CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-23
Junior Member
 
Join Date: 2007-08-29
Posts: 6
Rep Power: 0
vijukiran has an average reputation (10+)
Default SIC problem

hi friends,

this is the error i am getting when i try to reinitialise the SIC with one of our fw module on mgmt server.

"unable to contact certification authority on the management server,please make sure the certification authority daemon is running"

how to check whether this particular service is running or not and also i am not able reinitialise the CA as it is greyed out. pl send suggestions as i required to resert the SIC.

thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2007-10-23
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: SIC problem

You would only reinitialise the CA on the management server if last resort.
You have to strip out all of your VPN certs and SIC certs before it can be done which is why will be greyed out.

Perform a test communications with an established connection to another working gateway module and see what they says.

Is this a remote gateway that connects to across teh Internet using NAT, if so are there other working gateways with a similar working SIC. Test one of those and confirm.
Reply With Quote
  #3 (permalink)  
Old 2007-10-23
Junior Member
 
Join Date: 2007-08-29
Posts: 6
Rep Power: 0
vijukiran has an average reputation (10+)
Default Re: SIC problem

when i go to cluster gateway properties and click communication it gives the same error with the other fw module. autually these two fw modules in cluster.for your informaton this is not remote gateway. both the mgmt svr and enforement modules are directly connected through switch.

suggestions pl. thanks in advance
Reply With Quote
  #4 (permalink)  
Old 2007-10-23
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: SIC problem

The SMARTCenter should be listening on 18264 for the Cert Services. Check that can telnet on that port to the SMARTCenter. You will just get a blank screen and no response if successful.

What platform is the Mgmt on. Are you getting any logs from the gateways at the moment?
Reply With Quote
  #5 (permalink)  
Old 2007-10-24
Junior Member
 
Join Date: 2007-08-29
Posts: 6
Rep Power: 0
vijukiran has an average reputation (10+)
Default Re: SIC problem

I am not able to telnet on this port 18264 to the mgmt server from fw module and other way also.saying "connection refused". Logs are also not apperaing in smarttracker. mgmt server is running on win 2000 server.

suggestion pl. thanks in advance
Reply With Quote
  #6 (permalink)  
Old 2007-10-24
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: SIC problem

Has this ever worked? In-other words do you have an active policy on the firewall module.

As you could unload the policy and then re-establish SIC, NOTE: only do this if the box as the all@all policy installed. Other wise you will remove the installed policy already on the module. Not good if you lose all your VPN's ect.

Other wise worth a try,
Reply With Quote
  #7 (permalink)  
Old 2007-10-25
Junior Member
 
Join Date: 2007-08-29
Posts: 6
Rep Power: 0
vijukiran has an average reputation (10+)
Default Re: SIC problem

I have installed whole of the smartcentre software on a different machine and i made it as mgmt server.i have copied the conf and database folders from my previous installed smartcentre system and pasted in my new setup.i am able to login on smartcentre system and i am able to reset the SIC with fw module and it shows trust established. but when i test the SIC status. it is the giving the following error

SIC status for xxx.xxx.xxx not communicating
peer sent wrong DN:CN=xxx.xxx.xxx,O=xx.xxxxxx
**try to reset SIC at the peer and re-establish trust with peer**

suggestions pl.thanks in advance
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:33.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0