Skip to main content

How To Troubleshoot SIC-related Issues in Checkpoint GAIA

How To Troubleshoot SIC-related Issues in Checkpoint GAIA

How To Troubleshoot SIC-related Issues in Checkpoint GAIA

How-To-Troubleshoot-SIC-related-Issues-in-Checkpoint-GAIA
How To Troubleshoot SIC-related Issues in Checkpoint GAIA:-
SIC or Secure Internal Communication is how communicating components authenticate between themselves and the Security Management Server. When successfully authenticated, communication between these components is secure.
This Check Point feature ensures that these modules can communicate freely and securely using a simple communication
initialization process,
The following security measures are taken to ensure the safety of SIC:-
  • Certificates for authentication
  • Standards-based SSL for the creation of the secure channel
  • 3DES for encryption
Almost everytime SIC issues are due to :-
1. mismatch in activation key or
2. sic ports being blocked
Today i am going to show you, How to troubleshoot mismatch SIC?
To do so login in to Firewall CLI by using Putty or any terminal emulator software.
To view SIC status enter the Fw > cp_conf sic status command.
As you seen in below image, My SIC status is Trust established.
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
But for this article, i am going to re-established. to do so enter the cpconfig command and choose the option number 5.
How-To-Troubleshoot-SIC-related-Issues-in-Checkpoint-GAIA
now enter Y for re-initialization and enter your activation key here.
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
then enter 9 to exit from this session
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
if you issue cp_conf sic status , it will show you trust un-established here.
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
now open your Smart Dashboard, Open Your Firewall gateway properties, In the general properties , Click on the Test SIC status.
How-To-Troubleshoot-SIC-related-Issues-in-Checkpoint-GAIA
it will give your Not communication error.
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
then click on the Communication tab and click on the Reset option
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
and enter your same authentication key here and click on the Initialize option to initilize your SIC again.
How-To-Troubleshoot-SIC-related-Issues-in-Checkpoint-GAIA
Now again click on the Test SIC status option again. it will show you your SIC is communicating now:-)
How-To-Troubleshoot-SIC-related-Issues-in-Checkpoint-GAIA
Now if you issue cp_conf sic status in CLI mode ,
How To Troubleshoot SIC-related Issues in Checkpoint GAIA
Hope you like my post.How To Troubleshoot SIC-related Issues in Checkpoint GAIA. Please Share with others.

Comments

Popular posts from this blog

CLI Commands for Troubleshooting FortiGate Firewalls

CLI Commands for Troubleshooting FortiGate Firewalls 2015-12-21 Fortinet , Memorandum , Network Cheat Sheet , CLI , FortiGate , Fortinet , Quick Reference , SCP , Troubleshooting Johannes Weber This blog post is a list of common troubleshooting commands I am using on the FortiGate CLI . It is not complete nor very detailled, but provides the basic commands for troubleshooting network related issues that are not resolvable via the GUI. I am not focused on too many memory, process, kernel, etc. details. These must only be used if there are really specific problems. I am more focused on the general troubleshooting stuff. I am using it personally as a cheat sheet / quick reference and will update it from time to time. Coming from Cisco, everything is “show”. With Fortinet you have the choice confusion between show | get | diagnose | execute . Not that easy to remember. It is “ get router info6 routing-table” to show the routing table but “ diagn...

From MPLS to SD-WAN to SASE: An Evolution of Enterprise Networking

From MPLS to SD-WAN to SASE: An Evolution of Enterprise Networking The way we do business is changing. As critical business applications migrate to the cloud, and the mobile workforce continues to grow, networking and security solutions need to evolve in order to meet the changing business needs. Gartner believes (and we agree) that the future of networking lies with  SASE (Secure Access Service Edge)  – the convergence of networking and security into one cloud service. Here’s why. 1990s – 2000s: MPLS and the Era of Clear Network Boundaries? Back in the day, networking models were hardware-centric and manually configured. Applications, data, and services lived within private datacenters and relied on remote access solutions to connect remote workers. Dedicated network connectivity, known as MPLS, was the preferred approach for connecting remote locations. MPLS provides predictable performance, low latency and packet loss, and central management. However, MPLS is ...

FortiGate: Upgrading the firmware via CLI

FortiGate: Upgrading the firmware via CLI To use the following procedure, you must have a TFTP or FTP server that FortiDB can connect to. You must also log in using the “admin” administrator account. Start the FTP or TFTP server. Copy the new firmware image file to the FTP or TFTP server. Log into the CLI. Verify that FortiDB can connect to the FTP or TFTP server. For example, if the IP address of the TFTP server is 192.168.1.168, enter the CLI command: execute ping 192.168.1.168 Enter the following command to copy the firmware image from the TFTP server to FortiDB: execute restore image ftp execute restore image tftp Where is the name and location of the firmware image file and or is the IP address of the FTP or TFTP server. For example, if the firmware image file name is image.out and the IP address of the FTP or TFTP server is 192.168.1.168, enter: execute restore image tftp image.out 192.168.1.168 FortiDB responds with the message: This oper...