Solved

cannot install checkpoint policy

Posted on 2013-01-03
4
839 Views
Last Modified: 2013-01-09
I have the need for some help with my old checkpoint NG FP3

I have tried to revoke and create a new IKE Cert for use in my vpn and now my policy will not install

When I try to push the policy, it verifies and then sits on installing (for hours) with no errors .

I can abort and no policy changes were put in place (as in the old policy is still active)

HELP!
Ray
0
Comment
Question by:funray
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 13

Expert Comment

by:Sandy
ID: 38742923
i believe you need to select the appropriate cert in tunnel config also. Please check
0
 

Author Comment

by:funray
ID: 38743970
There is no where to select the cert in the tunnel config.  All I can do is select participating gateways

To be clear
1. I have revoked and created a new cert (using internal CA) on the checkpoint node
Before I could do this I had to remove the CP object as a participating gateway in the tunnel.

2. when I try to push the policy, the progress shows that it verifies OK but will not push the policy in. it just waits to infinity.  

3. The smartdashboard does not lock up, I am able to abort the push, and the old policy is still in place

it is as if the pushing is waiting for something to happen and it has no timeout
0
 

Accepted Solution

by:
funray earned 0 total points
ID: 38744093
Ok, i solved the problem.

my etc/hosts file  had the host name resolve to 127.0.0.1
once i changed it to the ip specified in the CP Object,  everything installed smoothly

I consider this issue resolved .
thx
0
 

Author Closing Comment

by:funray
ID: 38758221
The reason is because I figured it out on my own.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question