CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-23
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Management HA: can't synch

Hi,
I'm currently getting alerts as to my secondary Smart Center Server can't synch with the main one.

23Jul2007 2:09:25 accept SERVER A< mail ObjectName: SERVER B; Operation: Synchronize Peer; Administrator: localhost; Machine: localhost; Subject: Management HA; Audit Status: Failure; Additional Info: Type: automatic, event: SCS-SYNCH. Error: Synchronization is not allowed: No license. Peer's mode: standby, status: Lagging.; Operation Number: 26; product: SmartCenter Server;

I resetted the License last Wednesday with a valid no expiration one from Checkpoint directly and SmartUpdate takes it perfectly.
Reply With Quote
  #2 (permalink)  
Old 2007-07-23
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 278
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Management HA: can't synch

The license must be attached to the secondary SmartCenter via SmartUpdate (or manually). The most frequent mistake with licensing an HA SmartCenter is that the license must be for the IP of the Seconday server, not the primary.

Unlike most centrally managed licenses, that IP must be for the secondary server.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-07-23
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

Lammbo, thanks for the response


The licence on the 2ndary management server does INDEED have a central licence with its OWN IP address...


any other ideas? :)
Reply With Quote
  #4 (permalink)  
Old 2007-07-23
david david is offline
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Management HA: can't synch

Is it a HA license?
I had a similar problem a couple of years ago with NG FP3 & it turned out that the smart center license wasn't enabled for HA.
Reply With Quote
  #5 (permalink)  
Old 2007-07-23
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 278
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Management HA: can't synch

Do you also have the HA license (attached to Primary)?

Are the EXCACT same components installed on both servers?
Example - I once had Eventia Reporter installed on my Primary, but not my secondary - HA failed and no more synching until I made them identical.

There was a file I even had to edit once I uninstalled Reporter to make it work again... If you have similar issues, look at sk31109 and sk31219 for the answers.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #6 (permalink)  
Old 2007-07-23
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

Yeah the Primary HA has the ultimate licence that contains the HA module

The secondary HA also has the valid license, I double checked.

I also checked and

Primary HA:
(internal non-routable IP)
Log Server
SVN Foundation
Primary Log Server

Secondary HA:
(External routable IP)
Log Server
SVN Foundation
Secondary Log Server


I don't know what else to try at this point
Reply With Quote
  #7 (permalink)  
Old 2007-07-23
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Management HA: can't synch

Please post a cplic print from both of the system (hiding the IP addresses). I suspect you do not have:

A. The same license features on both systems
B. Do not have Management HA
C. Managed to put the same license (cert key) on both system.
Reply With Quote
  #8 (permalink)  
Old 2007-07-24
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 278
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Management HA: can't synch

Ditto to chillyjim's post.

If you look and you truly believe that your licensing is correct and HA is setup correctly, get CP to generate a few 30 day temp licenses and apply 1 to each of your management servers. This will absolutely rule out any licensing issues.

Obviously, if it still doesn't work with a temp on each SmartCenter, you have config issues.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #9 (permalink)  
Old 2007-07-24
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

Hi,

Here are the exports:

Main module (active)

[Expert@******]# cplic print
Host Expiration Features
[Non-Rout IP] never CPMP-VPG-XL-NGX CPVP-VPS-1-NGX CK-CEB9*****5B7
[Non-Rout IP] never CPMP-SCPRO-U-NGX CK-CEB9F*****B7


Secondary:
[Expert@*********]# cplic print
Host Expiration Features
[Routable IP] never CPMP-SCPRO-U-NGX CK-56EB9****6D5
Reply With Quote
  #10 (permalink)  
Old 2007-07-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Management HA: can't synch

Okay you win...

I would try to remove and replace the license from the command line.
Make sure the secondary SMC can reach the primary.
Call support.

The CPMP-SCPRO-NGX does include management HA so that shouldn't be an issue.

Did this ever work?
Reply With Quote
  #11 (permalink)  
Old 2007-07-26
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

Quote:
Originally Posted by chillyjim View Post
Okay you win...

I would try to remove and replace the license from the command line.
Make sure the secondary SMC can reach the primary.
Call support.

The CPMP-SCPRO-NGX does include management HA so that shouldn't be an issue.

Did this ever work?
it never did actually...but I"ll try what you guys suggested again with a EVAL just to rule out every possible cause

Thanks for the help btw
Reply With Quote
  #12 (permalink)  
Old 2007-08-08
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

EVAL didn't do the trick either...

Checkpoint Support asked me to rebuild the secondary management server...

we'll see if this works
Reply With Quote
  #13 (permalink)  
Old 2007-08-08
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 161
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Management HA: can't synch

well

I've rebuilt the server with the exact same licenses..and guess what it works!

Thanks all
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0