CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-23
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Can't connect to FW with SmartDashboard

When I try to login to the SMartDashboard from my desktop I get this error:

"Connection cannot be initiated. Make sure the server is up and running."

I have also tried connecting from another machine withe Smart client loaded and I get nothing. I have checked the allowable IPs in cpconfig and they are all correct. The firewall is still passing traffic fine, I just can't get to it to manage it anymore. I've tried unloading the policy from the firewall but it still won't let me connect. The last thing I did before it stopped working is a put a rule above the stealth rule(as in it's the very first rule) that implicitly allowed me to telnet from my workstation to the solaris box the firewall is running on. I assume it must have something to do with that....? Any ideas would be greatly appreciated.

Thanks!
Reply With Quote
  #2 (permalink)  
Old 2007-11-24
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Can't connect to FW with SmartDashboard

Hi
I have faced the same problem when generally running a SPLAT.
Then what I do...I reset the SIC and then access the Smartcenter and then create a rule on the top to accept CPMI(18190/tcp)connections from my smartdashboard console ie IP.And after that it works fine.
Source:my IP
Destination:Firewall
Service :CPMI

You can try this.

Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-11-26
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Thanks for the suggestion Ranjit...I did that and still now luck... :-(
Reply With Quote
  #4 (permalink)  
Old 2007-11-26
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 164
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

hi Speedtre,

Can you confirm if you have Standalone of distribute setup?

if distribute can you explain the layout ie. where the Mgmt is located to the firewall module.

cheers
Dan
Reply With Quote
  #5 (permalink)  
Old 2007-11-26
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
I've tried unloading the policy from the firewall but it still won't let me connect.
So you ran "fw unloadlocal" on the firewall and you still cannot get connected?

That specifically allows management connections. Are you trying to connect to the internal IP of the firewall or the external IP?

Do you have the implied rules enabled for management connections?

You could always try allowing all IP's to connect to the firewall for management and see what happens. There may be a NAT rule or something getting in the way.

Ray
Reply With Quote
  #6 (permalink)  
Old 2007-11-27
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
Originally Posted by Danielpb View Post
hi Speedtre,

Can you confirm if you have Standalone of distribute setup?

if distribute can you explain the layout ie. where the Mgmt is located to the firewall module.

cheers
Dan
Hey Dan. It's standalone and the mgmt is loaded on the same machine as the fw module.
Reply With Quote
  #7 (permalink)  
Old 2007-11-27
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 164
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Hi,

Okay so if you do an fw unloadlocal are you now able to ping the firewall/mgmt device?
Reply With Quote
  #8 (permalink)  
Old 2007-11-27
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
Originally Posted by RayPesek View Post
So you ran "fw unloadlocal" on the firewall and you still cannot get connected?

That specifically allows management connections. Are you trying to connect to the internal IP of the firewall or the external IP?

Do you have the implied rules enabled for management connections?

You could always try allowing all IP's to connect to the firewall for management and see what happens. There may be a NAT rule or something getting in the way.

Ray
Yes, ran fw unloadlocal and still get "Connection cannot be initiated. Make sure the server is up and running."

I can't tell what rules I still have in place because I can't view them on the SmartDashboard... :(
Reply With Quote
  #9 (permalink)  
Old 2007-11-27
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
Originally Posted by RayPesek View Post
So you ran "fw unloadlocal" on the firewall and you still cannot get connected?

That specifically allows management connections. Are you trying to connect to the internal IP of the firewall or the external IP?

Do you have the implied rules enabled for management connections?

You could always try allowing all IP's to connect to the firewall for management and see what happens. There may be a NAT rule or something getting in the way.

Ray
Also, I'm trying to connect to the internal IP of the fw
Reply With Quote
  #10 (permalink)  
Old 2007-11-27
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
Originally Posted by Danielpb View Post
Hi,

Okay so if you do an fw unloadlocal are you now able to ping the firewall/mgmt device?
Yes, when I do a fw unload localhost I can ping the FW.
Reply With Quote
  #11 (permalink)  
Old 2007-11-27
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Can't connect to FW with SmartDashboard

When you unload the policy, you can ping the CheckPoint system, but you can't login?

Have you set the clocks? Sometimes this interfers with the certificate. Check to make sure both the server and client have the clocks synced.

Also, you might want to try doing a cpstop, cpstart. Have you tried this yet?

You could try running netstat -an | grep LIST to see if the CheckPoint server is listening on the CPMI port too.
Reply With Quote
  #12 (permalink)  
Old 2007-11-27
Speedtre Speedtre is offline
Junior Member
 
Join Date: 2007-11-23
Posts: 7
Rep Power: 0
Speedtre has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Quote:
Originally Posted by RobertGraham View Post
When you unload the policy, you can ping the CheckPoint system, but you can't login?

Have you set the clocks? Sometimes this interfers with the certificate. Check to make sure both the server and client have the clocks synced.

Also, you might want to try doing a cpstop, cpstart. Have you tried this yet?

You could try running netstat -an | grep LIST to see if the CheckPoint server is listening on the CPMI port too.

No, I haven't set the clocks, I'll check that. I have done cpstart adn cpstop several times....
Reply With Quote
  #13 (permalink)  
Old 2007-11-27
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 164
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Hi,

If you can ping the firewall/mgmt from your node can you also try a telent on port 18190 (CPMI)....Do you get a Black screen or time out?

A Black screen would indicate the firewall/module is listening to the Check Point Management Interface port and you should be able to make a connection, Are you 100% on the password and user name you are using to connect?
Reply With Quote
  #14 (permalink)  
Old 2007-12-14
praful.raut praful.raut is offline
Junior Member
 
Join Date: 2007-12-13
Posts: 4
Rep Power: 0
praful.raut has an average reputation (10+)
Default problem with checkpoint management client

Hi users,

I have SPLAT Linx check point managment serevr on vmware and also have the checkpoint management
client NGX R65 on the same machine were Vmware is installed.

To connect to the management station i have to go through the intermediate server so that i can proxy the connection to the management server.
for this connection,I am using the ssh.
we have provision that Intermediate server automatically invoke the management client and
feel the information like username,password,ip address,port when try to connect to management server.

When i tried to connect to the management sever using checkpoint management client through intermediate server it gives an error
"Connection cannot be initiated. Make sure that the server x.x.x.x is up and running and that
you are defined as gui client"
but when i refresh the connection page for the same connection and manually type the password it gets connected.

I dont know why the management client show this pecular behaviour
is there any solution for this.
any help aprreciated

Thanks and Regards,
P Raut
Reply With Quote
  #15 (permalink)  
Old 2007-12-14
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

If you used Bridged Networking on the VMWare then you can go straight to the Management Server by IP address.

This is what I do at home, where I run SmartCenter in VMWare and a Firewall in a seperate VMWare. I can even relocate the VM to a different machine and works properly.

I suspect the problem is in how your networking is configured in VMWare, are you using NAT or Bridging. I suspect that as you say you need to proxy then is NAT

Use Bridging as the machine then appears to be on the local network as it's own machine, it responds to ping shows up in arp tables etc.
Reply With Quote
  #16 (permalink)  
Old 2007-12-27
rugby1725 rugby1725 is offline
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Speedtre: Have you tried connecting to the external IP on the firewall with the rulebase unloaded. You should be connecting to the IP that is listed in the IP Address field of your firewall object.
Reply With Quote
  #17 (permalink)  
Old 2008-01-24
bolingoman bolingoman is offline
Junior Member
 
Join Date: 2006-10-26
Posts: 9
Rep Power: 0
bolingoman has an average reputation (10+)
Default Re: Can't connect to FW with SmartDashboard

Hi there,

Don't ignore doing the simplest thing "cpstop & cpstart" as the first step of troubleshooting CP problems. Believe me, it saves lots of lives.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:13.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0