CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-31
smalldragoon smalldragoon is offline
Junior Member
 
Join Date: 2008-02-23
Posts: 5
Rep Power: 0
smalldragoon has an average reputation (10+)
Default commnication with site xxx.xxx.xxx.xxx has failed

Hi,
I have a problem with my gateway and I can not find where.
Today, some users called syaing that they can not get connected anymore : communication has failed ..
Th message is maybe a trick, as the problem is not on the com ?


Symptom :

try to update the site in the Securemote which already have the gw defined

-> Error : commnication with site xxx.xxx.xxx.xxx has failed

Try to create the site

-> error : commnication with site xxx.xxx.xxx.xxx has failed

So I tried from another computer and I have the same problem.

checking on others computers, I can not anymore get connected.
The GW is still running without any problem ( I restarted services as well. no chnages )

Is any has a clue for me ?
Thanks
Reply With Quote
  #2 (permalink)  
Old 2008-03-31
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: commnication with site xxx.xxx.xxx.xxx has failed

This sounds like:

1. vpnd is not running
2. something up stream is blocking the connection
3. You have the implied rules turned off and don't have a manual rule for VPN

Quick check:

- Anything in the firewall log?

- from the gateway (assuming SPLAT) "ps -ef | grep -i vpn"
Look for VPNd

- From the command line on the gateway "vpn debug on"
then look at $FWDIR/log/vpnd.elg and see what's making it to the gateway.
Reply With Quote
  #3 (permalink)  
Old 2008-04-01
smalldragoon smalldragoon is offline
Junior Member
 
Join Date: 2008-02-23
Posts: 5
Rep Power: 0
smalldragoon has an average reputation (10+)
Default Re: commnication with site xxx.xxx.xxx.xxx has failed

Hello
Sorry, I was not really precise.
so
- When I connect, I have only the line wiht the fw1_topo accepted, nothing else.

- I try to connect from the LAN, so nothing is blocking, and I ahve the same result

- vnpd is running :
root 4176 1 0 Feb07 ? 00:00:00 vpnd 0
root 4177 1 0 Feb07 ? 00:00:00 vpnd 0
root 4188 1 0 Feb07 ? 00:00:00 vpnd 0
root 17410 1 0 Feb16 ? 00:00:00 vpnd 0
root 10588 29629 0 09:34 ? 00:00:00 vpnd 0
root 10823 10799 0 09:47 pts/0 00:00:00 grep -i vpn

From another hand, The file is a new clue so :D
I have inside

[ 10953 1024]@bastion[1 Apr 9:52:04] ------------ VPND Starting: Tue Apr 1 09:52:04 2008

InvokeIsakmpServer: can't bind socket: Operation not permitted
InvokeIsakmpServer: can't bind socket: Operation not permitted
InvokeIsakmpServer: can't bind socket: Operation not permitted
InvokeIsakmpServer: can't bind socket: Operation not permitted
InvokeIsakmpServer: can't bind socket: Operation not permitted
InvokeIsakmpServer: can't bind socket: Operation not permitted

so, prob of rights ?
Reply With Quote
  #4 (permalink)  
Old 2008-04-01
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: commnication with site xxx.xxx.xxx.xxx has failed

Have you tried a reboot?

Try a "netstat -an | grep 500" and see if something is bound to UDP/500 which is IKE.
Reply With Quote
  #5 (permalink)  
Old 2008-04-01
smalldragoon smalldragoon is offline
Junior Member
 
Join Date: 2008-02-23
Posts: 5
Rep Power: 0
smalldragoon has an average reputation (10+)
Default Re: commnication with site xxx.xxx.xxx.xxx has failed

Hi,
the reboot was the solution, not because of the port, but for a license problem.
this GW is an old one which can not ( and must not ) be upgraded.
They pushed soem licences on all GW this WE.
With a cpstop/cpstart or restart : no problems.
After rebboting, I had all errors messages regarding licenses.
I reassigned the "old" license and everything came back in order
Thanks a lot for the help !!
Regards
Lionel
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:29.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0