I have got a support call the last week about inability to re-configure IP address on one of the Virtual Systems' VLAN interface on VSX R67.10 system.
To be more specific, say it was eth1.444 with IP address 192.168.xxx.yyy. During the migration to this VS, customer had to "hide" interface for some time. So he has changed its IP address to something like 1.1.1.1.
First time it has worked like a charm. But when he wanted to put the production IP address back, strange things began to happen. In the SmartDashboard it was all right, but instead of 192.168.xxx.yyy eth1.444 was still reported with 1.1.1.1 by ifconfig and cphaprob -a if commands.
Deletion and recreation fo the interface did not change the situation. Eventually the customer has opened a support call with us.
Apparently this is an known issue described in Check Point SecureKnowledge in sk67120.
The solution was to install policy on the VS after re-definition of the interface.
The issue is only specific to R67 and does not seem to appear with R65 and R75.40VS.
This is a professional blog of Check Point Certified Master Architect (CCMA). It does not represent position of my current employer.
Wednesday, January 30, 2013
Tuesday, January 22, 2013
Israeli Ministry of Defence chooses Fortinet over Check Point
According to the report of Israeli Calcalist (Hebrew) Ministry of Defence in Israel is abandoning Check Point for Fortinet.
Considering Israeli Ministry of Defense was one of the first loyal customers of Check Point, this is a very unpleasant event for CP and a huge win for Fortinet. I hope upper management of Check Point taks this as a wakeup call, after series of similar situations with other customers around the globe moving away to other, rather less expensive, solutions.
Considering Israeli Ministry of Defense was one of the first loyal customers of Check Point, this is a very unpleasant event for CP and a huge win for Fortinet. I hope upper management of Check Point taks this as a wakeup call, after series of similar situations with other customers around the globe moving away to other, rather less expensive, solutions.
Monday, January 21, 2013
Crossbeam passes Check Point in a BlueCoat
BlueCoat has announced the purchase of Crossbeam. The great drama of Crossbeam is now at its end.
It all started in 2011 when Check Point has announced 61000 appliance. Days of Crossbeam being a dominant of High End Check Point firewall vendor were obviously counted.
We all have heard stories and arguments about why Crossbeam should remain, about technology and features, about performance and advantages, but finally Crossbeam went to the market looking for a new partner.
As one of the Crossbeam certified experts, I admire their courage and spirit. I have liked the technology, and I have liked the people. I was very concern for them to go under and I am happy to see they have found a new business now.
Irony of this situation is that Crossbeam had suffered Check Point partnership twice.
First, there were C-series, the very first Check Point branded UTM appliances. They went extinct when Check Point had developed taste for its own UTM business. Crossbeam survived, with X-series. Not for long too long though.
I hope BlueCoat Will takes good care of them. I hope the people remain and the technology flourishes.
All the good luck guys!
It all started in 2011 when Check Point has announced 61000 appliance. Days of Crossbeam being a dominant of High End Check Point firewall vendor were obviously counted.
We all have heard stories and arguments about why Crossbeam should remain, about technology and features, about performance and advantages, but finally Crossbeam went to the market looking for a new partner.
As one of the Crossbeam certified experts, I admire their courage and spirit. I have liked the technology, and I have liked the people. I was very concern for them to go under and I am happy to see they have found a new business now.
Irony of this situation is that Crossbeam had suffered Check Point partnership twice.
First, there were C-series, the very first Check Point branded UTM appliances. They went extinct when Check Point had developed taste for its own UTM business. Crossbeam survived, with X-series. Not for long too long though.
I hope BlueCoat Will takes good care of them. I hope the people remain and the technology flourishes.
All the good luck guys!
Thursday, December 27, 2012
Installation / Upgrade Wizard
I am not sure if it is a Christmas miracle, but it's definitely a great present from Check Point.
We now have Upgrade Wizard on Check Point Support Portal, a tool that helps you choosing your upgrade path and installation sources fro bot appliances and open platform.
Great job, Check Point!!!
We now have Upgrade Wizard on Check Point Support Portal, a tool that helps you choosing your upgrade path and installation sources fro bot appliances and open platform.
Great job, Check Point!!!
Tuesday, December 4, 2012
No memory policy installation failure - resolved
I have faced a nasty issue lately with one of my VSX customers. After a certain IPS update the customer has lost ability to push policy to one of Virtual Systems. There was an error: "Load on Module failed - no memory". Strangely, it was just a single VS amont tens of others managed by the same CMA.
They have rebooted the VSX cluster hoping to fix the situation, but it only made it much worse. On the standby physical member the problematic VS was not even loaded, as pushed policy could not be anymore fetched. The cluster was broken, and the member went to "down" state.
Surprisingly, the first case one can find in SecureKnowledge, sk40768, has saved the day. There is a parameter related to showing rule's UUID in the logs, one has to switch it off as the solution case describes.
Once we have applied the solution, policy could be pushed without a problem. The second cluster member was still down, with weird interface probing errors and VS failed to run. We have had to reboot it, and after that everything came back to normal.
Lessongs learned:
1. Do no believe policy installation errors, they can be extremely misleading.
2. Do not rush into rebooting VSX cluster members, that could back-fire.
3. Do DB Revision Control before updating IPS, that would allow you to roll back quickly, if any issue with policy installation.
They have rebooted the VSX cluster hoping to fix the situation, but it only made it much worse. On the standby physical member the problematic VS was not even loaded, as pushed policy could not be anymore fetched. The cluster was broken, and the member went to "down" state.
Surprisingly, the first case one can find in SecureKnowledge, sk40768, has saved the day. There is a parameter related to showing rule's UUID in the logs, one has to switch it off as the solution case describes.
Once we have applied the solution, policy could be pushed without a problem. The second cluster member was still down, with weird interface probing errors and VS failed to run. We have had to reboot it, and after that everything came back to normal.
Lessongs learned:
1. Do no believe policy installation errors, they can be extremely misleading.
2. Do not rush into rebooting VSX cluster members, that could back-fire.
3. Do DB Revision Control before updating IPS, that would allow you to roll back quickly, if any issue with policy installation.
Friday, November 9, 2012
SPLAT R75.40 is not available for 4400 appliance
A colleague of mine has recently discovered an unfortunate fact SPLAT R75.40 has no support for 4400 appliance.
Everything works fine with R75.30, but after upgrading to R75.40 appliance status in SPLAT WebUI shows error code = INITIALIZE_CP_SENSORS_FAILED message. There is a SecureKnowledge case SK79800 mentioning incorrect drivel load. Unfortunately specific drivers are missing for 4400 appliance.
After numerous hours spent in resolution and a support call, the issue is still there. In fact, Check Point has confirmed that R75.40 SPLAT does not work properly on 4400.
One can use either GAIA R75.40 flavor or upgrade to R75.45. The last option obviously requires Management side upgrade as well.
Everything works fine with R75.30, but after upgrading to R75.40 appliance status in SPLAT WebUI shows error code = INITIALIZE_CP_SENSORS_FAILED message. There is a SecureKnowledge case SK79800 mentioning incorrect drivel load. Unfortunately specific drivers are missing for 4400 appliance.
After numerous hours spent in resolution and a support call, the issue is still there. In fact, Check Point has confirmed that R75.40 SPLAT does not work properly on 4400.
One can use either GAIA R75.40 flavor or upgrade to R75.45. The last option obviously requires Management side upgrade as well.
Monday, October 15, 2012
Finally, 10GB HP NIC is supported with Check Point
Miracles happen, even in technology world. I was informed today Check Point finally has 10 GBps optical card supported with HP hardware.
Tree years ago not having any 10 GB NIC supported with Check Point almost killed one of my VSX projects, where HP HW was planned to be used. There was a case with Check Point solution center, multiple meetings with CP executives and other numerous efforts to un-block the situation, and nothing really happened. Check Point han several 10GB NICs, but none of them were made by HP. And as you know, HP does not support "foreign" parts on their servers.
Long story short, that is no longer a case. If you are planning to run R75.40 on HP, you can have this card working in fully supported configuration. If you are running VSX, there is a driver for R67 you must use.
Update: Well, my joy must be a bit premature. According to the official specs, this card is only supported with G6 and G7 HP servers. And as you may know, G7 has end of sales by the October 2012.
Update 2: HP confirmes the mentioned card will not be supported with Gen8 line. Great news, Check Point and HP, great news indeed. /sarcasm/
Tree years ago not having any 10 GB NIC supported with Check Point almost killed one of my VSX projects, where HP HW was planned to be used. There was a case with Check Point solution center, multiple meetings with CP executives and other numerous efforts to un-block the situation, and nothing really happened. Check Point han several 10GB NICs, but none of them were made by HP. And as you know, HP does not support "foreign" parts on their servers.
Long story short, that is no longer a case. If you are planning to run R75.40 on HP, you can have this card working in fully supported configuration. If you are running VSX, there is a driver for R67 you must use.
Update: Well, my joy must be a bit premature. According to the official specs, this card is only supported with G6 and G7 HP servers. And as you may know, G7 has end of sales by the October 2012.
Update 2: HP confirmes the mentioned card will not be supported with Gen8 line. Great news, Check Point and HP, great news indeed. /sarcasm/
Subscribe to:
Posts (Atom)

