CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-18
Junior Member
 
Join Date: 2006-04-18
Posts: 1
Rep Power: 0
katmandu has an average reputation (10+)
Default Secondary mgmt console not synchronized

Hi guys,

I have built a 2nd management console according to checkpoint's documentation and followed all the steps.
I am now unable to sycnhronize the consoles, in the sunch screen it says in the "note" field "There is no CA DB".
Nat is working fine, I can install the user database onto both consoles, they both have host files with correct hosts. any ideas?

thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 2007-02-16
Junior Member
 
Join Date: 2007-01-22
Posts: 13
Rep Power: 0
zepperdude has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

I am getting this as well. Any ideas?
Reply With Quote
  #3 (permalink)  
Old 2007-02-17
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

There is sk26032 - "Error: "Failed to Synchronize me. Reason: Internal: Status NOT-OK. Error restoring CA DB" - https://secureknowledge.checkpoint.c...do?lid=sk26032
May be it's your case.
Reply With Quote
  #4 (permalink)  
Old 2007-02-19
Junior Member
 
Join Date: 2007-01-22
Posts: 13
Rep Power: 0
zepperdude has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

Can't see the article in SecureKnowledge - Still waiting for renewal of my support contract (mgmt red tape). Any additional info?

Last edited by zepperdude; 2007-02-19 at 07:51. Reason: more info
Reply With Quote
  #5 (permalink)  
Old 2007-02-19
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

This SK for FP3 HF2, but the idea is not bad, I think.
cpstop, then replace files on Secondary Management server from Primary Management server:
$FWDIR/conf/InternalCA.*
$FWDIR/conf/ica.*
Don't forget about backup.

Also confirm that files $FWDIR/conf/scheme.C are identical on both SmartCenter Servers.
Reply With Quote
  #6 (permalink)  
Old 2007-02-21
Junior Member
 
Join Date: 2007-01-22
Posts: 13
Rep Power: 0
zepperdude has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

tried - got rid of the CA NO DB error - but still doesn't sync.
Reply With Quote
  #7 (permalink)  
Old 2007-02-23
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

You can try to reinstall secondary smartcenter, for example on vmware server, and try to sync smartcenters for testing.
Reply With Quote
  #8 (permalink)  
Old 2007-02-23
Junior Member
 
Join Date: 2007-01-22
Posts: 13
Rep Power: 0
zepperdude has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

The new HFA_19 fixed the issue. Do not know what specific fix did it - but it now works!
Reply With Quote
  #9 (permalink)  
Old 2007-02-24
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

It's good.
There is only one fix in Release notes for HFA19.
"CP Management: Management High Availability
The move files protocol executed during the HA process releases a file descriptor when it unexpectedly terminates in the middle of forwarding files."
Reply With Quote
  #10 (permalink)  
Old 2007-02-27
Junior Member
 
Join Date: 2006-10-07
Posts: 24
Rep Power: 0
canghel has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

Same problem here:

Primary SmartCenter: NGX R61 (build 602000183)
Secondary SmartCenter: NGX 61 (build 602000183)

Cannot synchronize the two. Error message: "Failed to sychronize. Reason 'secondary_mgmt - Synchronization is not allowed when the SmartCenter Management Servers contain different Checkpoint products.'"

Checked installed software and it's the same on both servers.
Reply With Quote
  #11 (permalink)  
Old 2007-02-28
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

Quote:
Originally Posted by canghel View Post
Error message: "Failed to sychronize. Reason 'secondary_mgmt - Synchronization is not allowed when the SmartCenter Management Servers contain different Checkpoint products.'"
Which CP products did you install on both servers? Are they identical?
Did you ever install Eventia reporter on SmartCenter?
Reply With Quote
  #12 (permalink)  
Old 2007-02-28
Junior Member
 
Join Date: 2006-10-07
Posts: 24
Rep Power: 0
canghel has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

They are identical ...

SmartCenter (Primary / Secondary)
SmartConsole
Eventia Reporter add on

... but I noticed an extra line when running cpstart on the primary (see below in red):

cpstart: Starting product - SVN Foundation
The Check Point SVN Foundation service is starting.
The Check Point SVN Foundation service was started successfully.

cpstart: Starting product - VPN-1
The Check Point FireWall-1 service is starting.
The Check Point FireWall-1 service was started successfully.

cpstart: Starting product - SmartView Monitor
SmartView Monitor is disabled.

cpstart: Starting product - Eventia Reporter
Eventia Reporter SmartCenter Add-on running.

cpstart: Starting product - Edge Embedded Connector

Last edited by canghel; 2007-02-28 at 16:22.
Reply With Quote
  #13 (permalink)  
Old 2007-03-01
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

Did you install Reporter's add-on on Secondary SC?
Try next, replace $FWDIR/conf/scheme.C on Secondary SC from Primary. Don't forget to backup file before replace.
Reply With Quote
  #14 (permalink)  
Old 2007-09-19
Junior Member
 
Join Date: 2007-02-27
Posts: 3
Rep Power: 0
neela123456 has an average reputation (10+)
Default Re: Secondary mgmt console not synchronized

Hi
Can Any one please suggest Solution when Both SC are on Secure platform.
could not find Scheme.c in $FWDIR\conf

Thanks,
Neela
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:45.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0