I have faced a nasty issue lately with one of my VSX customers. After a certain IPS update the customer has lost ability to push policy to one of Virtual Systems. There was an error: "Load on Module failed - no memory". Strangely, it was just a single VS amont tens of others managed by the same CMA.
They have rebooted the VSX cluster hoping to fix the situation, but it only made it much worse. On the standby physical member the problematic VS was not even loaded, as pushed policy could not be anymore fetched. The cluster was broken, and the member went to "down" state.
Surprisingly, the first case one can find in SecureKnowledge, sk40768, has saved the day. There is a parameter related to showing rule's UUID in the logs, one has to switch it off as the solution case describes.
Once we have applied the solution, policy could be pushed without a problem. The second cluster member was still down, with weird interface probing errors and VS failed to run. We have had to reboot it, and after that everything came back to normal.
Lessongs learned:
1. Do no believe policy installation errors, they can be extremely misleading.
2. Do not rush into rebooting VSX cluster members, that could back-fire.
3. Do DB Revision Control before updating IPS, that would allow you to roll back quickly, if any issue with policy installation.
This is a professional blog of Check Point Certified Master Architect (CCMA). It does not represent position of my current employer.
Tuesday, December 4, 2012
Friday, November 9, 2012
SPLAT R75.40 is not available for 4400 appliance
A colleague of mine has recently discovered an unfortunate fact SPLAT R75.40 has no support for 4400 appliance.
Everything works fine with R75.30, but after upgrading to R75.40 appliance status in SPLAT WebUI shows error code = INITIALIZE_CP_SENSORS_FAILED message. There is a SecureKnowledge case SK79800 mentioning incorrect drivel load. Unfortunately specific drivers are missing for 4400 appliance.
After numerous hours spent in resolution and a support call, the issue is still there. In fact, Check Point has confirmed that R75.40 SPLAT does not work properly on 4400.
One can use either GAIA R75.40 flavor or upgrade to R75.45. The last option obviously requires Management side upgrade as well.
Everything works fine with R75.30, but after upgrading to R75.40 appliance status in SPLAT WebUI shows error code = INITIALIZE_CP_SENSORS_FAILED message. There is a SecureKnowledge case SK79800 mentioning incorrect drivel load. Unfortunately specific drivers are missing for 4400 appliance.
After numerous hours spent in resolution and a support call, the issue is still there. In fact, Check Point has confirmed that R75.40 SPLAT does not work properly on 4400.
One can use either GAIA R75.40 flavor or upgrade to R75.45. The last option obviously requires Management side upgrade as well.
Monday, October 15, 2012
Finally, 10GB HP NIC is supported with Check Point
Miracles happen, even in technology world. I was informed today Check Point finally has 10 GBps optical card supported with HP hardware.
Tree years ago not having any 10 GB NIC supported with Check Point almost killed one of my VSX projects, where HP HW was planned to be used. There was a case with Check Point solution center, multiple meetings with CP executives and other numerous efforts to un-block the situation, and nothing really happened. Check Point han several 10GB NICs, but none of them were made by HP. And as you know, HP does not support "foreign" parts on their servers.
Long story short, that is no longer a case. If you are planning to run R75.40 on HP, you can have this card working in fully supported configuration. If you are running VSX, there is a driver for R67 you must use.
Update: Well, my joy must be a bit premature. According to the official specs, this card is only supported with G6 and G7 HP servers. And as you may know, G7 has end of sales by the October 2012.
Update 2: HP confirmes the mentioned card will not be supported with Gen8 line. Great news, Check Point and HP, great news indeed. /sarcasm/
Tree years ago not having any 10 GB NIC supported with Check Point almost killed one of my VSX projects, where HP HW was planned to be used. There was a case with Check Point solution center, multiple meetings with CP executives and other numerous efforts to un-block the situation, and nothing really happened. Check Point han several 10GB NICs, but none of them were made by HP. And as you know, HP does not support "foreign" parts on their servers.
Long story short, that is no longer a case. If you are planning to run R75.40 on HP, you can have this card working in fully supported configuration. If you are running VSX, there is a driver for R67 you must use.
Update: Well, my joy must be a bit premature. According to the official specs, this card is only supported with G6 and G7 HP servers. And as you may know, G7 has end of sales by the October 2012.
Update 2: HP confirmes the mentioned card will not be supported with Gen8 line. Great news, Check Point and HP, great news indeed. /sarcasm/
Tuesday, September 25, 2012
E75.x Endpoint Connect Client: decrypting config file
Endpoint Connect is quite different from SecureClient, you know that. Latter has VPN site configuration in users.C file, and by default it is stored as cleartext.
E75.X client stores VPN configuration on Trac.conf file, and it is encrypted by default. If you are trying to troubleshoot some site creation issues or just curious, it might be interesting to be able to decrypt the configuration file.
This is what you need to do:
1. Login to your laptop as an administrator and locate E75.X files. Usually they are under %Program Files/CheckPoint/Endpoint Connect/ folder. Find there Trac.defaults file
2. Stop VPN client (close GUI) and then stop Check Point Endpoint Security VPN service
3. Open Trac.defaults file to edit, find OBSCURE_FILE parameter and change its value from 1 to 0.
4. Start VPN service and then the client. Trac.config file is now readable.
E75.X client stores VPN configuration on Trac.conf file, and it is encrypted by default. If you are trying to troubleshoot some site creation issues or just curious, it might be interesting to be able to decrypt the configuration file.
This is what you need to do:
1. Login to your laptop as an administrator and locate E75.X files. Usually they are under %Program Files/CheckPoint/Endpoint Connect/ folder. Find there Trac.defaults file
2. Stop VPN client (close GUI) and then stop Check Point Endpoint Security VPN service
3. Open Trac.defaults file to edit, find OBSCURE_FILE parameter and change its value from 1 to 0.
4. Start VPN service and then the client. Trac.config file is now readable.
Wednesday, September 12, 2012
Tufin revolution - part of CPUG 2012
Have you see Tufin revolution banner?
Come to CPUG 2012 conference to witness that revolution in motion. Tufin is sponsoring CPUG conference and is going to announce a new exiting revolutionary way to manage your firewalls.
It is not too late to register.
Come to CPUG 2012 conference to witness that revolution in motion. Tufin is sponsoring CPUG conference and is going to announce a new exiting revolutionary way to manage your firewalls.
It is not too late to register.
Next Generation FW war is not so cold anymore?
PAN and Check Point are known to attack each other. If I understand it correctly, PAN is chasing Check Point customers for years. I guess, we need to thank them for it. That is the main reason Check Point was so aggressive to introduce Identity Awareness and Application Control features. Anti-Bot software blade is taking the race even further.
But that was a cold war two years ago. It was a feature race. Now the tention seems to get more and more hit.
PAN has hired mythbusters to show some rather humiliating competitive analysis.
Check Point did not go so far, but take look at this site, "Facts or Hype". The argument is getting hotter.
I wonder when it finally makes to court. What do you think?
But that was a cold war two years ago. It was a feature race. Now the tention seems to get more and more hit.
PAN has hired mythbusters to show some rather humiliating competitive analysis.
Check Point did not go so far, but take look at this site, "Facts or Hype". The argument is getting hotter.
I wonder when it finally makes to court. What do you think?
Sunday, September 9, 2012
One week before CPUGCON 2012
It is only one week before CPUG 2012 conference starts in Chur, Switzerland.
Three reasons to come:
1. lots of interesting discussions,
2. lots of interesting people and
3. lots of fun.
Are you coming or what???
Subscribe to:
Posts (Atom)
