CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
roadrunner roadrunner is offline
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 3
roadrunner has an average reputation (10+)
Default Putkeys with two different firewalls with the same IPs

Putkeys with two different firewalls with the same IPs
(This is relevant to FireWall-1 4.1 and earlier)

What is actually happening with a putkey is that you are setting up a "chain" (sort of like S/Key). The "putkey password" is the seed for this chain. Each time an authenticated session between systems is needed, one "key" in the "chain" is used. After a while, it generates a new "chain" based off the "putkey password" and the previous chain.

You can see where this is going: when you fail over to system B, the management console thinks it's talking to A still. A thinks the state of the authentication is one way, B thinks it's another way. They can't talk to one another until you redo the putkeys.

The authentication really uses the nodename IP address of the box, not the IP address specified in masters (or any other place). If the nodename IP of the box is the same (or even if it isn't), you can probably use the -n trick to solve it. i.e.:

On Management Console:

fw putkey -n mgmt-ip fwA fwB

On FireWall A:

fw putkey -n fwA-ip mgmt-ip

On FireWall B:

fw putkey -n fwB-ip mgmt-ip

The assumption here is that fwA-ip and fwB-ip are unique to each system. Note that once you've done this, all further '-n' putkeys you do must be to the same IP address (i.e. the argument to -n is the same) or your putkeys will break. I found this one out the hard way.

-- GuyR - 11 Jan 2004


FAQForm
FAQs.Class: RemoteManagementFAQs
FAQs.OS:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:55.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0