CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-11
stacy99 stacy99 is offline
Junior Member
 
Join Date: 2006-11-13
Posts: 10
Rep Power: 0
stacy99 has an average reputation (10+)
Default 'fw stat x.x.x.x' from smartcentre failing.

I have a solaris manager (2 in HA), managing 10 nokia's...

From the manager when I run 'fw stat x.x.x.x' (IP of enforcement point) I usually get the name of the current policy and install date for that firewall.

eg.

HOST POLICY DATE
172.x.x.x polcy-071123-sb 30Nov2007 14:42:21 : [>eth-s3p2c0] [<eth-s3p2c0] [>eth-s1/s1p1c0] [<eth-s1/s1p1c0] [>eth-s3p3c0] [<eth-s3p3c0]

HOWEVER, from one particular firewall, which currently has a working SIC connection, verified by pushing policies to it from the manager, and testing SIC through SmartDashboard. When running the same command as above but for this firewalls IP I get the following:

HOST POLICY DATE
There is no SIC to 172.24.107.248

I am currently unable to reset SIC due to the downtime involved but need the fw stat command from the manager to reflect the true status of the firewall.

Due to the sensitive nature of these firewalls I'm unable to troubleshoot the problem (unable to reboot, cpstop/cpstart, or reset SIC) as the firewall is currently active at the moment but would be keen to hear if anyones seen this before and what the fix was.

cheers,

Stacy
Reply With Quote
  #2 (permalink)  
Old 2007-12-11
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 850
Rep Power: 3
melipla has an average reputation (10+)
Default Re: 'fw stat x.x.x.x' from smartcentre failing.

I've found that using "fw stat <ip>" works only for the IP address listed under the General Properties. Using IPs from other interfaces of the same gateway reports "There is no SIC".

Otherwise a "cpinfo" executed locally on the firewall should tell you the information you require. You could check SmartView Monitor in the off chance that it has it as well.
Reply With Quote
  #3 (permalink)  
Old 2007-12-12
stacy99 stacy99 is offline
Junior Member
 
Join Date: 2006-11-13
Posts: 10
Rep Power: 0
stacy99 has an average reputation (10+)
Default Re: 'fw stat x.x.x.x' from smartcentre failing.

I have now found that 'cpstat -h <ip> fw' works succesfully but 'fw stat <ip>' says "There is no SIC to <IP>"

The IP I'm using is the one in the General Properties for the firewall.

Anymore ideas?

Stacy
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:52.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0