<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF Not Coming Up - Showing Auth Error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151789#M24972</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco side is not P2P OSPF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cisco Side OSPF Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2573&lt;/P&gt;&lt;P&gt;description XXXXXXXXXXXXXX&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address XX.XX.XX.XX 255.255.255.252&lt;/P&gt;&lt;P&gt;ip ospf authentication message-digest&lt;/P&gt;&lt;P&gt;ip ospf message-digest-key 3 md5 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP Version is 80.40 and Build is 309&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jun 2022 04:06:44 GMT</pubDate>
    <dc:creator>subrun_jamil</dc:creator>
    <dc:date>2022-06-26T04:06:44Z</dc:date>
    <item>
      <title>OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151748#M24934</link>
      <description>&lt;P&gt;I am working to bring the ospf, Look like it is throwing Auth error all the time. I doubt at the checkpoint side I am missing something.&lt;/P&gt;&lt;P&gt;What could be the issue ? It is a new setup and there are no SmartDash Board Server Installed at the moment. Plan was to make the OSPF Connectivity. At the moment there are no initial rules at this Firewall. So accepting all traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debug log from cisco Side ( which is other side of the ospf neighbor ).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jun 23 10:52:42.860 AST-Sum: OSPF-1 ADJ&amp;nbsp;&amp;nbsp; Vl2573: Rcv pkt from 10.7.248.26 : Mismatched Authentication key - ID 3.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cisco Side OSPF Config &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2573&lt;/P&gt;&lt;P&gt;description XXXXXXXXXXXXXX&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 10.7.248.25 255.255.255.252&lt;/P&gt;&lt;P&gt;ip ospf authentication message-digest&lt;/P&gt;&lt;P&gt;ip ospf message-digest-key 3 md5 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OSPF_Settings_at_CP_Side.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17037i88DBDDF38D3DE0EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="OSPF_Settings_at_CP_Side.jpg" alt="OSPF_Settings_at_CP_Side.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OSPF_Settings_at_CP_Side_2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17038i8A627630012FEF07/image-size/large?v=v2&amp;amp;px=999" role="button" title="OSPF_Settings_at_CP_Side_2.jpg" alt="OSPF_Settings_at_CP_Side_2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 20:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151748#M24934</guid>
      <dc:creator>subrun_jamil</dc:creator>
      <dc:date>2022-06-24T20:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151766#M24946</link>
      <description>&lt;P&gt;If there are no initial rules on the firewall, you are actually dropping all traffic, including OSPF:&lt;/P&gt;
&lt;P&gt;From Admin Guide: "Until the &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/The-Initial-Policy.htm#" target="_blank" rel="noopener" data-mc-state="closed" data-aria-describedby="70f03394-3e07-472b-90fc-39ff61324632"&gt;Security Gateway&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt; installs the &lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/The-Initial-Policy.htm#" target="_blank" rel="noopener" data-mc-state="closed" data-aria-describedby="fca34a64-b518-4275-b61a-9c503263b94e"&gt;Security Policy&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;on the &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt; for the first time, security is enforced by an Initial Policy.&lt;/P&gt;
&lt;P&gt;The Initial Policy operates by adding the predefined implied rules to the Default Filter policy.&lt;/P&gt;
&lt;P&gt;These implied rules forbid most communication, yet allow the communication needed for the installation of the &lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;Security Policy&lt;/SPAN&gt;. The Initial Policy also protects the &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt; during &lt;SPAN class="mc-variable Vars_Other.tp_cp variable"&gt;Check Point&lt;/SPAN&gt; product upgrades, when a &lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/The-Initial-Policy.htm#" target="_blank" rel="noopener" data-mc-state="closed" data-aria-describedby="cc67494c-91bd-4adb-991b-dd24739205a0"&gt;SIC&amp;nbsp;&lt;/A&gt;certificate is reset on the &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;, or in the case of a &lt;SPAN class="mc-variable Vars_Other.tp_cp variable"&gt;Check Point&lt;/SPAN&gt; product license expiration."&lt;/P&gt;
&lt;P&gt;To allow OSPF until policy is configured and installed:&lt;/P&gt;
&lt;P&gt;Execute "fw unloadlocal" in expert mode on this gateway, IF IT IS NOT in production, to actually remove the default policy.&lt;/P&gt;
&lt;P&gt;If you need for routing to work while in wide-open state, execute "echo 1 &amp;gt; /proc/sys/net/ipv4/ip_forward"&lt;/P&gt;
&lt;P&gt;That last one is actually courtesy of &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt; .&lt;/P&gt;
&lt;P&gt;To properly configure your policy for OSPF, see sk39960.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 00:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151766#M24946</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-06-25T00:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151773#M24951</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;is 100% right. You NEED rules to allow ospf, period.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 04:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151773#M24951</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-25T04:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151774#M24952</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your reply.&lt;/P&gt;&lt;P&gt;I used "fw unloadlocal" so I dont think OSPF is getting blocked. As I shared earlier it is throwing Auth Error. ( image attached before )&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW# cpstat -f policy fw&lt;/P&gt;&lt;P&gt;Product name: Firewall&lt;BR /&gt;Policy name:&lt;BR /&gt;Policy install time:&lt;BR /&gt;Num. connections: 0&lt;BR /&gt;Peak num. connections: 0&lt;BR /&gt;Connections capacity limit: 0&lt;BR /&gt;Total accepted packets: 0&lt;BR /&gt;Total dropped packets: 0&lt;BR /&gt;Total rejected packets: 0&lt;BR /&gt;Total accepted bytes: 0&lt;BR /&gt;Total dropped bytes: 0&lt;BR /&gt;Total rejected bytes: 0&lt;BR /&gt;Total logged: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 04:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151774#M24952</guid>
      <dc:creator>subrun_jamil</dc:creator>
      <dc:date>2022-06-25T04:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151775#M24953</link>
      <description>&lt;P&gt;Hmm...&lt;/P&gt;
&lt;P&gt;I'm a bit surprised to see the packet counters at 0.&lt;/P&gt;
&lt;P&gt;That said, there used to be issue in R77.30 days specific to OSPF auth due to mtu missmatch, sk109092.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 05:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151775#M24953</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-06-25T05:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151777#M24955</link>
      <description>&lt;P&gt;Which version &amp;amp; jumbo is this Gateway installed with?&lt;/P&gt;
&lt;P&gt;(Note OSPF network type point-to-point isn't supported if set on the Cisco side).&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 03:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151777#M24955</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-26T03:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151789#M24972</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco side is not P2P OSPF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cisco Side OSPF Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2573&lt;/P&gt;&lt;P&gt;description XXXXXXXXXXXXXX&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address XX.XX.XX.XX 255.255.255.252&lt;/P&gt;&lt;P&gt;ip ospf authentication message-digest&lt;/P&gt;&lt;P&gt;ip ospf message-digest-key 3 md5 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP Version is 80.40 and Build is 309&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 04:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151789#M24972</guid>
      <dc:creator>subrun_jamil</dc:creator>
      <dc:date>2022-06-26T04:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151790#M24973</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My version is R80.40. Will check to see if enabling&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Subtract Authlen &lt;/STRONG&gt;resolves the issue&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 04:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151790#M24973</guid>
      <dc:creator>subrun_jamil</dc:creator>
      <dc:date>2022-06-26T04:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151818#M25002</link>
      <description>&lt;P&gt;To clarify you already have the latest GA jumbo installed (&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/Take_158.htm" target="_self"&gt;JHF T158&lt;/A&gt;)?&lt;/P&gt;
&lt;P&gt;What's the password complexity like, have you experimented with something simple?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 08:30:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151818#M25002</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-27T08:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151853#M25010</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After setting key with a 16 character one it got resolved.&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;&lt;P&gt;To clarify you already have the latest GA jumbo installed (&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/Take_158.htm" target="_self" rel="noopener noreferrer"&gt;JHF T158&lt;/A&gt;)?&amp;nbsp; -- I do not know how to check this. Can you suggest&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;Thanks for your intention to constantly trying to help me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 14:56:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151853#M25010</guid>
      <dc:creator>subrun_jamil</dc:creator>
      <dc:date>2022-06-27T14:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151855#M25011</link>
      <description>&lt;P&gt;If you need to check anything, I got working ospf/bgp in the lab on latest R81.10 jumbo 61 version, so happy to show you.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 15:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151855#M25011</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-27T15:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Not Coming Up - Showing Auth Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151859#M25013</link>
      <description>&lt;P&gt;Glad it's resolved.&lt;/P&gt;
&lt;P&gt;From the CLI in Expert mode on the Gateway: "cpinfo -y all"&lt;/P&gt;
&lt;P&gt;This should output the currently installed hotfix level information.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 15:20:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-Not-Coming-Up-Showing-Auth-Error/m-p/151859#M25013</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-27T15:20:08Z</dc:date>
    </item>
  </channel>
</rss>

