CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-13
keithsalter keithsalter is offline
Junior Member
 
Join Date: 2007-05-21
Posts: 5
Rep Power: 0
keithsalter has an average reputation (10+)
Default Solaris upgrade issues

We've recenly upgraded 4 Smartcentre servers from NG AI R55 to NGX R65. They're all running on Solaris 8 on SPARC boxes. The upgrades were all successful and followed the guidelines in the upgrade guide. No errors were reported during the upgrade - the only immediate issue was the ARP problem in Hotfix R65_01-3. We've since applied HFA01 to blanket fix the NAT problem.

However, since doing the upgrade we've had a couple of errors

1. SIC errors on the Smartcentre servers resulting in Smartclients not being able to attach to the Smartcentre servers see cpd.elg

extract below :

Code:
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] SIC certificate renewal time:
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] certificate not before       : Mon Jan  5 15:55:33 2004
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] certificate not after        : Sun Jan  4 15:55:33 2009
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] renew ratio                  : 0.750000
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] renew time                   : Sat Oct  6 04:55:33 2007
[CPD 999 1]@Smartcentre[11 Aug 14:34:41] now                          : Sat Aug 11 14:34:41 2007
this has required doing a cprestart which changed the certificate expiry date - see further extract from cpd.elg below :

Code:
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] SIC certificate renewal time:
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] certificate not before       : Fri Oct  5 04:55:41 2007
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] certificate not after        : Thu Oct  4 04:55:41 2012
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] renew ratio                  : 0.750000
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] renew time                   : Tue Jul  5 16:55:41 2011
[CPD 1015 1]@Smartcentre[2 Dec 15:44:43] now                          : Sun Dec  2 15:44:43 2007
I don't know why this happened but at least it's seems to be resolved now.

2. We're now having issues with logswitching. We have always used the commandline run from a cronjob to switch the logs at midnight on each Smartcentre server. This did work for a while after the upgrade but then we started having problems. So a manual switch via tracker was done. However now tracker can't switch the logs either.

The error we get via the gui and commandline is "Failed to connect".

3. In tracker - when selecting the Active Tab and choosing Open to accept the message about a performance hit we don't get any data displayed - just a message stating

"A new windows cannot be opened" - "Smartview Tracker allows a maximum of 5 windows to be opened concurrently".

This is depsite there being no other connected smartview clients and no other log windows (displaying more than one log file) being open.

Has anyone else seen similar issues or does anyone have any insight into them?

TIA

Keith
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0