Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

cannot install checkpoint policy

Posted on 2013-01-03
4
Medium Priority
?
841 Views
Last Modified: 2013-01-09
I have the need for some help with my old checkpoint NG FP3

I have tried to revoke and create a new IKE Cert for use in my vpn and now my policy will not install

When I try to push the policy, it verifies and then sits on installing (for hours) with no errors .

I can abort and no policy changes were put in place (as in the old policy is still active)

HELP!
Ray
0
Comment
Question by:funray
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 13

Expert Comment

by:Sandy
ID: 38742923
i believe you need to select the appropriate cert in tunnel config also. Please check
0
 

Author Comment

by:funray
ID: 38743970
There is no where to select the cert in the tunnel config.  All I can do is select participating gateways

To be clear
1. I have revoked and created a new cert (using internal CA) on the checkpoint node
Before I could do this I had to remove the CP object as a participating gateway in the tunnel.

2. when I try to push the policy, the progress shows that it verifies OK but will not push the policy in. it just waits to infinity.  

3. The smartdashboard does not lock up, I am able to abort the push, and the old policy is still in place

it is as if the pushing is waiting for something to happen and it has no timeout
0
 

Accepted Solution

by:
funray earned 0 total points
ID: 38744093
Ok, i solved the problem.

my etc/hosts file  had the host name resolve to 127.0.0.1
once i changed it to the ip specified in the CP Object,  everything installed smoothly

I consider this issue resolved .
thx
0
 

Author Closing Comment

by:funray
ID: 38758221
The reason is because I figured it out on my own.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Like many others, when I created a Windows 2008 RRAS VPN server, I connected via PPTP, and still do, but there are problems that can arise from solely using PPTP.  One particular problem was that the CFO of the company used a Virgin Broadband Wirele…
Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question