Professional Documents
Culture Documents
Issues
©2015 Check Point Software Technologies Ltd. [Restricted] ONLY for designated groups and individuals 1
Introduction
©2015 Check Point Software Technologies Ltd. [Restricted] ONLY for designated groups and individuals 2
Agenda
3 Troubleshooting scenarios
©2015 Check Point Software Technologies Ltd. [Restricted] ONLY for designated groups and individuals 3
Agenda
3 Troubleshooting scenarios
©2015 Check Point Software Technologies Ltd. [Restricted] ONLY for designated groups and individuals 4
Login process flow
Login Step 1: The GUI client open a CPMI connection over port 18190 to the MGMT
process flow server
GUI Login
issues Step 2: The fwm process on the MGMT server which listens on port 18190 receives
the request and checks whether the GUI client is listed in the
Troubleshoot
$FWDIR/conf/gui-clients file. Only in case it is listed in the file, the
scenarios
connection process will continue.
Cannot initiate
Step 3: The fwm process checks the MGMT server certificate (cp_mgmt). It verifies
Connectivity that the certificate is valid and that it matches the certificate details located
FWM
in the registry and the objects_5_0.C files. In case this step has finished
successfully, the SIC between the MGMT server and the GUI will be
Certificate established
FWM debug
In case the MGMT server certificate DN (CN + O) is not identical to the
FWM down
information appear in the objects_5_0,C and the registry files, the
connection will fail during the SIC negotiation.
Connection – In order to identify the DN of your MGMT server certificate, you can run the following
refused
command:
Authenticate # cpca_client lscert –dn “cn=cp_mgmt”
Step 4: Once the SIC negotiation has completed, the MGMT server will authenticate
the administrator.
Step 5: After the administrator was authenticated successfully, the fwm process will
load the different database files.
©2015 Check Point Software Technologies Ltd. 5
Agenda
3 Troubleshooting scenarios
©2015 Check Point Software Technologies Ltd. [Restricted] ONLY for designated groups and individuals 6
GUI Connectivity issues
Login
process flow
Connection to the management server via GUI can fail for various reasons, we
GUI Login will try to cover most of them.
issues
Troubleshoot The first thing that we must check when we have login issues is the error
scenarios message we receive.
Cannot initiate
We will divide the issues according to 3 main error messages:
Connectivity – Connection cannot be initiated
– The connection has been refused
FWM
– Authentication to server failed
Certificate
Note: In case you cant find a solution on the spot, It’s always recommended to
FWM debug
replicate the issue in the lab if it’s possible, in most cases it will decrease
FWM down
resolution time dramatically.
Connection
refused
Authenticate
3 Troubleshooting scenarios
Troubleshoot
scenarios
Cannot initiate
Connectivity
FWM
Certificate
FWM debug
FWM down
Connection
refused
Authenticate
Connectivity
Troubleshoot Incase there is a FW installed on the MGMT server (standalone), it’s possible
scenarios that the FW drops the CPMI traffic.
Cannot initiate
- For troubleshooting purposes Run: # fw unloadlocal on the FW and check if
Connectivity it solves the issue.
FWM Note: make sure that the customer is aware about the effect of this command
and that you are doing that during a maintenance window.
Certificate
FWM debug In the issue was solved, connect to the MGMT server via GUI and configure a
rule which allows the GUI client to connect to the MGMT server on port 18190
FWM down (CPMI).
Connection
refused
Authenticate
Connectivity
FWM down Note: both commands are collected by the cpinfo file, so if you
Connection
have a cpinfo file from the customer machine which was taken
refused during the problem you can check it there.
Authenticate
Connectivity
Connectivity
FWM Note: The above are dynamic files which contains cached GUI information.
Sometime these files become corrupted and deleting those files should cause
Certificate
the system to re-create them.
FWM debug
If the issue persists, collect the following information for further investigation:
FWM down
Connection upgrade_export file (in order to try and reproduce the issue in our lab ).
refused Search for relevant messages in $FWDIR/log/fwm.elg
Authenticate
collect fwm debug (in case you did not find enough information in the fwm.elg file ):
Connectivity
Stop the fwm debug – by typing the commands:
# fw debug fwm off TDERROR_ALL_ALL=0
FWM
Collect the log filet:
Certificate $FWDIR/log/fwm.elg
FWM debug
FWM down
Connection
refused
Authenticate
Connectivity
Connectivity
** We will discuss the proper handling further on.
FWM
Certificate
FWM debug
FWM down
Connection
refused
Authenticate
Connectivity
Connectivity
Authenticate Once the process has crashed unset the TDERROR and collect the output:
#unset TDERROR_ALL_ALL
In case the above troubleshooting process did not solve the issue – we will proceed the
investigation in our lab environment.
Troubleshoot Note: In case the issue is replicated in your lab use fix_ndb (refer to sk36339) to
scenarios check and repair database.
corruptions in the *.NDB files, especially in the following files:
Cannot initiate
o $FWDIR/conf/fwauthd.NDB
Connectivity
o $FWDIR/conf/robo-control.NDB
o $FWDIR/conf/robo-gateways.NDB
FWM
Small Note: The following files contain information regarding edge devices:
Certificate
o $FWDIR/conf/robo-control.NDB
FWM debug o $FWDIR/conf/robo-gateways.NDB
Incase the customer does not use any edge device, it’s possible to remove these
FWM down files and they will be recreated.
Connection
refused
Authenticate
GUI Login
issues
Troubleshoot
scenarios
Cannot initiate
Connectivity
FWM
Certificate
FWM debug
FWM down
Connection
refused
Authenticate
GUI Login The error message indicates that the MGMT server certificate has
issues
Troubleshoot expired
scenarios
Make sure that the time & date are correct on the management server
Cannot initiate
FWM debug
FWM down
Connection
refused
Authenticate
GUI Login
issues
Troubleshoot
scenarios
Cannot initiate
Connectivity
FWM
Certificate
FWM debug
FWM down
Connection
refused
Authenticate