CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-24
jemma_noor jemma_noor is offline
Junior Member
 
Join Date: 2005-12-08
Posts: 19
Rep Power: 0
jemma_noor has an average reputation (10+)
Default Unable to connect to second Gateway

Hello,

We've installed and cofigured a second NOkia box (ip350) as an enforcement module. The first box (ip330) is set up as a SmartCentre server and enforcement module.

We are now trying to add and push the license from ip330 smartcentre server to IP350 but receive repeated error messages along the line of Sic status not established.

We use 'local' licensing on ip330 and checkpoint ng fp3 on both boxes.

What we'd like is to manage both boxes from a single smartcentre server, although each device is situated at a different site but will be connected to each other over the LAN.

It could be that we need to install smartcentre server on ip350 and then create a gway node on the ip330?

Any suggestions would be welcomed.

Thank you.
Reply With Quote
  #2 (permalink)  
Old 2006-01-24
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Unable to connect to second Gateway

The way you have it set up should work. Have you established SIC between the IP330 and the IP350?
Reply With Quote
  #3 (permalink)  
Old 2006-01-25
jemma_noor jemma_noor is offline
Junior Member
 
Join Date: 2005-12-08
Posts: 19
Rep Power: 0
jemma_noor has an average reputation (10+)
Default Re: Unable to connect to second Gateway

Yes, that's what I thought. But when installing the Enforcement module on the second box, I am asked for an Activation Code - What is this? The sic state is uninitialised at this stage.

I type the admin password of the first box but still fail to authenticate via Sic.

Any other suggestions before I resort to installing both the module and smartcenter on the second box?

Thank you.
Reply With Quote
  #4 (permalink)  
Old 2006-01-25
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Unable to connect to second Gateway

The activation is the SIC password. You have to put that on the firewall and when you set SIC for that object in the management station you use that activation code, not the admin password.
Reply With Quote
  #5 (permalink)  
Old 2006-01-26
jemma_noor jemma_noor is offline
Junior Member
 
Join Date: 2005-12-08
Posts: 19
Rep Power: 0
jemma_noor has an average reputation (10+)
Default Re: Unable to connect to second Gateway

Thanks for the reply 'Lackie'.

Unfortunately I don't know where the SiC/Activation code is on the existing firewall/smartcentre server - both fwall module and smartcentre run off the IP330.

Any suggestions?

Thank you.
Reply With Quote
  #6 (permalink)  
Old 2006-01-26
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Unable to connect to second Gateway

You don't need to know the SIC password for the current firewall (IP330) as there will not be one because the Management station does not need one to connect to itself.

You have to specify the 'one time password' on the new firewall. If you have not already done it or if you don't know it you can redefine it in cpconfig on the firewall.

Once you have that established, In dashboard, you go into the object for that firewall and into the 'Communication' section/button. This is where you put that same 'one time password' in for that firewall.

This will establish SIC between the Management station and the new firewall.
Reply With Quote
  #7 (permalink)  
Old 2006-01-27
jemma_noor jemma_noor is offline
Junior Member
 
Join Date: 2005-12-08
Posts: 19
Rep Power: 0
jemma_noor has an average reputation (10+)
Default Re: Unable to connect to second Gateway

Hi again,

Yes, this is exactly what I have tried. The error reported when initialising the sic is
"SIC Status for fwall1: Unknown

Failed to connect to peer

** Check that peer is running **".

And the Trust stat in the communication box is "Initialized but trust not established".
Reply With Quote
  #8 (permalink)  
Old 2006-01-27
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Unable to connect to second Gateway

Check to see if there is a policy loaded on the firewall. If there is, unload it and try testing the SIC again. If that doesn't work, follow the below:

On the new firewall, run 'cpconfig' and select Secure Internal Communcation. Reset the 'one time password' on the Nokia. When you exit cpconfig it will run a cpstop and cpstart. Because you have changed the SIC password on the appliance now, it will load the default policy that will block all connections. Unload this policy with 'fw unloadlocal'. You will need to have console access to the appliance to run this command. Once the policy is unloaded go into Dashboard and open up the object. Go into the Communication button and select Reset. Put in the same one time password in the spaces provide and select Initialize. This should be enough to reset SIC.

If that doesn't work then you may have a problem with the install on the firewall.
Reply With Quote
  #9 (permalink)  
Old 2006-01-27
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Unable to connect to second Gateway

Add to previous message, if I may

May be you need to install policy to the old module before sic will be establish and after new firewall object was created.

If you want to see additional information about connections try to run on new module
fw monitor -e "accept src=ip_address_managment or dst=ip_address_managmnet;"

Last edited by kva.kva; 2006-01-27 at 12:44.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:56.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0