CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-14
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Another urgent help!!!

Hi,

My NGX R60 Mgmt Console has stopped working since yesterday, the service just doesn't start as you can see from the output below:


[Expert@SecPlat_R60]# cpstart
cpstart: A file is missing or has been modified. For more details run `cphash -v`

[Expert@SecPlat_R60]# cphash -d -v cpstart
[ 10576 2002723488]@SecPlat_R60[14 Mar 11:13:54] is_initialized: new process or forked
[ 10576 2002723488]@SecPlat_R60[14 Mar 11:13:54] rand_add_seedfile: Failed to read seed
[ 10576 2002723488]@SecPlat_R60[14 Mar 11:13:54] fwrand_write_seed: Failed to read seed.
[ 10576 2002723488]@SecPlat_R60[14 Mar 11:13:54] fwrand_write_seed: Failed to write seed.
[ 10576 2002723488]@SecPlat_R60[14 Mar 11:13:54] verify_files: cpshared_filename failed

Have you guys already seen a problem like this ?

I've searched this problem in Checkpoint's Knowledge base but couldn't find anything, so I decided to install SPLAT on another machine and restore the backup I had.


Now I've installed Splat on another machine (different hardware) to RESTORE the .tgz file I have from the BACKUP of the problematic Smart Center Server. It brings me all the system configuration such as routes, crontab, users and interface configurations, but not the Rulebase and all the objects , which are the most important for me.

Do you know if the EXPORT or Upgrade_Export commands would be useful for me ? How do I use this tools ?



Thanks a lot !!

Robori
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #2 (permalink)  
Old 2007-03-14
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Another urgent help!!!

Quote:
Originally Posted by robori View Post
Have you guys already seen a problem like this ?
I have not.

Quote:
Originally Posted by robori View Post
Now I've installed Splat on another machine (different hardware) to RESTORE the .tgz file I have from the BACKUP of the problematic Smart Center Server. It brings me all the system configuration such as routes, crontab, users and interface configurations, but not the Rulebase and all the objects , which are the most important for me.

Do you know if the EXPORT or Upgrade_Export commands would be useful for me ? How do I use this tools ?
I would use the "backup" and "restore" functions. Be aware that when you run the "restore" it will tell you which files it will restore. There's two categories--system and checkpoint data (the second category is labeled wrong because I can't remember exactly what CP calls it). The Check Point data will NOT restore if you do not have IDENTICAL products installed. Run a sysconfig -> 10 (Product Installation) -> Next -> Accept License -> compare this list to the new hardware list.

Install identical products and re-run the restore.
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2007-03-14
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: Another urgent help!!!

Thanks for your comments!


Well, when you issue the RESTORE command there are two options to restore: System and Cp_products. Now I understand why the rules and objects weren't restored, that's because I could only select System. : (

I'm trying to select Cp_Products in the restore time, in the problematic box itself (in the Management Station which I can't "cpstart"), but it doesn't allow me to do so. It just lets me select SYSTEM. WHy is it ?


Thanks again
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #4 (permalink)  
Old 2007-03-14
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Another urgent help!!!

Quote:
Originally Posted by robori View Post
Well, when you issue the RESTORE command there are two options to restore: System and Cp_products. Now I understand why the rules and objects weren't restored, that's because I could only select System.
Yes, as far as I know, you can only restore CP Products if the restore utility detects that you have the same products installed.

Quote:
Originally Posted by robori View Post
I'm trying to select Cp_Products in the restore time, in the problematic box itself (in the Management Station which I can't "cpstart"), but it doesn't allow me to do so. It just lets me select SYSTEM. WHy is it ?
You need to verify that you have the same products installed as when you took the backup.

I don't recommend restoring to the problematic server unless you reinstall it. I'd suggest that you use your temporary server, use sysconfig to identify products installed on both servers.
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2007-03-14
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: Another urgent help!!!

Hmmm, okay.

I'm doing what you suggested right now, I'll let you know how it goes !!!



Thanks a lot !!!
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #6 (permalink)  
Old 2007-03-14
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: Another urgent help!!!

Thanks very much Melipla!!

I followed all the steps and it worked very well !!!! Both the system config and the firewall rulebase and all objects are in place now!!!

Wahooo !!!


Again, thanks a lot for your helpful hints !!!!

: )

Robori
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #7 (permalink)  
Old 2007-03-15
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: Another urgent help!!!

Now there's a little bit of a problem. I reinstaled SPLAT R60 NGX products on the same machine/hardware and used the RESTORE command. Now everything looks good, system settings, objects and rules, OK!

But in Smartview MOnitor every gateway is showing the UNTRUSTED status and I can't actually manage the firewalls or install policy.

I'd like to know how to re-stablish de SIC, I'm trying using cpconfig on the gateway and after that reseting on the firewall object on the SmartDashboard but it doesn't work.


Do you guys have a clue on what's the problem ?


Thank you!
Robori
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #8 (permalink)  
Old 2007-03-16
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Another urgent help!!!

Quote:
Originally Posted by robori View Post
But in Smartview MOnitor every gateway is showing the UNTRUSTED status and I can't actually manage the firewalls or install policy.

I'd like to know how to re-stablish de SIC, I'm trying using cpconfig on the gateway and after that reseting on the firewall object on the SmartDashboard but it doesn't work.
If you need to re-establish SIC, log into the remote gateway, run cpconfig select the SIC option and re-initialize the trust w/an activation key. Then on the SmartCenter server, open the object click on Communication button and click Reset, then type in your activation key and click initialize. If there are problems, it will display in this window, so save the output.

One thing to check, on the remote gateway run cpconfig, and select the SIC option, what does it say the "Trust State" is? Then check the Dashboard and see what the Trust State is listed as under communication.
__________________
Its all in the documentation.
Reply With Quote
  #9 (permalink)  
Old 2008-08-31
Junior Member
 
Join Date: 2008-02-14
Posts: 11
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Another urgent help!!!

Hi All Guru,
I have problem to set a SIC on the Firewall module and Smart centre server communication.

I did the following
1. through console cpconfig- SIC estabilished
2. Smart centre - on the Firewall module MY-fw1- communication - reset and initiate the SIC .
the following error occurs.
any solution to fixthe problem.

SIC Status for MY-fw1: Not Communicating

Peer does not have a certificate for SIC [error no. 111]

** Try to re-establish the trust **

When I install Policy on the MY-fw1- ERROR below.

Installation Targets Version Policy Type Details

MY-fw1 NGX R65 Advanced Security Installation failed.

Reason: Peer sent SIC name that is different than the one configured for it on SmartCenter Server try to reset SIC at the peer and re-establish the trust.



regards,
LEE
Reply With Quote
  #10 (permalink)  
Old 2008-09-01
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Another urgent help!!!

Double check that the name defined on the SMARTCenter Object for the Gateway is the same as that is defined as the hostname on the actual gateway and that on the gateway there is a localhost resolution for it's own name.
Reply With Quote
  #11 (permalink)  
Old 2008-09-01
Junior Member
 
Join Date: 2008-02-14
Posts: 11
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Another urgent help!!!

I checked both smartcenter and firewall module name are same.

Firewall module console : trust state: initialized but Trust was not established.

Smart center firewall object communication :- Trust state :-Trust estabilished


any other clue to fix this problem

regards,
LEE.
Reply With Quote
  #12 (permalink)  
Old 2008-09-01
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 268
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Another urgent help!!!

Lee,
try running fw unloadlocal on the gateway before trying to establish the trust, sometimes the local policy will disallow the trust to be established.
Regards, Maarten
Reply With Quote
  #13 (permalink)  
Old 2008-09-02
Junior Member
 
Join Date: 2008-02-14
Posts: 11
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Another urgent help!!!

Maarten,
did execute the command " Fw unloadlocal" and tried the SIC estabilsh. No joy.

same error on the smart center SIC status

"SIC Status for adc-fw1: Not Communicating

Peer does not have a certificate for SIC [error no. 111]

** Try to re-establish the trust ** "

the gateway module SIC status
"Initialized but Trust was not established"

after activate the key and exit the error message
"Reason: SIC Protocol Error [ SIC error no. 300 ].
Policy Fetch Failed
Failed to fetch policy from masters in masters file"


any clue to fix this problem.
LEE.
Reply With Quote
  #14 (permalink)  
Old 2008-09-03
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Another urgent help!!!

Quote:
Originally Posted by leekutti View Post

"SIC Status for adc-fw1: Not Communicating

Peer does not have a certificate for SIC [error no. 111]
In smartdashboard under the gateway object, do you have "VPN" checked in General Properties? [If you didn't, you have to click OK before the cert is generated] In the VPN section of the gw object, is there a certificate listed under "Repository of Certificates Available to the Gateway"?
__________________
Its all in the documentation.
Reply With Quote
  #15 (permalink)  
Old 2008-09-03
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 268
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Another urgent help!!!

make sure the host defenition on the gateway is properly set and the object has the same IP and name. then reset the sic and try again.

Regards, Maarten.
Reply With Quote
  #16 (permalink)  
Old 2008-09-04
Junior Member
 
Join Date: 2008-02-14
Posts: 11
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Another urgent help!!!

Hi there,

NOJOY.


Host name and the IP address are same on both smartcenter server and gateway module.

Smart center server - VPN option checked and the certificate is list under the "Repository of Certificates Available to the Gateway".

PS:- the gateway module had communication with smart center until I was established new SIC established on the gateway and Smart center. but the smart view tracker gate way Status was "UNTRUSTED".

this is some thing weird.

regards,
LEE.
Reply With Quote
  #17 (permalink)  
Old 2008-09-05
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Another urgent help!!!

Quote:
Originally Posted by leekutti View Post
SIC Status for MY-fw1: Not Communicating

Peer does not have a certificate for SIC [error no. 111]

** Try to re-establish the trust **

When I install Policy on the MY-fw1- ERROR below.

Installation Targets Version Policy Type Details

MY-fw1 NGX R65 Advanced Security Installation failed.

Reason: Peer sent SIC name that is different than the one configured for it on SmartCenter Server try to reset SIC at the peer and re-establish the trust.
I'm guessing you've never successfully established SIC with this gateway?

Can you verify that the traffic between the gateway and the smartcenter server is not being NATed?

Did you have any problems installing the gateway, say with the random pool or anything else?
__________________
Its all in the documentation.
Reply With Quote
  #18 (permalink)  
Old 2008-09-08
Junior Member
 
Join Date: 2008-02-14
Posts: 11
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Another urgent help!!!

Hi,
No NAT ing in between the Gateway and Smart centre server. It has connectivity until last week. when I found the " UNTRUSTED" mode on the Smartview monitor and establish the SIC, it lost connectivty it seems.
any clue .
PS :- Time - smartcentre and gate time are same.

Still no Joy.

regards,
LEE.
Reply With Quote
  #19 (permalink)  
Old 2008-09-09
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 268
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Another urgent help!!!

Lee,

Do you know if there are any changes in the path between the Gateway and the Smartcenter, try telnetting from the smartcenter to the remote firewall on the 18190 and 18191 ports.
normally the firewall should allow this connection. Make sure you run a fw monitor while doing so, then you can see if there is any traffic coming back.

I once had many problems like this with some WAN Accellerator box in between that was doing some caching and yes it chachjed the SIC packet.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #20 (permalink)  
Old 2008-09-09
Junior Member
 
Join Date: 2006-12-22
Posts: 16
Rep Power: 0
borek has an average reputation (10+)
Default Re: Another urgent help!!!

Once i had problem with establishing SIC. It was caused by the not running (seg faulting) cpd daemon.

Just to be sure check the main processes: cpwd_admin list

In my case i did restart (it was when the new 2.6 kernel splat was released) and it worked.

borek
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0