I can't help but ask the obvious, but is there a rule in your policy
that allows for FW traffic to pass between your management server and
your enforcement modules? There should be a resources group called
Firewall-1 that should in the minimum contain FW1, CP_reporting,
FW1_cvp, FW1_Encapsulation, FW1_key, FW1_lea, FW1_log, FW1_mgmt.
Without these, you may have established SIC, but once you push a policy
to your enforcement module, if the policy does not allow for FW
communications between the Management server and the Enforcement Module
you won't be able to communicate back and forth.
Source Destination Service Action
MGMT Firewall Firewall-1
Accept
Firewall MGMT
Best regards,
Layne Meier
Atlanta Newspapers, Inc.
On May 20, 2004, at 7:57 AM, Hans-Joachim Hoetger wrote:
On Thu, May 20, 2004 at 10:17:28AM +0200, Matthias Leu wrote:
Hans-Joachim Hoetger wrote:
Hello,
i am installing our first NG R55 module (on Solaris). I can
initialize
the SIC and it shows 'Trust established' afterwards. But then i cant
communicate with the module. Wether a policy install nor a topology
detection works. Even the 'test SIC Status' fails with the message:
SIC Status for gateway-NG: Not Communicating
Internal SSL authentication error [ Certificate chain is
inconsistent ]
What can i do about this?
cheers
Hi,
have you tried to reset SIC? You can do this at the Firewall Module by
using cpconfig. cprestart may be necessary afterwards. Then, reset it
at
your SmartCenter and try to initialize SIC again. Same result?
Is the time of these two systems the same?
Hope it helps,
Hello,
yes, i reset the SIC several times. The 'cpstop, cpstart' ist done
automatically by cpconfig. Both systems are ntp syncronized. Thank you
for the hints.
cheers
--
Hans-Joachim Hoetger voice: +49-5246-80-1555
Telef�nica Deutschland GmbH fax: +49-5246-80-2555
"Gut ist auch des Emporkommen von Linux als Herausforderer
von Microsoft." Angela Merkel (Die Zeit, 4.Mai 2000)
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================