CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 549
Rep Power: 10
BarryStiefel has disabled reputation
Default Has only loopback (lo) interface, aborting...

Has only loopback (lo) interface, aborting...



When attempting to install a policy, I get the following error message:

Installing Security Policy foobar on all.all@firewall Has only loopback (lo) interface, aborting... Failed to Load Security Policy: No such file or directory Fetching Security Policy from firewall failed

Answer

It is possible that FireWall-1 has no clue about any of the interfaces that are loaded. You can force FireWall-1 to refresh it's interface list by uninstalling and reinstalling the kernel module as follows: fw ctl uninstall fw ctl install fw fetch localhostYou should also check the Interfaces tab on the workstation object representing your firewall. If the interfaces listed are incorrect or missing, perform an SNMP Get and reset Anti-Spoofing as appropriate. You should then be able to install your policy.



This error may also be caused by backing out a service pack on Solaris (Sparc and i386). If the back out process fails, /etc/init.d/fw1boot and /etc/init.d/fw1bootd may not be restored correctly. As a result, FireWall-1 may give an error saying it recognizes only the loopback interface. A workaround is to backup the files /etc/init.d/fw1boot and /etc/init.d/fw1bootd before backing out the service pack and restoring them after backing out the service pack.

This error may also come up because the FireWall-1-specific startup scripts are either non-existent or are symlinks on a Solaris platform (for some reason, these don't work right). A copy of /etc/init.d/fw1bootd should be in /etc/rc2.d/S00fw1bootd and a copy of /etc/init.d/fw1boot should be named /etc/rcS.d/S25fw1boot.

This error message may also come up as a result of missing a dumb terminal definition in terminfo (happens frequently on Solaris), which can easily be fixed as follows:



# cd /usr/share/lib/terminfo

# cp v/vt100 d/dumb

Another person suggested moving $FWDIR/conf/product.conf to $FWDIR/conf/inst.conf and re-running fwconfig or cpconfig. You should also check to see /etc/fwboot/if.dev has the correct interface types listed there. This can happen when re-running fwconfig or cpconfig. A person from Check Point explains the "accept" or "deny" in this file:

"The deny/accept sets only the way the FW talks to the driver. If it will use DLPI or not. DLPI is supported on some adapters, and not supported by others. If you would change all the 'deny' to 'accept' you could have extremly odd behaviour with the FW. It is best not to touch the file, and if cpconfig asks you about cards that do not appear in the file, it is recommended that if in doubt about the capabilities of the NIC you should choose to deny DLPI."





-- RobertGraham - 16 Mar 2004

FAQForm FAQs.Class: TroubleshootingFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:46.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0