Solved

Unable to connect to FW-1 Dashboard with External IP address

Posted on 2009-04-03
6
265 Views
Last Modified: 2013-11-16
I need to remote into FW-1 Dashboard.  Currently I am not able to connect with the external IP address.  Nor can I ssh/https.   Whenever I cpstop/cprestart, I notice a error "VPN-FW-1 stop, Fail to reset VPN-1".  This particular customer has NG FW-1 R55 with Encryption Module for VPN.  I wanted to help them setup a VPN Remote Access for end users.  Any suggestions?
0
Comment
Question by:hotrod_952
  • 3
  • 3
6 Comments
 
LVL 4

Assisted Solution

by:Multipath
Multipath earned 20 total points
ID: 24065804
Do a cplic print and make sure the vpn module is there.  I think your issue is the VPN not coming up which could be due to many things like ip address not matching license or not being licensed.
0
 

Author Comment

by:hotrod_952
ID: 24073953
This particular customer is license for CPFW-ENC-U-NG  which allows you to upgrade to VPN-1 module.  Also, I've verified that the external IP address is licensed.  
0
 
LVL 4

Expert Comment

by:Multipath
ID: 24074050
Are there in messages in the message file when you try to start it?  I am not sure what platform you are on.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 

Accepted Solution

by:
hotrod_952 earned 0 total points
ID: 24090208
I called Checkpoint User Center and they mention that this particular license is for gateway encryption.  In order for them to have VPN capabilities they must purchase additional licenses.  This explains why after I create the remote access VPN they gateway was accessible from secure remote.
0
 

Author Comment

by:hotrod_952
ID: 24090222
Thanks
0
 
LVL 4

Expert Comment

by:Multipath
ID: 24093291
As I commented in the first reply

"Do a cplic print and make sure the vpn module is there.  I think your issue is the VPN not coming up which could be due to many things like ip address not matching license or not being licensed."

As this was the problem should I not be given the points?
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now