CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-27
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default cpconfig

Which of the following Options in cpconfig is used to "reset" the SIC on the firewall? Thanks.

Configuration Options:
----------------------
(1) Licenses
(2) Administrator
(3) GUI Clients
(4) SNMP Extension
(5) Group Permissions
(6) PKCS#11 Token
(7) Random Pool
(8) Certificate Authority
(9) Certificate's Fingerprint
(10) Enable Check Point SecureXL
(11) Automatic start of Check Point Products
__________________
Systems Engineer
Reply With Quote
  #2 (permalink)  
Old 2006-02-27
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: cpconfig

Can someone please reply to my question?
Many thanks in advance.
__________________
Systems Engineer
Reply With Quote
  #3 (permalink)  
Old 2006-02-27
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: cpconfig

What options are awalable inside (8) Certificate Authority?
Reply With Quote
  #4 (permalink)  
Old 2006-02-27
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: cpconfig

looks like that's a management install??

use fwm sic_reset from the command line
__________________
///M
Reply With Quote
  #5 (permalink)  
Old 2006-02-28
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: cpconfig

It's definitely a management install, the (3) GUI Clients gives this away for example.

I think it might be a standalone install though with that number of options. Is it a Nokia install by any chance?

Also 'fwm sic_reset' destroys the Internal Certificate Authority and therefore invalidates the certifciates (and SIC) for all modules.

It's not the way I would choose to do it, better off going to the enforcement module and running cpconfig there, before resetting/re-establishing in Smart Dashboard.

Out of interest, what was the original motivation for the question?
Reply With Quote
  #6 (permalink)  
Old 2006-02-28
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: cpconfig

I have 6 other firewalls at various sites across US would using fwm sic_reset cause issues with them? I wanted to add a new firewall at my current location and I was trying to bring that online. I wanted to reset the SIC because I forget the SIC that I had used on this Nokia IP710 firewall when I first built it.

I don't know the different with the management/standalone install. I am running IPSO 3.9 came preinstalled on this Nokia IP710.

Usually in the past when you run cpconfig, you have an option in the main menu for "Secure Internal Communication" which I can't find on here.

More help needed.
Thanks.
__________________
Systems Engineer
Reply With Quote
  #7 (permalink)  
Old 2006-02-28
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: cpconfig

This is the menu when I select Option 8

Enter your choice (1-12) :8

Configuring Certificate Authority...
====================================
The Internal CA is initialized with the following name: "firewallname"

Do you want to change it (y/n) [n] ?



************************************************** ************************************************** ****************
This is the menu when I select Option 7

Enter your choice (1-12) : 7

Configuring Random Pool...
==========================
You are now asked to perform a short random keystroke session.
The random data collected in this session will be used in
various cryptographic operations.

Please enter random text containing at least six different
characters. You will see the '*' symbol after keystrokes that
are too fast or too similar to preceding keystrokes. These
keystrokes will be ignored.

Please keep typing until you hear the beep and the bar is full.

[ ]
__________________
Systems Engineer
Reply With Quote
  #8 (permalink)  
Old 2006-02-28
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: cpconfig

Hi Humayun,

You don't have the option for 'Secure Internal Communication' via cpconfig when it is a managment install.

This is because it is typically reset at an enforcement module, then re-established using the GUI connected to the management server.

This is why I'm sure that you have a managment install or standalone (enforcement module and management on the same box). The fact that there is a Certificate Authority confirms this.

You may have to reconfigure the install if you only want this box to be an Enforcement Module only for example.

Don't issue the 'fwm sic_reset' command on the Management Server if you are managing multiple firewalls and do not want to reset SIC on all of them. Invoking this command will basically though up a warning text and y/n prompt which you should read and understand before accepting.

If you have one problem firewall, it's much better to go to the command prompt and run through the Secure Internal Communication command from cpconfig.

Hope that helps.
Reply With Quote
  #9 (permalink)  
Old 2006-03-01
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: cpconfig

right, well if you've got 6 remote firewalls then definately don't run fwm sic_reset :) will take a bit of un-needed work to get them all talking again..
i was assuming you had one local firewall enforcement point you could just re-establish sic with

reset sic on the enforcement..
__________________
///M
Reply With Quote
  #10 (permalink)  
Old 2006-03-01
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: cpconfig

This was just going to be a new firewall and I have a separate management server which we use to currently manage the 6 other firewalls. This came preinstalled with IPSO3.9 build 41 so I am assuming that I need to reinstall CP on this and make this only a firewall.


Thanks for your help guys.
__________________
Systems Engineer
Reply With Quote
  #11 (permalink)  
Old 2006-03-02
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: cpconfig

Thats correct, you will have to uninstall and reinstall CP to set it up as just a firewall.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0