CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-04
msarzina@yahoo.it msarzina@yahoo.it is offline
Junior Member
 
Join Date: 2007-03-04
Posts: 18
Rep Power: 0
msarzina@yahoo.it has an average reputation (10+)
Default Management interface

Hi All

i have this topology in the lab (all Ver R65 OS SecurePlatform)


eth2 eth1 eth1 eth2
ServerA----->fw1---------------->fw2------>ServerB
eth0| eth0|
|--------------------|
|
|------>guiclient
|
|-eth0-SmartcenterZ

on fw1 fw2 and smartcenterZ there is an

eth4

not connected preconfigured with the same ip address 195.12.31.42/32

i start installing the splat+smartcenter via sysconfig configuring the eth0 (i don t change via sysconfig the preconfigured eth4 ip address selected as management interface

the same for the fw1 splat eth0 eth1 eth2 and fw2 splat eth0 eth1 eth2 via sysconfig leaving the eth4 as it is (/32 same ip address and selected as management inetrface)

then i access the dashboard i find the management with the main ip address on the eth0 and in the topology i can see the eth4 in the second line

i start the gateway typing the hostname and the eth0 given via sysconfig ip address, sic works fine the topology is imported succesfully

i define an any to any any service accept log rule

then i push the policy

i start ssh from serverA to serverB everything works fine even the logging in smarttracker

then i define a simple star vpn site to site between the 2 fws center the fw1 satellite the fw2 in the firewall properties i restrict the encryption domain for the NetA and NetB respectively and i change the VPN Link selection on the respectiv e eth1 interface

VPN doesn t work and log stops working

to make VPN and log working i have to run sysconfig and to select the eth0 as management interface on both fws

the question is why initially the routing firewalling an logging is working properly and then after the VPN definition logging and firewalling stop working until i redefine the select management interface from eth4 to eth0?

how management comes in place stopping all the functions only after a VPN definition and until a management ineterface re- selection?



details
on the 3 splat devices

fw1 eth0 192.168.254.101/24
fw1 eth1 172.16.16.1/30
fw1 eth2 192.168.15.1/24

fw2 eth0 192.168.254.102/24
fw2 eth1 172.16.16.2/30
fw2 eth2 192.168.30.1/24

smartcenterZ eth0 192.168.254.100

route on fw1 route 192.168.30.0/24 to fw2-eth1

route on fw2 route 192.168.15.0/24 to fw1-eth1
Reply With Quote
  #2 (permalink)  
Old 2008-04-06
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Management interface

are you running a cluster, if so post up a cphaprob stat and cphaprob -a if and cphaprob -i list.
Reply With Quote
  #3 (permalink)  
Old 2008-04-08
msarzina@yahoo.it msarzina@yahoo.it is offline
Junior Member
 
Join Date: 2007-03-04
Posts: 18
Rep Power: 0
msarzina@yahoo.it has an average reputation (10+)
Default Re: Management interface

Actually i am not running a cluster just a single firewall to a single firewall

Marco
Reply With Quote
  #4 (permalink)  
Old 2008-04-08
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Management interface

Quote:
eth4

not connected preconfigured with the same ip address 195.12.31.42/32
How can eth4 be your "management interface" if its not connected to anything?

The fact that your smartcenter server is on the same network as eth0 is the reason why it you have to change to eth0...
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2008-04-09
msarzina@yahoo.it msarzina@yahoo.it is offline
Junior Member
 
Join Date: 2007-03-04
Posts: 18
Rep Power: 0
msarzina@yahoo.it has an average reputation (10+)
Default Re: Management interface

You're right, i am only wondering why even non changing the management to eth0 the system works fine until i install a vpn satellite site to site between them
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:13.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0