CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-30
Junior Member
 
Join Date: 2006-04-30
Posts: 24
Rep Power: 0
yelwoci has an average reputation (10+)
Default Compiling DCERPC error after SD 541060425

NG AI R55 HFA17 Linux WGL-X 2.4.9-34.13pdsv #1 Mon Dec 1 12:50:10 CST
Same thing on this and one other firewall same OS/CP, different policies.

2003 i686 unknown
After Smart Defense Update 28apr06 (I think)

1 error in preprocessor
#include "fwui_head.def"
from file /opt/CPfw1-R55/conf/Standard.pf, line 5595:
#include "base.def"
from file /opt/CPfw1-R55/lib/fwui_head.def, line 315:
#include "dcerpc.def"
from file /opt/CPfw1-R55/lib/base.def, line 738:
DCERPCt_NDR_LABEL_RFFU=0)
cpp: line 421, Error: Redefining defined variable "DCERPCt_NDR_OK"

Have tried D Barcon's submission:-
rm inspect.C and updates.def
reset the asm_update_version
re update SD
reinstall policy
but it fails
do I need to delete the DCE section?

Regards

Ian Cowley
Reply With Quote
  #2 (permalink)  
Old 2006-04-30
Junior Member
 
Join Date: 2006-04-30
Posts: 24
Rep Power: 0
yelwoci has an average reputation (10+)
Default Re: Compiling DCERPC error after SD 541060425

I think I've found the problem!

I'd copied the $FWDIR/lib/dcerpc_hfa.def to dcerpc.def to overcome some issues across VPNs and Microsoft Shares.

I wondered if the latest SD hadn't taken the differences in the 'hfa' version.
So I copied the original back and cpstart and reinstalled the policy

all OK...but I now might have my original problems back!

It would be nice to be able roll back and/or inhibit particular SD versions

Ian Cowley
Reply With Quote
  #3 (permalink)  
Old 2006-05-01
Junior Member
 
Join Date: 2006-05-01
Location: Halifax, Nova Scotia, Canada
Posts: 6
Rep Power: 0
membree has an average reputation (10+)
Default Re: Compiling DCERPC error after SD 541060425

I had exactly the same problem on NG AI R55 HFA17 and was able to resolve it by reverting to the previous saved policy database revision. I didn't know what the problem was but expect that your explanation is correct as I also am using the updated dcerpc.def. Hopefully Check Point will updated the SmartDefense code to recognize both versions of dcerpc.def and re-release it sometime soon.

Saving a policy database revision prior to installing a SmartDefense update as described in the SmartDefense thread "Best practice for SmartDefense update" really is an excellent idea as I have been burned by SmartDefense updates that broke policy installation twice now.


The D Barcon submission was to deal with a somewhat different issue (this was the previous time I was burned). Check Point issued a SmartDefense update with a bug that prevented policy compilation and then re-released an undocumented corrected version a few hours later using the same version number as the original broken version. Those unfortunate enough to have installed the new version prior to it being corrected (like us) were stuck, SmartDefense didn't recognize the corrected version because it had the same version as what was installed so wouldn't install the correction. The D Barcon submission was Check Point's solution, a description of how to back out a SmartDefense update so that the same SmartDefense version can be reinstalled. In the current case, there hasn't been a corrected version so following this procedure would have no effect. Since that time, I generally wait a few days before installing a SmartDefense release so that others can bear the pain. Waiting didn't save us this time though.

Last edited by membree; 2006-05-01 at 10:50.
Reply With Quote
  #4 (permalink)  
Old 2006-05-01
Junior Member
 
Join Date: 2006-04-30
Posts: 24
Rep Power: 0
yelwoci has an average reputation (10+)
Default Re: Compiling DCERPC error after SD 541060425

I have to admit there were a few FLAME mails from me to Checkpoints Support team.
If you don't have an Enterprise Support package, they won't talk to you.
Even if you find a bug - like R60A update_export/import package doesn't work from R55.

Then they give you an update, that you've paid for, that breaks the firewall.
They won't fix it unlesss you pay them money.
That in any commercial or legal framework is extortion IMHO

Any road...I've bypassed the problem..so I've cooled down a bit!!

Ian Cowley
Reply With Quote
  #5 (permalink)  
Old 2006-05-02
Junior Member
 
Join Date: 2006-05-01
Location: Halifax, Nova Scotia, Canada
Posts: 6
Rep Power: 0
membree has an average reputation (10+)
Default Re: Compiling DCERPC error after SD 541060425

I noticed that SmartDefense update version 541060430 was available today. There is no documentation on the SmartDefense site for this version (541060425 is the most recent documented version). I installed it and my Firewall policies install with no problems. Check Point appear to have resolved the dcerpc_hfa.def incompatibility that was present in 541060425.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 03:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0