CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > IPS-1
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-01-29
Junior Member
 
Join Date: 2009-04-24
Posts: 7
Rep Power: 0
mark.edwards has an average reputation (10+)
Default IPS Event Analysis authentication

Our manager has recently been upgraded to R70.2 and as a result the IPS Event Analysis package was added. However if I try to logon to the IPS Event Analysis it fails with an authentication to server failed error.

I can logon to the manager (SmartDashboard) without any problems and If I select IPS Event Analysis it also fails with the same error.
I have the necessary licenses.

I have gone through the documenatation and can't find anything relating to this.
Reply With Quote
  #2 (permalink)  
Old 2010-01-29
Senior Member
 
Join Date: 2009-03-21
Posts: 183
Rep Power: 2
MrSnakey has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by mark.edwards View Post
Our manager has recently been upgraded to R70.2 and as a result the IPS Event Analysis package was added. However if I try to logon to the IPS Event Analysis it fails with an authentication to server failed error.

I can logon to the manager (SmartDashboard) without any problems and If I select IPS Event Analysis it also fails with the same error.
I have the necessary licenses.

I have gone through the documenatation and can't find anything relating to this.
You may not be licensed for it. Post your license and I'll check or if you're feeling brave, you could check yourself.

Do 'cplic print' and post the output MINUS THE IP ADDRESS AND THE SIGNATURE STRING.

If you are licensed for it then... well I don't know, I've not used it outside of *local.
__________________
--
Mr Snakey
Remember: Speculation does no-one any good.
Visit http://www.snakeoilresearch.com

Last edited by MrSnakey; 2010-01-29 at 13:25.
Reply With Quote
  #3 (permalink)  
Old 2010-02-01
Junior Member
 
Join Date: 2009-04-24
Posts: 7
Rep Power: 0
mark.edwards has an average reputation (10+)
Default Re: IPS Event Analysis authentication

[Expert@smart1-man-ats]# cplic print

Host Expiration Features
****** never cpsm-c-50 cpsb-npm cpsb-epm cpsb-logs cpsb-mntr cpsb-udir cpsb-prvs cpsb-ipsa
Reply With Quote
  #4 (permalink)  
Old 2010-03-12
Junior Member
 
Join Date: 2006-10-11
Posts: 18
Rep Power: 0
mhicks has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Greetings,

I am having the same issue you described. I am not licensed for the product, but I am using a CPMP-EVAL-1-NGX eval license.

TAC is useless on this. All they told me is that I cant run IPS Event Analysis Blade because I am in Management HA mode. I don't seem to want to believe that.
Reply With Quote
  #5 (permalink)  
Old 2010-03-12
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 876
Rep Power: 5
lammbo has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by mhicks View Post
Greetings,

I am having the same issue you described. I am not licensed for the product, but I am using a CPMP-EVAL-1-NGX eval license.

TAC is useless on this. All they told me is that I cant run IPS Event Analysis Blade because I am in Management HA mode. I don't seem to want to believe that.
Say what?!? You can't run it if you're in HA MGMT? Is this a known limitation like not being able to run QoS and CoreXL at the moment? (I HOPE this is only until they fix the code)

Can someone confirm this information? I don't recall seeing this in the list of known limitations.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #6 (permalink)  
Old 2010-03-12
Junior Member
 
Join Date: 2006-10-11
Posts: 18
Rep Power: 0
mhicks has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by lammbo View Post
Say what?!? You can't run it if you're in HA MGMT? Is this a known limitation like not being able to run QoS and CoreXL at the moment? (I HOPE this is only until they fix the code)

Can someone confirm this information? I don't recall seeing this in the list of known limitations.
A simple search returned this:

R70.20 Known Limitations (https://supportcenter.checkpoint.com...onid=sk43166#4)

"00524529,
00522141 The Event Correlation, Reporting, and IPS Event Analysis Blades cannot be installed on Security Management servers in High Availability. For High Availability environments, install the Reporting, Event Correlation, or IPS Event Analysis server on a dedicated Log server."


Which is why I am asking for help.

Last edited by mhicks; 2010-03-12 at 10:54.
Reply With Quote
  #7 (permalink)  
Old 2010-03-12
Senior Member
 
Join Date: 2009-04-30
Location: Colorado, USA
Posts: 397
Rep Power: 2
ShadowPeak.com has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by mhicks View Post
Greetings,

I am having the same issue you described. I am not licensed for the product, but I am using a CPMP-EVAL-1-NGX eval license.

(snip)
Just a quick note here: new R70 features like SmartWorkflow and IPS Event Analysis do not work at all under a CPMP-EVAL-1-NGX license. If you have the ability to generate a "quick eval" license in your usercenter account (or know someone who does such as your reseller) you'll need to pick this new blade-based license instead: "CPSG-P808-CPSM-PU008-EVAL - Check Point Security Bundle Eval - including SG808 and SMU008 for 30 days".
Reply With Quote
  #8 (permalink)  
Old 2010-03-12
Junior Member
 
Join Date: 2006-10-11
Posts: 18
Rep Power: 0
mhicks has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by ShadowPeak.com View Post
Just a quick note here: new R70 features like SmartWorkflow and IPS Event Analysis do not work at all under a CPMP-EVAL-1-NGX license. If you have the ability to generate a "quick eval" license in your usercenter account (or know someone who does such as your reseller) you'll need to pick this new blade-based license instead: "CPSG-P808-CPSM-PU008-EVAL - Check Point Security Bundle Eval - including SG808 and SMU008 for 30 days".
Thanks, I will have my SE hook me up. By the way, I used SmartWorkflow using the CPMP-EVAL-1-NGX license on my r70.1 smart1.
Reply With Quote
  #9 (permalink)  
Old 2010-03-12
Senior Member
 
Join Date: 2009-04-30
Location: Colorado, USA
Posts: 397
Rep Power: 2
ShadowPeak.com has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Quote:
Originally Posted by mhicks View Post
Thanks, I will have my SE hook me up. By the way, I used SmartWorkflow using the CPMP-EVAL-1-NGX license on my r70.1 smart1.
Interesting. I had a student in my CCSE R70 class invalidate his 15-day trial license and he had difficulty getting SmartWorkflow working during a lab exercise with a CPMP-EVAL-1-NGX license present. Once I installed a CPSG-P808-CPSM-PU008-EVAL license everything was golden. It might not have been a licensing issue after all; I'll definitely take a closer look if it happens again. Thanks!

Last edited by ShadowPeak.com; 2010-03-12 at 21:10.
Reply With Quote
  #10 (permalink)  
Old 2010-03-16
Junior Member
 
Join Date: 2006-10-11
Posts: 18
Rep Power: 0
mhicks has an average reputation (10+)
Default Re: IPS Event Analysis authentication

FYI, I installed the CPSG-P808-CPSM-PU008-EVAL Check Point Security Bundle Eval - including SG808 and SMU008 for 30 days and it still doesnt work. I still get the same authentication failed message.
Reply With Quote
  #11 (permalink)  
Old 2010-03-25
Junior Member
 
Join Date: 2010-02-23
Posts: 20
Rep Power: 0
Optic has an average reputation (10+)
Default Re: IPS Event Analysis authentication

Hi,

I was getting an authentication error until I edited the Management Server object in SmartDashboard and ticked "IPS Event Analysis" option on the Management tab.

I then had to chooce "Policy, Install Database" to apply the change.

Once I did this, the authentication error with IPS Event Analysis client went away.

Even though I can open the client I cannot get any events to appear in it. :( It all appears to be working fine only it isn't...

Cheers,
David
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:23.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1