CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-04
Junior Member
 
Join Date: 2005-10-04
Posts: 2
Rep Power: 0
Tenchi-Man has an average reputation (10+)
Default Managemnet HA Sync error

Hi,

Any idea about the R55 Management HA fails to synchronize with error "policy save Failed to merge the ICA DB. Possible security error!".

It works properly for over half a year before.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-01-17
Junior Member
 
Join Date: 2006-01-17
Posts: 1
Rep Power: 0
Simon Richardson has an average reputation (10+)
Default Re: Managemnet HA Sync error

hi,

I have a customer with the same error. Same version, on Windows 2003

The full error is

failed to syncronize
Reason: failed to merge the ICA DB. possible security error !!!

Its now showing as 'lagging' - logging is still going on on the secondary, and the SIC is still fine.

Again, this customer's has worked fine for over a year. All we did was try to troubleshoot an enforcement module that wasn't logging to the secondary smartcenter. we didn't change any of the policy per-se. We didn't edit the masters file on the enforcement module, just changed within the enforcement module object the 'order' of logging of the smartcenter servers, under the Logs and Masters tab of the SmartDashboard.

Logically this is an issue with the Internal CA of the Primary or Secondary getting out of sync, but I've tried copying from the Primary to the Secondary to

InternalCA.p12 and the InternalCA.NDB* files and InternalCA.crl file

I haven't yet looked to see if there's a /conf/crls/ICA_CRL0.crl file on the secondary or primary.

Any ideas as this is clearly something other people have come across but maybe not posted resolutions ?

cheers

Simon
Reply With Quote
  #3 (permalink)  
Old 2006-03-08
Senior Member
 
Join Date: 2006-03-08
Posts: 111
Rep Power: 3
varera has an average reputation (10+)
Default Re: Managemnet HA Sync error

please check the time setting for primary and secondary MGMT objects. they should have exactly the same time.
Reply With Quote
  #4 (permalink)  
Old 2006-06-14
Junior Member
 
Join Date: 2006-06-14
Posts: 2
Rep Power: 0
S-Express has an average reputation (10+)
Default Re: Managemnet HA Sync error ICA DB

I'm afraid I don't have anything to add apart from a "me too" response. I found this post using Google when our HA setup started having the same issue today.

I have verified the time setting between the servers and that's okay. I also had a trawl through the Checkpoint Secureknowledge page, and there is nothing applicable to this problem.

I'll investigate further using Simon's post as a starter, but thought it would be worth bumping this post to see if the other users have resolved this issue.

Thanks

Martin.
Reply With Quote
  #5 (permalink)  
Old 2006-06-15
Junior Member
 
Join Date: 2006-06-14
Posts: 2
Rep Power: 0
S-Express has an average reputation (10+)
Default Re: Managemnet HA Sync error

Well, I thought I'd have a stab at fixing it myself. I ended up copying over the /conf/InternalCA.* and /conf/ica.* files from the primary to the secondary. This has fixed my ICA DB sync error.
Reply With Quote
  #6 (permalink)  
Old 2006-06-19
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: Managemnet HA Sync error

What's the command to change the time?
__________________
Systems Engineer
Reply With Quote
  #7 (permalink)  
Old 2007-06-06
Junior Member
 
Join Date: 2006-07-13
Location: Georgia, US
Posts: 12
Rep Power: 0
gt2847c has an average reputation (10+)
Send a message via ICQ to gt2847c Send a message via AIM to gt2847c Send a message via Yahoo to gt2847c
Default Re: Managemnet HA Sync error

The recommended method is to use NTP for time sync. That makes sure that primary and backup stay in time sync. There are a number of public NTP servers out there if you don't have one internally. Googling for NTP servers or the US Naval observatory will net them for you. Time settings, NTP, and others can be set either by command line (non-expert) mode or through the web interface.


BTW, I'm grateful for the InternalCA.* files fix. I use NTP to keep my clocks set correctly as I have an internal pair of GPS based NTP servers, but time wasn't the issue. My secondary had been lagging for a few weeks which normally doesn't bother me much as one is in the US and the backup is in Europe, so they typically lag after a rule change/save. I just recently tried to force the sync to make sure all was well, but got the message about the ICA db being out and when I checked, the dates and sizes on the InternalCA file showed them to be quite out of date on the backup box.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:23.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0