CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-15
Junior Member
 
Join Date: 2006-05-02
Posts: 24
Rep Power: 0
Steve has an average reputation (10+)
Default SIC error

getting SIC error 111 - unable to initialise sic as peer does not have a certificate....

anyone seen this before? I have re-initialised the CA on the manager but still the same.

Running cp r55 on manager and firewall.

thanks.
Reply With Quote
  #2 (permalink)  
Old 2006-05-15
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: SIC error

Try to debug - https://secureknowledge.checkpoint.c....do?id=sk30579

Very often mistakes from this SK article -
"...Verify the SmartCenter Server's IP address and name are in the HOSTS file on the remote Gateway.
NOTE: If the IP address of the SmartCenter Server uses static NAT, add the public IP address of the SmartCenter Server to the HOSTS file on the remote Gateway, to resolve to its hostname.

Verify correct date and time on the operating systems. If the SmartCenter Server and remote Gateway reside in two different time zones, the remote Gateway may need to wait for the Certificate to become valid..."
Reply With Quote
  #3 (permalink)  
Old 2006-05-15
Member
 
Join Date: 2006-01-20
Posts: 39
Rep Power: 0
bvanniekerk has an average reputation (10+)
Default Re: SIC error

Hi

You've checked hostname used in Internal CA is the same as Master in objects.C file?
Check if Internal CA generated has the fwm server name in ...;O=<fwm>;...
This shold also be in host file.

Rgrds
b
Reply With Quote
  #4 (permalink)  
Old 2006-09-15
Junior Member
 
Join Date: 2006-09-15
Posts: 1
Rep Power: 0
freinet has an average reputation (10+)
Default Re: SIC error

Hi, I think this comes way too late but maybe someone will face this problem again somtime:

If you connect the SmartCenter to a switchport in a VLAN and use VLANs on the enforcement module, you have to reduce the the MTU on the SmartCenter interface to 1496 Bytes. Otherwise, the 4-byte VLAN tag seems to disturb the certificate operation.
Reply With Quote
  #5 (permalink)  
Old 2007-07-26
Junior Member
 
Join Date: 2007-02-19
Posts: 6
Rep Power: 0
MorfiusX has an average reputation (10+)
Default Re: SIC error

Quote:
Originally Posted by freinet View Post
Hi, I think this comes way too late but maybe someone will face this problem again somtime:

If you connect the SmartCenter to a switchport in a VLAN and use VLANs on the enforcement module, you have to reduce the the MTU on the SmartCenter interface to 1496 Bytes. Otherwise, the 4-byte VLAN tag seems to disturb the certificate operation.
Just a note. I had a new system being set up in an on site environment. Once I got everything working, I moved the gateways to an off site data center. The SmartCenter machine stayed at the on site location. When I moved the gateways, I ran into the error above. Setting the MTU resolved the problem.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:29.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0