CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-10
Junior Member
 
Join Date: 2007-08-31
Posts: 3
Rep Power: 0
Packet has an average reputation (10+)
Default Resetting SIC on reboot (with Mgmt server as Vmware guest) NGX R65

This is a scenario I'm playing with and I got it working mostly.

Scenario: NGX R65 as enforcement only module with DAIP on Windows 2003 SP2.
Mgmt server NGX R65 on Windows 2003 SP2 running in a Vmware session on same machine.
Everything (except VPN) works just fine - hide nat for the mgmt server to get windows updates as needed and for another internal network to get out as hide nat, etc. so the connectivity between the mgmt server and the enforcement module is all good.

however, i've noticed that on rebooting the physical machine (and a clean/normal shutdown and reboot of the vmware session as well), SIC stays established - shows 'SIC established' but on testing SIC status, i get an unable to resolve object ip. (cant recall exact error, but basically it cant resolve the ip of the module)
so, cant push a new policy at that moment either because it cant resolve the object.
cpstop/cpstart on both vmware mgmt server and DAIP enforcement module doesnt do anything.
From trial and error, i found out that if i reset SIC status between the two and specify the current ip obtained via DHCP (on the DAIP), SIC status is good and it stays fine, can push policies, et all.
Until the next reboot...

Is there a simpler way to do this rather than having to reset SIC status each reboot?
Reply With Quote
  #2 (permalink)  
Old 2007-09-11
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 247
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Resetting SIC on reboot (with Mgmt server as Vmware guest) NGX R65

You already wrote the answer yourself.
Reply With Quote
  #3 (permalink)  
Old 2007-09-12
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Resetting SIC on reboot (with Mgmt server as Vmware guest) NGX R65

Why not define the gateway object with it's internal IP object. That way then the object can be resolved and a policy pushed.
Reply With Quote
  #4 (permalink)  
Old 2007-09-12
Junior Member
 
Join Date: 2007-08-31
Posts: 3
Rep Power: 0
Packet has an average reputation (10+)
Default Re: Resetting SIC on reboot (with Mgmt server as Vmware guest) NGX R65

dantro: thanks for confirming - but some kinda cmd line/scriptable/automated thing would be ideal - if you know of any.

mcnallym: not sure about that, honestly.
when i installed the enforcement module as part of the checkpoint install on the host, it asked me if an interface was DAIP and i chose 'yes' to that.

i just tried adding a new gateway object - now i might be doing something wrong here, but it seems to me that i cant define any interface properties to be dhcp enabled if i dont choose the checkbox next to 'dynamic address' in 'general properties' (side-effect of dynamic address is that the 'remote access' etc settings disappear - which is the next battle coz i wanted a client to site vpn)

now whether this is due to the fact that i had chosen DAIP when i first installed the said enforcement module, i dont know for sure.

seems to be that if a static address is defined in the 'general properties' page, it will not allow any other interface to be set to dhcp/dynamic.
atleast that's how it appears to me in the topology section.
as ever, open to all suggestions.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:17.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0