CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Windows
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-28
Junior Member
 
Join Date: 2008-08-28
Posts: 1
Rep Power: 0
Chilulu has an average reputation (10+)
Default Event Log Error: FW-1: setting external interface to <interface_name>

Greetings from Japan!

I am running Check Point VPN-1 & FireWall-1 NG w/ AI (R55) HFA_04 on Windows Server 2003. For some reason, VPN functions of the machine occasionally gets disabled after policy updates from the management system (SmartDashboard). During the "outage" I can still access local networks routed by the firewall, as well as the internet. The following error consistently appears in Event Viewer (System) after every policy update/install, so I am guessing it has something to do with the problem.

FW1: FW-1: setting external interface to <interface_name>

When the problem occurs, the only way I can seem to get the tunnels back is by restarting the system, but the strange thing is, the above error appears again right after the OS comes online (with VPN functions back to normal until the next unlucky policy update).

Does anyone have any idea what this error means, and how to resolve it?

I confirmed the external interface is properly identified by <interface_name> and IP on the management system (Check Point device topology). I also tried manually creating an "external.if" file (containing <interface_name>) under "/conf" but this had no effect. I guess this file is only used in Linux/UNIX implementations.

At present I can't do any policy updates during the day, due to the risk of bringing inter-site connectivity down. As long as I don't do any updates, things are pretty quiet, but I don't want to keep waiting for the evening/weekend to change policies. More importantly, I don't want to keep having to restart the firewall after every update.

If anyone can shed some light on this, please let me know...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:36.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0