CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-10
Junior Member
 
Join Date: 2005-11-10
Posts: 7
Rep Power: 0
jeepee has an average reputation (10+)
Default SIC name error when fetching after ngx upgrade on Win2003

We are in the process to upgrade our SmartCenter from NG to NGX.
We upgraded the Smartcenter Server to NGX (HFA-1 + Backward Compatibility package for R55 Gateway)
We are able to push new rules from SmartDashboard but when we want to fetch rules from the gateway(NG) using the "fw fetch" command we get the folowing error:

Management rejected fetch for this module - sic name does not match.


Gateway Config: Solaris 9 + HFA-12
Old SmartCenter: Win2000 SP4 Fully Patched + NG HFA-12
New SmartCenter: Win2003 SP1 Fully Patched + NGX HFA-01 + Backward Compatibility Package for R55 Gateway
GUI client: WinXP SP2 + NG HFA-1 + NGX with no HFA

Steps Taken:
1-SmartCenter:Upgraded lisences before upgrade from the "fetch from file" button in cpconfig interface
2-Cpstop on SmartCenter+used "upgrade_export.exe" from NGX CD-Rom
4-Configure new SmartCenter Server with new hardware new OS(Win2003Sp1) and the same IP than the old Server
5-Install NGX SmartCenter using "imported configuration" (Used upgrade tools from the CD)
6-Reboot+Install HFA-1+Install Backward Compatibility Package+Reboot
7-Start SmartDashBoard from GUI and push succefully rules
8-Login on gateway and try to fetch using "fw fetch" command and get the sic error
9-Reset sic on gateway using the cpconfig menu (See SK30579)-get the same error
10-Compared sic in registry (See SK30579) and its ok
11-Reset sic on the SmartCenter using "fwm sic_reset" command(See SK13176 + SK14532)-get the same error
13-Already tested upgrade with Smartcenter on WIn2000 SP4+NGX and it works fine. The problem seems only to be there when using imported configuration with a Win2003 Server SmartCenter
Reply With Quote
  #2 (permalink)  
Old 2005-11-10
Junior Member
 
Join Date: 2005-11-10
Posts: 7
Rep Power: 0
jeepee has an average reputation (10+)
Default Re: SIC name error when fetching after ngx upgrade on Win2003

Have tested theses configurations too:

Fresh Solaris 9 Install as a NGX Gateway + Fresh Win2003SP1 NGX SmartCenter with brand new rules --> No SIC error --> Then use "upgrade_import" to import our config and then the SIC error get back even if we reset sic on both sides.

We also got the same problem in the past when we tried to upgrade NG SmartCenter From NT4 to 2003 and finally Give up and only upgraded to Win2000

Last edited by jeepee; 2005-11-13 at 20:45.
Reply With Quote
  #3 (permalink)  
Old 2005-11-17
Junior Member
 
Join Date: 2005-11-10
Posts: 7
Rep Power: 0
jeepee has an average reputation (10+)
Default Re: SIC name error when fetching after ngx upgrade on Win2003

nobody have an idea?
Reply With Quote
  #4 (permalink)  
Old 2005-11-17
Member
 
Join Date: 2005-10-25
Location: North Brunswick, NJ
Posts: 38
Rep Power: 0
czech12 has an average reputation (10+)
Default Re: SIC name error when fetching after ngx upgrade on Win2003

Again, just a quick thought, but I noticed you said the new server had the same IP address. Did you make sure the name was the same? The Check Point CA is built from the hostname of the server. If that was not the same, there would definitely be SIC problems...
__________________
====================
Aaron Vivo
CCSE Plus, CCMSE, NSA
====================
Reply With Quote
  #5 (permalink)  
Old 2005-11-17
Junior Member
 
Join Date: 2005-11-10
Posts: 7
Rep Power: 0
jeepee has an average reputation (10+)
Default Re: SIC name error when fetching after ngx upgrade on Win2003

Yes, same name. And the SIC is ok in the registry of the gateway and the management.

I'm currently with CheckPoint for the issue but don't find anything at this moment.
Reply With Quote
  #6 (permalink)  
Old 2005-11-17
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: SIC name error when fetching after ngx upgrade on Win2003

My only thought would have been to do the sic_reset but you have already done that. Guess you could try doing the sic_reset and also resetting the SIC on the enforcement module at the same time.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0