CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-21
Peter Smith Peter Smith is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 14
Rep Power: 0
Peter Smith has an average reputation (10+)
Default sychronisation issues

I have just changed the IP address of my primary SCS which has worked OK (after much trying!)
Does anyone know how I can get my secondary SCS to sync with the primary at the primary's new address? I'm guessing I have to reinstall the chekcpoint software on the secondary SCS. Any help would be greatly appreciated

(I have tried reinstalling the checkpoint software on the secondary SCS. I can sync OK with the primary, but if I then fail over to the secondary SCS and try to sync with the enforcement modules from the secondary SCS I get "internal SSL" errors even though the clocks are the same on the primary and secondary SCS's. I've tried resetting the clocks on the primary and secondary SCS's and re-establishing sic between the primary and secondary SCS's. I can sychronise OK but get the same "internal SSL" errors when trying to push policies from the secondary)
Reply With Quote
  #2 (permalink)  
Old 2008-02-22
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,030
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: sychronisation issues

I would ask if the SCS was installed after the SIC was established to the gateways. I would hazard a guess and say that it was.

With the SCS installed, resic the gateways with the Primary. The problem I believe is that the gateways SIC doesn't know about tge SCS box so won't accept the connection from it.

Just try with one box first and see what happens.
Reply With Quote
  #3 (permalink)  
Old 2008-02-22
chuachongchee chuachongchee is offline
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 157
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: sychronisation issues

Quote:
Originally Posted by mcnallym View Post
I would ask if the SCS was installed after the SIC was established to the gateways. I would hazard a guess and say that it was.

With the SCS installed, resic the gateways with the Primary. The problem I believe is that the gateways SIC doesn't know about tge SCS box so won't accept the connection from it.

Just try with one box first and see what happens.
If sync works ok, try to do a manual install of scs database... go to
Policy > Install Database

Try that if it works..
Reply With Quote
  #4 (permalink)  
Old 2008-02-23
Peter Smith Peter Smith is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 14
Rep Power: 0
Peter Smith has an average reputation (10+)
Default Re: sychronisation issues

thanks for your reply guys. I shall try this. Nice to hear from you again Mike!!
Reply With Quote
  #5 (permalink)  
Old 2008-02-27
Peter Smith Peter Smith is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 14
Rep Power: 0
Peter Smith has an average reputation (10+)
Default Re: sychronisation issues

Yes that worked fine, thanks again. Basically if you rebuild the secondary scs you can't sic from the secondary scs to an enforcement module until you've sic'd from the primary to he secondary and then re-sic'd from the primary to the enforcement module.

I wonder why the error message talked about clock settings?
Reply With Quote
  #6 (permalink)  
Old 2008-02-27
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 495
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: sychronisation issues

Most likely because the Secondary Management had a SIC certificate that was created earlier than the Primary (and is therefore invalid).

Or it could just be a generic error, because this is the most common mistake ppl make with this.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:20.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0