CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 3/8, 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-29
Member
 
Join Date: 2006-08-21
Posts: 30
Rep Power: 0
usmanshaikh has an average reputation (10+)
Default Error connecting to Management server

Hi,

i am runnign CP R55 in a distributed environemnt...
I recently modified my GUI clients on the management server via 'ssh'ing to the box and rebooted the server..Since then I have not ben able to connect to the box via smart dashboard and gives the error message saying " make sure server is up and running and you are defined as a GUI client"
ssh to the box also fails now..however I verified that the modified GUI clinets exist by loggin on via console..

Any ideas as to what needs to be done now..An urgent reply will be appreciated

U
Reply With Quote
  #2 (permalink)  
Old 2006-09-29
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 1,649
Rep Power: 5
northlandboy has an average reputation (10+)
Default Re: Error connecting to Management server

If ssh is failing, then it's more likely a firewall policy issue than an issue with gui clients. There is no connection between ssh and gui clients.

When you connect with SmartDashboard, are you getting an immediate reject (GUI clients problem, or fwm not running) or a longer timeout (firewall problem).

What debugging have you done on the management server? cpstat mg, or anything like that? Logs?

Firewall logs?

tcpdump?

Any of the basics?
Reply With Quote
  #3 (permalink)  
Old 2006-09-29
Member
 
Join Date: 2006-08-21
Posts: 30
Rep Power: 0
usmanshaikh has an average reputation (10+)
Default Re: Error connecting to Management server

Hi,

Thanks for getting back on this...It was the firewall loading the local policy at boot time which is a reject by default..I had do a cpstart and then an unloadlocal and all seems to be ok now..I have disabled this option now via cpconfig...

>>When you connect with SmartDashboard, are you getting an immediate reject (GUI clients problem, or fwm not running) or a >>longer timeout (firewall problem).

Interesting to know.....Something new for me

Much appreciated

Usman
Reply With Quote
  #4 (permalink)  
Old 2006-09-29
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 1,649
Rep Power: 5
northlandboy has an average reputation (10+)
Default Re: Error connecting to Management server

It's pretty standard with Check Point when your default is drop, not reject. So if users say they are getting an immediate reject, then you know it's not a firewall problem. If they say it is timing out, then it's either a firewall or routing issue.

Sounds like you've got some misconfiguration going on - did you configure your management server as both management and enforcement, but it should only be management?
Reply With Quote
  #5 (permalink)  
Old 2006-10-02
Senior Member
 
Join Date: 2006-01-25
Posts: 1,314
Rep Power: 6
melipla has an average reputation (10+)
Default Re: Error connecting to Management server

Quote:
Originally Posted by northlandboy View Post
Sounds like you've got some misconfiguration going on - did you configure your management server as both management and enforcement, but it should only be management?
With R55W, doing an initial install, if you select "Smartcenter server" as a CP product, it automatically selects VPN-1/enforcement. You have no choice but to load the FW module in addition to the Smartcenter Server. I know this isn't the case in R60. I don't know how R55 behaves. Just a little FYI.
Reply With Quote
  #6 (permalink)  
Old 2006-10-19
Junior Member
 
Join Date: 2006-10-19
Posts: 9
Rep Power: 0
k0rruptuk has an average reputation (10+)
Default Re: Error connecting to Management server

Quote:
Originally Posted by usmanshaikh View Post
Hi,

I have disabled this option now via cpconfig...
Where abouts do you disable this? I have the same issue in that everytime my SmartCenter server is restarted I have to manually go in and do a fw unloadlocal
Reply With Quote
  #7 (permalink)  
Old 2006-10-19
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 564
Rep Power: 4
abusharif has an average reputation (10+)
Default Re: Error connecting to Management server

fw unloadlocal to temporaly disable (till next push or reboot or cprestart)
or
control_bootsec -r to remove the default policy from loading at all


To disable firewall module from management module:

cpprod_util FwIsFireWallModule
if output is 1 do:
cpprod_util FwSetFireWallModule 0

Last edited by abusharif; 2006-10-19 at 06:41.
Reply With Quote
  #8 (permalink)  
Old 2006-10-19
Junior Member
 
Join Date: 2006-10-19
Posts: 9
Rep Power: 0
k0rruptuk has an average reputation (10+)
Default Re: Error connecting to Management server

Thank you for the prompt answer!!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:07.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2