CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-04
Junior Member
 
Join Date: 2007-09-18
Posts: 9
Rep Power: 0
gt123 has an average reputation (10+)
Default SIC cannot be established

I'm hoping someone could help me on this one.

I am running NG R55 on my Windows 2K Smartcenter server. It had a C and a D drive on it with the installation files being on Drive D. The C drive crashed and I could not longer boot up. I took the D drive and was able to slave it onto another workstation so I could access the files.

I got another server and installed W2K and then installed the management software (R55) . Then I did a straight file copy of the conf and the database directories over to the new server. I am not able to perform the upgrade_export utility on the old drive.

I am able to bring up the Smartdashboard now and view the policies but the mangement server remains untrusted with the modules.

I am not able to reset the SIC between the new management server and the enforcement module . When I try, I get a "Peer sent wrong DN try to reset SIC at the peer and reestablish the trust " message.

I'm hoping you can help on this. Thank you in advance.
Reply With Quote
  #2 (permalink)  
Old 2008-01-04
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SIC cannot be established

Did you use exactly the same computer name for the new SmartCenter?

Do you use the certificates for anything other than SIC? Such as user certificates for remote access? If not, there is a command you can run that will destroy the certificate authority and build a new one.

Did you already run the SIC reset on the firewall or is this when you get it? What steps are you doing in what order?

I'd get an upgrade_export right now, though. :-)

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-07
Junior Member
 
Join Date: 2007-09-18
Posts: 9
Rep Power: 0
gt123 has an average reputation (10+)
Default Re: SIC cannot be established

Did you use exactly the same computer name for the new SmartCenter?

I am not sure if I used the same computer name. The Windows administrators built it again using the same name but the only difference is that the new box is on the domain while the old box was in a workgroup. I believe that the name may be different when you include the dns suffix. Sorry, we were suppose to consolidate them onto our management server so I wasn't backup up or paying attention to the names.


Do you use the certificates for anything other than SIC? Such as user certificates for remote access? If not, there is a command you can run that will destroy the certificate authority and build a new one.

No, we are not using the certificates for remote access. Is that command fwm sic_reset ?

Did you already run the SIC reset on the firewall or is this when you get it? What steps are you doing in what order?

Yes, I already ran the sic reset on the firewall and I tried to do this on the smartdashboard but no luck. I did the firewall first and then the smartdashboard and reversed it as well but no luck.
The message I get does indicate a incorrect computer name and ICA as the message I get points to the name in the ICA file.

Does the fwm sic_reset destroy this and builds a new one ?
Reply With Quote
  #4 (permalink)  
Old 2008-01-07
Senior Member
 
Join Date: 2007-07-16
Posts: 618
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: SIC cannot be established

Your SIC is stuffed.... the files you need are in the $CPDIR directory, which IIRC defaults to C:\Program Files\Checkpoint on a Win2K build. Without the $CPDIR/conf and $CPDIR/database directories, what you've done is way to flaky to be reliable.

Best solution would be to find an old upgrade_export (you did archive these on a seperate box, right???) stop the SC, extract these directories manually, and place appropriately. That might (if you're lucky!) get your original root CA going. Or another way might be to run the upgrade_import, and then copy the newer $FWDIR/conf directory over the top of that. You may have more success that way.

Either way, your system is going to be flaky from now on. Honestly, I'd find a way to extract the rules and objects, and rebuild from a base system again.
Reply With Quote
  #5 (permalink)  
Old 2008-01-21
Junior Member
 
Join Date: 2007-09-18
Posts: 9
Rep Power: 0
gt123 has an average reputation (10+)
Default Re: SIC cannot be established

I got it going. Here's what I did.

1) reinstalled the Management server software
2) Manually copied the files over from the /conf and the /database directories in the $FWDIR and the $CPDIR except the ica files.

Then I was able to establish a sic with the firewalls and able to push policies.
Reply With Quote
  #6 (permalink)  
Old 2008-01-21
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SIC cannot be established

Thanks for the follow-up,

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:01.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0