CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-03
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default fwm sic_reset impact ?

Hi,

Will executing the command

fwm sic_reset

On my manager have any immediate effect on my enforcement points ? I know i will need to restablish a trust with them but will it bring down any VPNs those enforcement points have active at the time ? Or any other effect ?

Thanks
Walcat
Reply With Quote
  #2 (permalink)  
Old 2007-09-03
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: fwm sic_reset impact ?

If you are using certificate-based VPNs, you will invalidate your certificates because you've blatted your certs. So you run the risk of losing authentication if a tunnel re-negotiates. I also believe that remote-access VPNs will have problems until you re-establish trust with the Gateway.

I wouldn't do the fwm sic_reset until you're absolutely sure its necessary. If you can, log a call with CP to validate that you have to do this first.
Reply With Quote
  #3 (permalink)  
Old 2007-09-04
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: fwm sic_reset impact ?

You should only do the fwm sic_reset command if no other choice. It really is a pain having to remove all of the VPN config from the policy, turn off the VPN on the gateways etc.

You then have to reenter all of the VPN config leading potentially to mistakes in incorrectly configuring the VPN again, and then having to push the policy, I also personally do a vpn tu and reset the tunnels once the policy push has been done to force the negotiation again.

It shouldn't affect existing connections, but you won't get new connections if memory serves me correctly.
Reply With Quote
  #4 (permalink)  
Old 2007-09-05
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default Re: fwm sic_reset impact ?

Thanks for the reply guys.

I am thinking i need to fo this because of the following, though if there is another way please shout out.

I recently created a new CP FW object but had the attatched error displayed when i clicked OK.

I also tried to view the certificate on the other enforcement points managed by the manager and got the error attatched.

I am at a loss as to how to resolve this hence i was going down the fwm sic_reset route, but to be honest didnt realise i would need to reconfig all the vpn stuff again.

Ideas anyone ?

Thanks
Attached Images
File Type: bmp certifcate - enforcement creation.bmp (7.5 KB, 191 views)
File Type: bmp certifcate when viewed.bmp (15.9 KB, 170 views)
Reply With Quote
  #5 (permalink)  
Old 2007-09-06
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: fwm sic_reset impact ?

When you get that sort of message then yes, I believe you will need to reset the CA on the SMARTCenter.

It requries you to delete all of the existing certificates that the CA has created, hence the need to remove the existing VPN config. If there are still certs then the fwm sic_reset won't work.
Reply With Quote
  #6 (permalink)  
Old 2007-09-06
manrag manrag is offline
Member
 
Join Date: 2007-05-31
Posts: 52
Rep Power: 2
manrag has an average reputation (10+)
Default Re: fwm sic_reset impact ?

If youre using simplified mode you will only have to get your gateways out of the communities, and disable VPN rules. After the fwm sic_reset just include the gateways in the communities and enable the rules.
Reply With Quote
  #7 (permalink)  
Old 2007-09-11
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default Re: fwm sic_reset impact ?

Thanks for the replies guys.

If i am not using certificates for the VPNs but shared secrets will this still effect the VPNS and will i still need to do things you have suggested ?

Thanks
Reply With Quote
  #8 (permalink)  
Old 2007-09-11
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: fwm sic_reset impact ?

Even if using pre-shared secret, when you enable VPN in general properties of the gateway then it will generate a certificate that needs to be deleted. This requires that the gateway not be used in any VPN configuration and that then the VPN tick box is unticked.
Reply With Quote
  #9 (permalink)  
Old 2008-01-17
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default Re: fwm sic_reset impact ?

Hi,

Well the fwm sic_reset went ok all enforcement points still working, logging and VPNs working fine.

But...The HA management has stopped working, the SIC is established, but the HA management fails with 'failed to synchonize, reason : failed to connect to the peer'

Any ideas ?

Thanks
Reply With Quote
  #10 (permalink)  
Old 2008-01-17
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: fwm sic_reset impact ?

You'll need to re-set the SIC between the Secondary and Primary SmartCenter servers. You may also need to perform a fwm sic_reset on the Secondary SC.
Reply With Quote
  #11 (permalink)  
Old 2008-01-20
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default Re: fwm sic_reset impact ?

If i test the SIC on the secondary servers object it comes back without issue, and says they are communicating ?

Do you still think it might need resetting ?

Thanks
Reply With Quote
  #12 (permalink)  
Old 2008-01-20
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: fwm sic_reset impact ?

I'd still do the reset. But you may want to log a support call with CP first.
Reply With Quote
  #13 (permalink)  
Old 2008-03-14
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 51
Rep Power: 3
walcat_0 has an average reputation (10+)
Default Re: fwm sic_reset impact ?

Well thought i 'd post an update.

Tried resetting the SIC on the secondary manager as suggested but this didnt work wither, still getting message 'Failed to connect to peer'

Again can see two comms on the snoop on the secondary manager between the two managers, but not working.

I have managed to fix it though after help from this site (thanks guys)....

Here's how

On secondary manager
1. CPSTOP
2. cd $FWDIR/conf/mgha
3. Remove or rename files in that directory
4. CPSTART

On the primary/active manager
1. In dashboard, policy----Management high availability
2. At this stage the staus was now 'Never syncd'
3. Performed manaual sync and worked first time both servers synd

Thanks for everyones help, hope this helps in the future
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0