| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| getting SIC error 111 - unable to initialise sic as peer does not have a certificate.... anyone seen this before? I have re-initialised the CA on the manager but still the same. Running cp r55 on manager and firewall. thanks. |
| |||
| Try to debug - https://secureknowledge.checkpoint.c....do?id=sk30579 Very often mistakes from this SK article - "...Verify the SmartCenter Server's IP address and name are in the HOSTS file on the remote Gateway. NOTE: If the IP address of the SmartCenter Server uses static NAT, add the public IP address of the SmartCenter Server to the HOSTS file on the remote Gateway, to resolve to its hostname. Verify correct date and time on the operating systems. If the SmartCenter Server and remote Gateway reside in two different time zones, the remote Gateway may need to wait for the Certificate to become valid..." |
| |||
| Hi, I think this comes way too late but maybe someone will face this problem again somtime: If you connect the SmartCenter to a switchport in a VLAN and use VLANs on the enforcement module, you have to reduce the the MTU on the SmartCenter interface to 1496 Bytes. Otherwise, the 4-byte VLAN tag seems to disturb the certificate operation. |
| |||
| Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
| |