CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default cannot add rule on checkpoint FW-1 R62

Just installed R62 and smartdashboard can connect to fw, but cannot add the rule, I don't know what is going on, the error messages as below, pls help.

failed to connect to the module or the connection was lost.
Reply With Quote
  #2 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: cannot add rule on checkpoint FW-1 R62

when I add the new rule, it shown as below, is it normal?

Both your explicitly and implicitly defined rules will be a part of the new security policy.
Reply With Quote
  #3 (permalink)  
Old 2008-04-16
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: cannot add rule on checkpoint FW-1 R62

Ref your second post - yes a message like that is normal because by default there are some "Global Properties" turned on which provide so called "Implicit Rules", and you have added rules too, rules you add are "Explicit Rules".

As for your first post, it's not completely clear to me what you mean, so...

couple questions for you.

1) Is your SmartCenter Server and FireWall on the same box?

2) When you say you "cannot add a rule" do you mean you cannot "Install the Policy"? (I think that is what you mean). or do you mean your SmartDashboard cannot connect to the SmartCenter Server?
Reply With Quote
  #4 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: cannot add rule on checkpoint FW-1 R62

sorry to make any confuse, smartcenter and fw are the same box, the rule can be added, but when I install the policy, the error message displayed. Since this is fresh install, no any rule before, so I only add a simple rule such as host to any http accept, something like that, but failure when I install policy.

smartdashboard can connect to smartcenter.
Reply With Quote
  #5 (permalink)  
Old 2008-04-16
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: cannot add rule on checkpoint FW-1 R62

get a command prompt on the firewall and type the following commands:

fw stat <======= this tells you what policy is installed at the moment I expect it to be "Initial Policy"

cplic print <===== this tells you what license is installed

"failed to connect to the module" normally means that SIC is not established - and its a long time ago since I did a stand alone installation, but I thought that setting up SIC was not required on a STAND ALONE configuration like yours.

but lets check anyway:

Double click up your FW object in Smart Dasboard, on the General Tab:
1) is Firewall selected?
2) select the communication button and select TEST SIC - does is say "communicating"?

Last edited by coldark; 2008-04-16 at 02:18.
Reply With Quote
  #6 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: cannot add rule on checkpoint FW-1 R62

once I come back to office and I will check it again.

Many thanks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0