| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| How do you set up the GUI Client for a Nokia IP260 box, we have just purchased a new IP260 and can not find any options under the HTTP page to configure the GUI client, and when trying to access the box via SmartDashboard, it states thatv no GUI clients have been configured. Sorry this is not under the Nokia section but I do not have thre rights to post in thaT SECTION. |
| |||
| Sorry for hijacking this thread, but I'm having the same problem with an IP350 box running R55. When I run cpconfig, I get the following: Configuration Options: ---------------------- (1) Licenses (2) SNMP Extension (3) PKCS#11 Token (4) Random Pool (5) Secure Internal Communication (6) Enable cluster membership for this gateway (7) Enable Check Point SecureXL (8) Automatic start of Check Point Products (9) Exit Enter your choice (1-9) : I don't see any way to add a gui client or an administrative user. What am I missing here? Thanks, Shaun |
| |||
| Shaun, It looks like the appliance that you did the cpconfig on is not a management station, only a firewall. You define the GUI clients on the management station. If you wanted this appliance to be a management station, you will have to reinstall Check Point and select the proper choice for that. |
| |||
| Thanks for the info Lackie. The funny thing is that I now have all the packages supplied installed, and I have the same problem. Is a management station the same as a policy server? If I remember correctly, they're different things. Here's a list of the packages I have installed: Check Point VPN-1 NG with Application Intelligence (R55) for IPSO 3.8 (Sun May 2 22:37:33 IDT 2004 Build 541000584) /opt/CPfw1-R55p Check Point Policy Server NG with Application Intelligence (R55) for IPSO 3.8 (Mon Jan 5 13:49:41 IST 2004 Build 541000551) /opt/CPdtps-R55p Check Point FloodGate-1 NG with Application Intelligence (R55) for IPSO 3.8 (Tue Jan 6 16:16:53 IST 2004 Build 541000553) /opt/CPfg1-R55p Check Point CPinfo NG with Application Intelligence (R55) for IPSO 3.8 (Sun Nov 30 17:35:10 IST 2003 Build 541000522) /opt/CPinfo-R55p Check Point SmartView Reporter NG with Application Intelligence (R55) for IPSO 3.8 (Wed Jan 7 08:45:21 IST 2004 Build 541000551) /opt/CPrt-R55p Check Point SmartView Monitor NG with Application Intelligence (R55) for IPSO 3.8 (Thu Jan 1 12:38:12 IST 2004 Build 541000551) /opt/CPrtm-R55p Check Point SVN Foundation NG with Application Intelligence (R55) for IPSO 3.8 (Mon Mar 8 15:54:37 IST 2004 Build 541000577) /opt/CPshared-R55p Check Point UserAuthority Server NG with Application Intelligence (R55) for IPSO 3.8 (Wed Dec 31 18:30:18 IST 2003 Build 541000552) /opt/CPuag-R55p I still don't have an option to add an administrative user or a management station from cpconfig (it looks like this): Configuration Options: ---------------------- (1) Licenses (2) SNMP Extension (3) PKCS#11 Token (4) Random Pool (5) Secure Internal Communication (6) Enable cluster membership for this gateway (7) Automatic start of Check Point Products (8) Exit Enter your choice (1-8) : HELP! Shaun |
| |||
| While those packages are installed, the issue would be: are they On or Off? Is this a new or existing deployment? if it is new, I'd encourage you to look into doing this as distributed with your management server components installed on another piece of hardware (if you have it). Once the management components are installed, make sure the clocks synchronize to the same ntp source, and establish SIC -- you'll be all set. |
| |||
| Quote:
Is it possible to run the management server on the ip350? What issues does this create. Where do I get the wrapper to install this? Thx Shaun Last edited by Shaun Gallant; 2005-10-25 at 12:55. |
| |||
| You will have to turn off and delete all of the installed packages. Then reinstall Check Point. During the install (or during the first cpconfig), when you are given the options, make sure you install it as a managment station (I believe Check Point is now calling it a Smart Center Server). |
| |||
| I finally got Nokia on the phone and they told me the same thing. After a week of ripping out my hair, I actually have a functional firewall (although I still need to flesh out my policies). Thanks for everyone's help Shaun |
| |||
| I had the same problem running R55, the only difference is that I didn't install the box, so I didn't know what happened... I guess you have at least a GUI Client where you have the R55 Management set installed. Look up for the "Chekpoint Configuration" application, and there you have a "GUI Clients" tab.... |
| |||
| I would like to join to this thread, because I haven't found sollution for my problem. It's the same as in this thread, but with a little twist: the CP reinstall hadn't helped. My environment: Nokia IP265, IPSO 3.9, CPXP-SC5-500-NG(Check Point Express - VPN-1 Express Gateway SmartCenter Express for 5 Sites, Version: NGX) And my story: I'm a very rookie with CheckPoint. When I fisrt try to install the fw there was options in cpconfig for GUI clients, but there isn't any more. I get only that it's not a Smart Center Server. I've tried to remove and reinstall the CP via Voyager and CLI, but there is no question what type of fw will be the fw and what is the GUI client when start the cp first time after the CP's reinstall. (As far as I can remember it has asked if it is an express or pro version at the first time, and has asked for the GUI cilent's address). I've tried to reinstall the IPSO in the bootmanager, because I thought that, maybe there is a setting file in file system storing information what means that it's not a SmartCenter Server, and I wanted to overwrite or delete that file. Unfortunately it hasn't helped. I don't have a clue what to do. Could you give me some advice, please, even how I can clean the whole file system without causing demages? Csaba |
| |||
| When you install it, it will ask you if it's a smartcenter Server. If you don't select yes then it will only install the firewall portion of the package. Make sure on the installation that you select that it's a smartcenter server. |
| |||
| Thank You Lackie for your reply, but my problem is that there is no option to choose that it's a SmarCenter server as well. Here is what I have during the install. (It was a "clean" system, I have just reinstalled the IPSO package from Boot Manager before the test, so there wasn't any remained settings in the system, and after the IPSO reinstall I have just made the necessary settings onyly, and then I have installed the IPSO_wrapper_R60.tgz package (58377KByte)): End of new package installation cleaning up ..done A reboot may be necessary to activate packages. ************************************************** *********************** *******************INSTALL/UPGRADE PROCESS COMPLETED********************* Please do the following if the INSTALL/UPGRADE is Successful: 1) Logout and re-login. 2) Run 'cpconfig' and configure the firewall. 3) Install the new License if required. 4) Reboot the box. *******************INSTALL/UPGRADE PROCESS COMPLETED********************* ************************************************** ********************** (Here was a log off and log in.) hu-budfw001[admin]# cpconfig Welcome to Check Point Configuration Program ================================================= Please read the following license agreement. Hit 'ENTER' to continue... . . . Do you accept all the terms of this license agreement (y/n) ? y Is this a Dynamically Assigned IP Address gateway installation ? (y/n) [n] ? Would you like to install a Check Point clustering product (CPHA, CPLS or State Synchronization)? (y/n) [n] ? IP forwarding disabled Hardening OS Security: IP forwarding will be disabled during boot. Generating default filter Default Filter installed Hardening OS Security: Default Filter will be applied during boot. This program will guide you through several steps where you will define your Check Point products configuration. At any later time, you can reconfigure these parameters by running cpconfig Configuring Licenses... ======================= Host Expiration Signature Features Note: The recommended way of managing licenses is using SmartUpdate. cpconfig can be used to manage local licenses only on this machine. Do you want to add licenses (y/n) [y] ? |
| |||
| Fodorcs, The Nokia IP265 is a flash-based piece of hardware and Checkpoint have developed a specific version of NGX for this hardware. VPN-1 Pro/Express Package for IPSO 3.9 / 4.0 for Flash based platforms You will need a logon to the CP User Centre to download this IPSO wrapper. Afaik, I am not sure that the IP265 can support runnning the enforcement module AND the manangement server on the same unit. I have an IP385 (flash-based) running the firewall and a Windows 2003 Server running the management server side of things. I'm sure someone with an IP265 can either confirm this or tell you that I am talking rubbish! lol |
| |||
| Thank You, I have tried the IP265 Flash based system specific package as well, but with the same result. The strange part of my story I had the option to choose if the appliance is a standalone device and is hosting the SmartCenter Server as well. Unfotunately I had known more less than now about that things, and choosed the wrong option. Its possible that it's a feature, I don't know why our reseller has not mentioned it. It wasn't a nice from them. So, finally I have ordered the CD with the Windows versions of the programs, and I will try it. Can I use our present license to use the Windows version of the SmartCenter Server? |
![]() |
| Thread Tools | |
| Display Modes | |
| |