CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-30
Junior Member
 
Join Date: 2007-03-29
Posts: 3
Rep Power: 0
GavinC has an average reputation (10+)
Default Policy installation fails

Hi All,

I'm new to this forum so was wondering if anyone can help me with an issue I'm experiancing.
I have a SPLAT smartcenter NGXR60 HFA_05 with a Nokia IP330 NGX R60 HFA_05

When I try to install the policy I get the following message:-
Load on Module failed - failed to load Security Policy

From the Nokia if I run the fw fetch command it attempts to fetch the policy but then errors with the following:-
"/opt/CPsuite-R60/fw1/state/__tmp/FW1/local.ft" line 65 duplicate entry in table...
No matter what I try I always get this error. Any help would be much appreciated as it is extremly urgent as currently we cannot apply new policies to our live firewall.
Regards,
Gavin
Reply With Quote
  #2 (permalink)  
Old 2007-03-30
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Policy installation fails

Quote:
I have a SPLAT smartcenter NGXR60 HFA_05 with a Nokia IP330 NGX R60 HFA_05
I don't think you can run NGX on IP330, it only has 64 MB RAM. My recommendation is to get yourself a halfway decent PC or server, install a 2 or 4-port NIC (or several if needed) and run SPLAT on your gateway also - ditch the Nokia box, it's too old and non-upgradable.

Check for SPLAT compatibility:
http://www.checkpoint.com/products/s...ngx/index.html
http://www.checkpoint.com/products/s...ting_tool.html

Quote:
When I try to install the policy I get the following message:-
Load on Module failed - failed to load Security Policy

From the Nokia if I run the fw fetch command it attempts to fetch the policy but then errors with the following:-
"/opt/CPsuite-R60/fw1/state/__tmp/FW1/local.ft" line 65 duplicate entry in table...
No matter what I try I always get this error. Any help would be much appreciated as it is extremly urgent as currently we cannot apply new policies to our live firewall.
This one is trickier and the last time I saw this, it was because of AUTO-NAT. I had a similar issue when I recently turned on a Smart Defense setting for DNS Cache Poisoning protection.

Do you use auto-NAT?
If so, do you have anything like this:
host: HOST1 (has internal IP and AUTO-NAT IP)
host: NAT_HOST1 (has only the external IP for the same host above?)

Since my NGX was upgraded from an older version, I had this type of host situation and that is what caused the same scenario you describe for me. I only had the 2 DNS servers that caused the issue ONLY BECAUSE of SmartDefense, but hundreds of the NAT paired objects have existed in my db for well over a year without issue until then. It played hell with my state table on HA firewalls and I got the same error message and symptoms.

Your issue could be solely the inadequate Nokia hardware, but here is the case summary of my issue:
-----------------------------
With the article regarding the duplicate entries pointing to NAT as an issue, I thought that there might be an issue with how SmartDefense was implementing the DNS protection with an object that has automatic NAT enabled. John made mention of the fact that he also has objects that specifies the public IP address of the DNS servers and that he was really only trying to implement the protection. It turns out that, even though he had unchecked "DNS server" from each of the objects, the change wasn't taking. The change only took if John unchecked the automatic NAT (to get rid of the relationship between the objects), unchecked DNS server on the manual NAT object (opening it up again to verify and make sure that it would take effect), unchecked DNS server on the original private IP objects for the DNS servers, and then re-enabled automatic NAT (since it had been enabled and working prior to the new changes). After making all those changes and saving policy, the DNS servers no longer showed up in the SmartDefense protection and John was able to push policy. The long and short of it is that the firewalls were checking for this duplicate object relationship in the inspect code (thus the errors) whereas the SmartCenter was not (no errors).
----------------------------
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-04-02
Junior Member
 
Join Date: 2007-03-29
Posts: 3
Rep Power: 0
GavinC has an average reputation (10+)
Default Re: Policy installation fails

Hi Thanks for the response,
I have now resolved the issue, while it was exactly the same resoloution as yours, the advice you gave pointed me in the right direction.
Basically I had defined two hosts as web servers to be protected by web defense with the same IP address... Typo on my part...
Thanks again for your reply it has helped me resolve a very urgent issue.

Best Regards,

Gavin
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0