Dear All,

I had a problem on "fetch floodgate policy", when I run "CPSTART", I will
get the following error (fetch QOS policy failed):

Installing Security Policy xxxx_policy on [EMAIL PROTECTED]
Fetching Security Policy from localhost succeeded

Fetching Securuity Policy From: 10.0.0.1

FloodGate-1: Loading - FloodGate-1

FloodGate-1: Loading Kernel module...
FloodGate-1: Starting fgd50

FloodGate-1: Fetching QOS Policy from localhost
Fetching FloodGate-1 QOS Policy:
 Management rejected fetch for this module - sic name does not match.
 Fetch failed: connection failed - END_BY_APPLICATION
 Failed to Fetch QOS Policy.

Failed to fetch QOS Policy.
FloodGate-1 Stated

My troubleshooting and verification:

Due to this symptom, I check the SIC , but I make sure that it is not caused
by SIC problem.  Because, when I run "fgate fetch 10.0.0.1" command to fetch
QOS policy which was succeed and can be installed QOS policy (After Firewall
service started by "cpstart" command.)

My environment is:

  a.. Management Console is a Provider-1 and CMA is using "invalid IP
address" and site in internal network
  b.. Firewall Module is on other external network site
  c.. Due to this scenario it will have a special NAT rule for External
Firewall module connect to Internal Management Console, the following is a
NAT rule on this external firewall module:
        Original Source            Original Destination
Translated Source                 Translated Destination
        --------------------------------------------------------------------
------------------------------------
        External Firewall          CMA (invalid IP)
=original                               CMA (valid IP)

         (Unchecked "Translate destination on client side" at global
properties)


My question:

Does anybody know that how to solve this problem?



Thank you for your kind attention and I appreciate that if you can give me
any advice.

Thank You,

Kingsley


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to