CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-17
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Is there a way to set SIC through command line?

Hi, there,

I know that we can use command line to push policy,etc. but is there a way to set SIC through command line? That is, can "set SIC" be done on FW management station (SPLAT expert shell)?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 2007-10-17
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Is there a way to set SIC through command line?

Hi
run the command cpconfig.
then goto option 5 & 6.

you can reset the SIC from there.

Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-10-18
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

but you still need to reset sic on SmartDashboard, right? Can this step do-able by command line?
Reply With Quote
  #4 (permalink)  
Old 2007-10-18
Member
 
Join Date: 2006-11-03
Posts: 34
Rep Power: 0
inetd has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

cp_conf sic init <password>
Reply With Quote
  #5 (permalink)  
Old 2007-10-18
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

the command can be executed on each FW modules. But it cannot run on management:

"You cannot run sic cmds on this machine"

SIC has to be set on both modules and management, how to set it on management through command line?

Thanks.
Reply With Quote
  #6 (permalink)  
Old 2007-10-19
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Is there a way to set SIC through command line?

Hi
If you want to reset through the command line you can reset with the command #reset_sic.
then open the Smartdashboard, and check the SIC status there.

Regards
Ranjit
Reply With Quote
  #7 (permalink)  
Old 2007-10-19
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

Thanks for the reply. But that's exactly what I want to avoid, the GUI.

Is there a way to do reset SIC on both modules and management server through command line?
Reply With Quote
  #8 (permalink)  
Old 2007-10-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

Silly question but why are you trying so hard to avoid the Dashboard?

The Dashboard is the heart of the Check Point system and it's designed so that you do the configuration through the Dashboard. It isn't really designed to be driven through the command line. To use and get the most out of Check Point then you really should use the Dashboard.

From knowledgebase

SIC cannot be reinitialized through the command line on a SmartCenter Server installed machine. In order to establish or reinitialize the SIC for individual Security Gateways (firewall modules) that this SmartCenter Server is managing, attempt this through the Secure Internal Communication section in the General Properties of the network object representing the target firewall module.
Reply With Quote
  #9 (permalink)  
Old 2007-10-19
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Is there a way to set SIC through command line?

because I want to write a script to do the whole thing if possible :-)

I'm trying to avoid GUI because there's no easy way to do the GUI part...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:43.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0