CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-27
Junior Member
 
Join Date: 2005-09-21
Location: Lincoln, Nebraska, USA
Posts: 3
Rep Power: 0
AlexLewisLnk has an average reputation (10+)
Default StormAgentMsg: Failed to access URL

stormcenter blocklist fails to download after SANS/ICS changes to different CA in Sept 2007. SmartTracker shows following in log:

StormAgentName: CPDShield
StormAgentAction: Retrieve blocklist
StormAgentMsg: Failed to access URL

Check Point engineer gave me a link for attached file which is replacement CA cert to load on firewall. Steps to install:

1. On the gateway, backup $FWDIR/conf/equifax.cer
2. On the gateway, copy new equifax.cer file to $FWDIR/conf
3. Install policy to the gateway
4. Wait a minute or so, and on the gateway, check "dynamic_objects -l". The CPDShield object should show the block list.
Attached Files
File Type: zip StormCenter-cert-Oct2007.zip (1.1 KB, 131 views)
Reply With Quote
  #2 (permalink)  
Old 2007-11-28
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

Confirmed......

Error messages:

Quote:
Number: 1
Date: 26Nov2007
Time: 11:11:11
Product: VPN-1 Power/UTM
Origin: firewall
Type: Control
Action:
Information: StormAgentName: CPDShield
StormAgentAction: Retrieve blocklist
StormAgentMsg: Failed to access URL


Number: 2
Date: 26Nov2007
Time: 11:11:12
Product: VPN-1 Power/UTM
Origin: firewall
Type: Control
Action:
Information: StormAgentName: CPDShield
StormAgentAction: Retrieve blocklist
StormAgentMsg: Data has expired. Clearing defined ranges
Before cert update:

Quote:
# dynamic_objects -l

object name : CPDShield
range 0 : 0.0.0.1 0.0.0.1

Operation completed successfully
After cert update:

Quote:
# dynamic_objects -l

object name : CPDShield
range 0 : 58.68.76.0 58.68.76.255
range 1 : 60.168.84.0 60.168.84.255
range 2 : 67.15.204.0 67.15.204.255
range 3 : 69.56.243.0 69.56.243.255
range 4 : 78.60.40.0 78.60.40.255
range 5 : 78.128.39.0 78.128.39.255
range 6 : 84.19.184.0 84.19.184.255
range 7 : 121.14.136.0 121.14.136.255
range 8 : 123.253.134.0 123.253.134.255
range 9 : 139.55.63.0 139.55.63.255
range 10 : 139.55.82.0 139.55.82.255
range 11 : 139.55.113.0 139.55.113.255
range 12 : 148.208.199.0 148.208.199.255
range 13 : 172.187.159.0 172.187.159.255
range 14 : 195.110.148.0 195.110.148.255
range 15 : 202.76.108.0 202.76.108.255
range 16 : 209.173.166.0 209.173.166.255
range 17 : 209.173.181.0 209.173.181.255
range 18 : 218.1.65.0 218.1.65.255
range 19 : 222.90.65.0 222.90.65.255

Operation completed successfully
Reply With Quote
  #3 (permalink)  
Old 2007-12-03
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

Thanks, that fixed that problem.

Have you had any success sending logs via R65 to DShield? Their pages say you need to use their ID but SmartDashboard only gives you a place to put in your email address and password. I can see the logs going out but my page says I'm not submitting logs.

Take care,

Ray
Reply With Quote
  #4 (permalink)  
Old 2008-02-20
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

Thanks

Great info thanks

Love this site, so many answers so little time!

:)

Brent
Reply With Quote
  #5 (permalink)  
Old 2008-02-20
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

And the answer to my problem is that CP does not support the current method of sending logs to DShield. It changed and they did not know it and have not issued a fix yet.

Ray
Reply With Quote
  #6 (permalink)  
Old 2008-02-26
Junior Member
 
Join Date: 2007-02-27
Posts: 9
Rep Power: 0
phelanre has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

Would this have any effect on a VPN tunnel?
I tried following these steps and started getting different logs/failure messages from one of my vpn tunnels, so I uninstalled the new cert.
I can look up the specific vpn errors if necessary.
Reply With Quote
  #7 (permalink)  
Old 2008-02-26
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: StormAgentMsg: Failed to access URL

No, it wouldn't have any effect on VPNs.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0