31 through 109147-37 or later (ld security update for Solaris 8)
- 110934-20 (pkgadd patch for Solaris 8)

Solaris 9:
- 112963-16 through 112963-23 or later (ld security update)
- 113713-17 (pkgadd patch)

Last edited by Tenchi-Man; 2005-10-05 at 19:37.
Reply With Quote
  #3 (permalink)  
Old 2005-10-07
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

yes, this is a very common and annoying problem! i've lost count of how many times this has tricked me!
Remove the patches, install the product, then re-add the patches.
Reply With Quote
  #4 (permalink)  
Old 2005-10-07
Junior Member
 
Join Date: 2005-10-04
Posts: 2
Rep Power: 0
ahreece has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

That was the problem of course. Everything installed fine once the patches removed. And of course, once you know what the problem is, you can find the solution on Check Points knowledgebase.

Which brings up an intersting question. I've noticed that CheckPoint's stance on the patches seems to be "they aren't supported." Which brings up another question: Once the patches are removed, should they be re-applied?
Reply With Quote
  #5 (permalink)  
Old 2005-10-08
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

Below is a snip from a Nokia resolution. My suggestion is not to re-install the patches.

When Solaris patch 11963-22 is installed, a modification to the file ld.so.1 is made which will cause an existing Check Point installation to stop working. This also prevents Check Point from being installed.

Other patches that modify the file ld.so.1 are:

SPARC Platform
- Solaris 8 with patch 109147-37 or later
- Solaris 9 with patch 112963-22 or later
- Solaris 10 with patch 117461-04 or later

x86 Platform
- Solaris 8 with patch 109148-37 or later
- Solaris 9 with patch 113986-18 or later
Reply With Quote
  #6 (permalink)  
Old 2005-10-10
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

i'm not sure why you wouldn't re-install the patch.. it only affects the installation process as far as i've been told?
Reply With Quote
  #7 (permalink)  
Old 2005-10-12
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

I know that 11963-22 affects more than the install. Not sure about the rest.
Reply With Quote
  #8 (permalink)  
Old 2005-10-13
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

ah ok

113713-17 (pkgadd patch)

that's the patch that has given me issues before, i always put it back on after installing FW1, and have no problems
Reply With Quote
  #9 (permalink)  
Old 2005-10-21
Junior Member
 
Join Date: 2005-10-21
Posts: 1
Rep Power: 0
begemot has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

Official answer from our CheckPoint partner:

You should NOT use the following patches at all:

- Solaris 8 109147-37
- Solaris 9 112963-22
- Solaris 10 117461-04

Checkpoint product manager works this issue directly with SUN.
As soon as this issue will be solved you will see a note at Sun website.

PS. with this patches many CP services dumps core ( fwm, fwd, etc)

Last edited by begemot; 2005-10-21 at 01:15.
Reply With Quote
  #10 (permalink)  
Old 2005-11-08
Junior Member
 
Join Date: 2005-11-08
Location: Milan, Italy
Posts: 20
Rep Power: 0
blackberry has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

I confirm for Solaris8 the rev 109147-38 causes same problems to Checkpoint NG FP3 HFA325 and you need to remove it in order to end the installation without errors.

Sun Microsystems released the 109147-39 but i didn't tried yet.

Last edited by blackberry; 2005-11-08 at 15:16.
Reply With Quote
  #11 (permalink)  
Old 2005-12-09
Junior Member
 
Join Date: 2005-11-08
Location: Milan, Italy
Posts: 20
Rep Power: 0
blackberry has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

109147-40 finally works! fine on MDS and NGFP3


# patchadd 109147-40

Checking installed patches...
Verifying sufficient filesystem capacity (dry run method)...
Installing patch packages...

Patch number 109147-40 has been successfully installed.
See /var/sadm/patch/109147-40/log for details

Patch packages installed:
SUNWcsl
SUNWcslx
SUNWcsr
SUNWcsu
SUNWcsxu


# fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 3 Build 53920

# fw stat
HOST POLICY DATE
localhost - - :

Last edited by blackberry; 2005-12-10 at 01:45.
Reply With Quote
  #12 (permalink)  
Old 2005-12-12
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: CheckPoint FW-1 NG AI Install Failling

nice! thanks for the update :)
__________________
///M
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:04.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0