| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hello, I have a firewall that we noticed was not logging anymore, and has not been for some time now. After looking into it we noticed that SIC was no longer established. I plan to reset SIC on both sides but am wondering, does the cpstop/cpstart actually stop all traffic from passing or does it still allow traffic to pass but just does not filter it? I am wondering for customer impact reasons and whether or not it should be performed off hours. Thanks in advance for any help |
| |||
| Yes, a cpstop will stop all traffic. You can stack the commands to save time by separating them with a ; as in cpstop;cpstart <Enter> Does a SIC reset require a cpstop? I don't recall that it does. Are you sure it's not just an expired certificate on the firewall or management server? Having to do a SIC reset is not a common occurrence in a running firewall. Ray |
| |||
| thanks for the reply... I am pretty sure it needs SIC reset because when you look under communication it says "initialized but trust not established" I am also pretty sure that it performs a cpstop because this is what it says when I run the option #6 under cpconfig: This program will let you re-configure your Check Point products configuration. Configuration Options: ---------------------- (1) Licenses (2) SNMP Extension (3) Group Permissions (4) PKCS#11 Token (5) Random Pool (6) Secure Internal Communication (7) Enable cluster membership for this gateway (8) Enable Check Point SecureXL (9) Automatic start of Check Point Products (10) Exit Enter your choice (1-10) :6 Configuring Secure Internal Communication... ============================================ The Secure Internal Communication is used for authentication between Check Point components Trust State: Trust established Would you like re-initialize communication? (y/n) [n] ? y Note: The Secure Internal Communication will be reset now, and all Check Point Services will be stopped (cpstop). No communication will be possible until you reset and re-initialize the communication properly! |
![]() |
| Thread Tools | |
| Display Modes | |
| |