<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Gateway fails to connect Gaia Portal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115522#M16251</link>
    <description>&lt;P&gt;Easy trick to fix this...windows + R -&amp;gt; iexplore -&amp;gt; once you open old explorer, go to tools -&amp;gt; internet options -&amp;gt; check all ssl tls options at the bottom -&amp;gt; hit ok -&amp;gt; try again. Im 99% sure it will work.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Apr 2021 16:59:15 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-04-07T16:59:15Z</dc:date>
    <item>
      <title>Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115490#M16242</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a pair of 5800 gateways running R80.10 - since the moment I started working on them I noticed I cannot access the Gaia Portal to complete their configuration via Smart Wizard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I Have tried 3 different browsers (Chrome, FireFox, Explorer) but nothing works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to restart the httpd2 process, but unfortunately that didn't help as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the httpd2 error log output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Gateway ip addr is 1.1.1.1/24&amp;nbsp;&lt;/P&gt;&lt;P&gt;**here is the output of the httpd2 error logs:&lt;/P&gt;&lt;P&gt;[Wed Apr 07 11:17:46.148003 2021] [ssl:info] [pid 17114] [client 4.4.4.4:57663] AH01964: Connection to child 1 established (server 1.1.1.1:443)&lt;BR /&gt;[Wed Apr 07 11:17:46.148102 2021] [ssl:debug] [pid 17114] ssl_engine_kernel.c(1949): [client 4.4.4.4:57663] AH02645: Server name not provided via TLS extension (using default/first virtual host)&lt;BR /&gt;[Wed Apr 07 11:17:46.148269 2021] [ssl:info] [pid 17116] [client 4.4.4.4:57664] AH01964: Connection to child 3 established (server 1.1.1.1:443)&lt;BR /&gt;[Wed Apr 07 11:17:46.148341 2021] [ssl:debug] [pid 17116] ssl_engine_kernel.c(1949): [client 4.4.4.4:57664] AH02645: Server name not provided via TLS extension (using default/first virtual host)&lt;BR /&gt;[Wed Apr 07 11:17:48.164178 2021] [reqtimeout:info] [pid 17114] [client 4.4.4.4:57663] AH01382: Request header read timeout&lt;BR /&gt;[Wed Apr 07 11:17:48.164192 2021] [ssl:debug] [pid 17114] ssl_engine_io.c(1212): (70007)The timeout specified has expired: [client 4.4.4.4:57663] AH02007: SSL handshake interrupted by system [Hint: Stop button pressed in browser?!]&lt;BR /&gt;[Wed Apr 07 11:17:48.164197 2021] [ssl:info] [pid 17114] [client 4.4.4.4:57663] AH01998: Connection closed to child 1 with abortive shutdown (server 1.1.1.1:443)&lt;BR /&gt;[Wed Apr 07 11:17:48.165199 2021] [reqtimeout:info] [pid 17116] [client 4.4.4.4:57664] AH01382: Request header read timeout&lt;BR /&gt;[Wed Apr 07 11:17:48.165217 2021] [ssl:debug] [pid 17116] ssl_engine_io.c(1212): (70007)The timeout specified has expired: [client 4.4.4.4:57664] AH02007: SSL handshake interrupted by system [Hint: Stop button pressed in browser?!]&lt;BR /&gt;[Wed Apr 07 11:17:48.165222 2021] [ssl:info] [pid 17116] [client 4.4.4.4:57664] AH01998: Connection closed to child 3 with abortive shutdown (server 1.1.1.1:443)&lt;BR /&gt;[Wed Apr 07 11:29:58.955943 2021] [core:info] [pid 17109] AH00096: removed PID file /var/run/httpd2.pid (pid=17109)&lt;BR /&gt;[Wed Apr 07 11:29:58.955956 2021] [mpm_prefork:notice] [pid 17109] AH00169: caught SIGTERM, shutting down&lt;BR /&gt;[Wed Apr 07 11:30:02.488435 2021] [mime_magic:error] [pid 32593] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic&lt;BR /&gt;[Wed Apr 07 11:30:03.001587 2021] [ssl:warn] [pid 32593] AH01906: 1.1.1.1:443:0 server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)&lt;BR /&gt;[Wed Apr 07 11:30:03.001600 2021] [ssl:warn] [pid 32593] AH01909: 1.1.1.1:443:0 server certificate does NOT include an ID which matches the server name&lt;BR /&gt;[Wed Apr 07 11:30:03.009620 2021] [so:warn] [pid 32593] AH01574: module setenvif_module is already loaded, skipping&lt;BR /&gt;[Wed Apr 07 11:30:03.009629 2021] [so:warn] [pid 32593] AH01574: module headers_module is already loaded, skipping&lt;BR /&gt;[Wed Apr 07 11:30:03.011242 2021] [core:warn] [pid 32593] AH00117: Ignoring deprecated use of DefaultType in line 420 of /web/conf/httpd2.conf.&lt;BR /&gt;AH00558: httpd2: Could not reliably determine the server's fully qualified domain name, using 1.1.1.1. Set the 'ServerName' directive globally to suppress this message&lt;BR /&gt;[Wed Apr 07 11:30:03.011398 2021] [mime_magic:error] [pid 32593] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic&lt;BR /&gt;[Wed Apr 07 11:30:04.000646 2021] [ssl:warn] [pid 32593] AH01906: 1.1.1.1:443:0 server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)&lt;BR /&gt;[Wed Apr 07 11:30:04.000657 2021] [ssl:warn] [pid 32593] AH01909: 1.1.1.1:443:0 server certificate does NOT include an ID which matches the server name&lt;BR /&gt;[Wed Apr 07 11:30:04.002698 2021] [mpm_prefork:notice] [pid 32593] AH00163: CPWS/2.4.16 (Unix) OpenSSL/1.0.1p configured -- resuming normal operations&lt;BR /&gt;[Wed Apr 07 11:30:04.002714 2021] [core:notice] [pid 32593] AH00094: Command line: '/web/cpshared/web/Apache/2.2.0/bin/httpd2 -f /web/conf/httpd2.conf -D FOREGROUND'&lt;/P&gt;&lt;P&gt;**the output of tcpdump -ni Mgmt port 443 -&lt;/P&gt;&lt;P&gt;[Expert@FwVero:0]# tcpdump -ni Mgmt port 443&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on Mgmt, link-type EN10MB (Ethernet), capture size 96 bytes&lt;BR /&gt;12:09:18.365857 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: S 292501612:292501612(0) win 8192 &amp;lt;mss 1460,nop,wscale 2,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:09:18.368609 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: . ack 1321397747 win 16625&lt;BR /&gt;12:09:18.369687 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: P 0:137(137) ack 1 win 16625&lt;BR /&gt;12:09:18.373318 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: P 137:495(358) ack 1242 win 16314&lt;BR /&gt;12:09:18.583904 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: . ack 1333 win 16625&lt;BR /&gt;12:09:18.584642 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: . ack 1333 win 16625 &amp;lt;nop,nop,sack 1 {1242:1333}&amp;gt;&lt;BR /&gt;12:09:20.421895 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: . ack 1403 win 16607&lt;BR /&gt;12:09:23.611619 IP 4.4.4.4.58667 &amp;gt; 1.1.1.1.https: R 495:495(0) ack 1403 win 0&lt;BR /&gt;12:09:27.617689 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: S 3703035644:3703035644(0) win 8192 &amp;lt;mss 1460,nop,wscale 2,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:09:27.620461 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: . ack 1152516678 win 16625&lt;BR /&gt;12:09:27.620625 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: P 0:169(169) ack 1 win 16625&lt;BR /&gt;12:09:27.623757 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: P 169:260(91) ack 171 win 16582&lt;BR /&gt;12:09:27.626365 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: F 260:260(0) ack 171 win 16582&lt;BR /&gt;12:09:27.626609 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: S 1569341768:1569341768(0) win 8192 &amp;lt;mss 1460,nop,wscale 2,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:09:27.629144 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: R 261:261(0) ack 240 win 0&lt;BR /&gt;12:09:27.629193 IP 4.4.4.4.58671 &amp;gt; 1.1.1.1.https: R 3703035906:3703035906(0) win 0&lt;BR /&gt;12:09:27.629356 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: . ack 3879169805 win 16625&lt;BR /&gt;12:09:27.629469 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: P 0:169(169) ack 1 win 16625&lt;BR /&gt;12:09:27.632546 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: P 169:260(91) ack 171 win 16582&lt;BR /&gt;12:09:27.635287 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: P 260:729(469) ack 171 win 16582&lt;BR /&gt;12:09:27.657449 IP 4.4.4.4.58672 &amp;gt; 1.1.1.1.https: . ack 171 win 16582&lt;BR /&gt;12:11:08.263681 IP 2.2.2.2.56342 &amp;gt; 1.1.1.1.https: S 2238622963:2238622963(0) win 65535 &amp;lt;mss 1460,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:11:08.267368 IP 2.2.2.2.56342 &amp;gt; 1.1.1.1.https: . ack 1094179899 win 1024&lt;BR /&gt;12:11:08.267725 IP 2.2.2.2.56342 &amp;gt; 1.1.1.1.https: P 0:180(180) ack 1 win 1024&lt;BR /&gt;12:11:08.277309 IP 2.2.2.2.56342 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;BR /&gt;12:11:10.288314 IP 2.2.2.2.56342 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;BR /&gt;12:11:17.338249 IP 2.2.2.2.56343 &amp;gt; 1.1.1.1.https: S 742014096:742014096(0) win 65535 &amp;lt;mss 1460,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:11:17.341970 IP 2.2.2.2.56343 &amp;gt; 1.1.1.1.https: . ack 676845258 win 1024&lt;BR /&gt;12:11:17.342370 IP 2.2.2.2.56343 &amp;gt; 1.1.1.1.https: P 0:180(180) ack 1 win 1024&lt;BR /&gt;12:11:17.351341 IP 2.2.2.2.56343 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;BR /&gt;12:11:19.363603 IP 2.2.2.2.56343 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;BR /&gt;12:11:28.713434 IP 2.2.2.2.56346 &amp;gt; 1.1.1.1.https: S 3725733948:3725733948(0) win 65535 &amp;lt;mss 1460,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;12:11:28.716443 IP 2.2.2.2.56346 &amp;gt; 1.1.1.1.https: . ack 2315813135 win 1024&lt;BR /&gt;12:11:28.719327 IP 2.2.2.2.56346 &amp;gt; 1.1.1.1.https: P 0:180(180) ack 1 win 1024&lt;BR /&gt;12:11:28.728326 IP 2.2.2.2.56346 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;BR /&gt;12:11:30.740611 IP 2.2.2.2.56346 &amp;gt; 1.1.1.1.https: . ack 1 win 1024 &amp;lt;nop,nop,sack 1 {1461:1567}&amp;gt;&lt;/P&gt;&lt;P&gt;36 packets captured&lt;BR /&gt;72 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;/P&gt;&lt;P&gt;I would appreciate any help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 11:49:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115490#M16242</guid>
      <dc:creator>veronikush29</dc:creator>
      <dc:date>2021-04-07T11:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115522#M16251</link>
      <description>&lt;P&gt;Easy trick to fix this...windows + R -&amp;gt; iexplore -&amp;gt; once you open old explorer, go to tools -&amp;gt; internet options -&amp;gt; check all ssl tls options at the bottom -&amp;gt; hit ok -&amp;gt; try again. Im 99% sure it will work.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 16:59:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115522#M16251</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-04-07T16:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115762#M16314</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="81D89FC0-7506-435C-8127-6D0E6EBAE1D4.jpeg" style="width: 1242px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11337iA689E6DBFFB81795/image-size/medium?v=v2&amp;amp;px=400" role="button" title="81D89FC0-7506-435C-8127-6D0E6EBAE1D4.jpeg" alt="81D89FC0-7506-435C-8127-6D0E6EBAE1D4.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Hi! Thank you for your reply, unfortunately it didn’t help &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;All the SSL TLS options are enabled, but the page is stuck in this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 06:23:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115762#M16314</guid>
      <dc:creator>veronikush29</dc:creator>
      <dc:date>2021-04-11T06:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115804#M16323</link>
      <description>&lt;P&gt;Did you click the "continue to this website (not recommended)" link?&lt;BR /&gt;And is this R80.10 with no JHF installed?&lt;BR /&gt;Maybe the issue is:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121373" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121373&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course, R80.10 is almost End of Support.&lt;BR /&gt;You should be using a later release.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 05:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/115804#M16323</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-12T05:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/154592#M26235</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What was the solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;Shira&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 07:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/154592#M26235</guid>
      <dc:creator>Shira</dc:creator>
      <dc:date>2022-08-05T07:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway fails to connect Gaia Portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/154639#M26239</link>
      <description>&lt;P&gt;Hi &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; it was a long time ago - but if I remember correctly it was an MTU problem somewhere in my network that caused this. After we changed the MTU to match everywhere it worked.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 12:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-fails-to-connect-Gaia-Portal/m-p/154639#M26239</guid>
      <dc:creator>veronikush29</dc:creator>
      <dc:date>2022-08-05T12:46:51Z</dc:date>
    </item>
  </channel>
</rss>

