Hello Mailing lists users,

Thank you, Cesar Berho and Reinhard for replying to my e-mail, sorry I
haven't answer your ideas before. I tried what Mr. Reinhard said with out
results. I synchronize the computer clock with the FW1 and verify every tab
of the CheckPoint Configuration tool, for synchronizing clocks but nothing.
When I tried what Mr. Berho said and the CLI says:

Configuring Secure Internal Communication...
============================================
The Secure Internal Communication is used for authentication between
Check Point components

Trust State: Trust established

Would you like re-initialize communication? (y/n) [n] ? y

Note: The Secure Internal Communication will be reset now,
and all Check Point Services will be stopped (cpstop).
No communication will be possible until you reset and
re-initialize the communication properly!
Are you sure? (y/n) [n] ? n

When I hit "y", my Nokia will stop communicating my network until this
process is configured properly?????. What if I can't reestablish the
communication and trust?. What is the process "cpstop"? When I reboot the
Nokia, my old installed rule base will work or the Nokia won't communicate
any segment until the trust thing is completed???

Sorry for all inconveniences but I don't want more surprises with my Nokia.

Regards,

PD: I apologize for my English grammar; I still have some problems writing
in this language. ;-)



-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of Cesar Berho
Sent: Thursday, October 27, 2005 8:28 PM
To: [email protected]
Subject: Re: [FW-1] Certificate error!

This is an error caused, because secure internal communication (SIC) is
spoiled, and you have to renew it, to execute this process please follow
this steps:
At your Nokia, execute the following command "Nokia [admin]# cpconfig"
Choose the option where says " Secure Internal Communication" it will ask if
you want to continue
Configuring Secure Internal Communication...
============================================
The Secure Internal Communication is used for authentication between
Check Point components

Trust State: Trust established

Would you like re-initialize communication? (y/n)

Choose "y" this will renew it at your firewall (after the process finish,
the box will reboot)

Then at you SmartCenter, go to the properties of your checkpoint host
(console) and at general properties, push "Communication", then a box  in
another window appears and you can reestablish SIC.

After finishing, reinstall your policies.

Regards,
Cesar Berho

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Harold
Rugama C
Sent: MiƩrcoles, 26 de Octubre de 2005 06:27 p.m.
To: [email protected]
Subject: [FW-1] Certificate error!

Hello Mailing list users,

Thank you all for your support, all your ideas gave several ways to solve
this inconvenience.

But now I'm frustrated!, I don't know what to do!

When I'm trying to compile my base rule, everything is great but when I
tried to installed them at my IP350, an error pop up.

Stating:

Advanced Security:

Reason: SIC is not initialized either at the SmartCenter Server or the
peer [ SIC error no. 119 ] check that SIC is configured both on
SmartCenter Server and peer, and that both have valid SIC certificates.

With my SmartDash Board I click on properties and then General Properties
option, then at the Communication buttom, it says Trust establish, but
when I click the "TEST SIC STATUS" button an error shows up stating:

SIC Status for nip350-fw1:        Not Communicating

Internal SSL authentication error [ Certificate chain is inconsistent ]


What is this???, someone has an idea how can I solve this???

Regards,

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to