<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gaia WebUI connection reset in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190736#M35200</link>
    <description>&lt;P&gt;Is it only a particular segment that’s having an issue or from anywhere?&lt;BR /&gt;Is the Platform Portal port in the Cluster object to to use port 4434?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2023 13:49:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-08-28T13:49:32Z</dc:date>
    <item>
      <title>Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190685#M35187</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I need help about situation bellow: i have a cluster with 2 security gateways 6200 and version R81.10 jumbo hotfix take 109. When a trying access Gaia Webui in the port 4434 i see in tcpdump that connection reset. This behavor happens in both gateways, in the same in segment network. I've been around for some SK's like sk118801, sk97648, sk91380 and sk8456, but unsuccessfully. Does anyone have any ideas about this problem?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log:&lt;/P&gt;&lt;P&gt;[Expert@sg-02:0]# tcpdump -nni any port 4434&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes&lt;BR /&gt;01:04:50.861888 ethertype IPv4, IP 192.168.2.102.55182 &amp;gt; 192.168.2.103.4434: Flags [S], seq 2801337733, win 29200, options [mss 1460,sackOK,TS val 1588764672 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;01:04:50.861888 IP 192.168.2.102.55182 &amp;gt; 192.168.2.103.4434: Flags [S], seq 2801337733, win 29200, options [mss 1460,sackOK,TS val 1588764672 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;01:04:50.862435 IP 192.168.2.103.4434 &amp;gt; 192.168.2.102.55182: Flags [R.], seq 0, ack 2801337734, win 0, length 0&lt;BR /&gt;01:04:50.862438 ethertype IPv4, IP 192.168.2.103.4434 &amp;gt; 192.168.2.102.55182: Flags [R.], seq 0, ack 1, win 0, length 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Mon Aug 28 00:29:50.567941 2023] [mpm_prefork:notice] [pid 16389] AH00169: caught SIGTERM, shutting down&lt;BR /&gt;[Mon Aug 28 00:29:52.641150 2023] [mime_magic:error] [pid 18542] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic&lt;BR /&gt;[Mon Aug 28 00:29:52.655702 2023] [so:warn] [pid 18542] AH01574: module setenvif_module is already loaded, skipping&lt;BR /&gt;[Mon Aug 28 00:29:52.655719 2023] [so:warn] [pid 18542] AH01574: module headers_module is already loaded, skipping&lt;BR /&gt;[Mon Aug 28 00:29:52.658564 2023] [core:warn] [pid 18542] AH00117: Ignoring deprecated use of DefaultType in line 421 of /web/conf/httpd2.conf.&lt;BR /&gt;AH00558: httpd2: Could not reliably determine the server's fully qualified domain name, using 192.168.2.103. Set the 'ServerName' directive globally to suppress this message&lt;BR /&gt;[Mon Aug 28 00:29:52.658751 2023] [mime_magic:error] [pid 18542] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic&lt;BR /&gt;[Mon Aug 28 00:29:52.658796 2023] [ssl:warn] [pid 18542] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]&lt;BR /&gt;[Mon Aug 28 00:29:52.660513 2023] [mpm_prefork:notice] [pid 18542] AH00163: CPWS/2.4.55 (Unix) OpenSSL/1.1.1t configured -- resuming normal operations&lt;BR /&gt;[Mon Aug 28 00:29:52.660552 2023] [core:notice] [pid 18542] AH00094: Command line: '/web/cpshared/web/Apache/2.2.0/bin/httpd2 -f /web/conf/httpd2.conf -D FOREGROUND&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 04:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190685#M35187</guid>
      <dc:creator>eltonsimoes</dc:creator>
      <dc:date>2023-08-28T04:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190736#M35200</link>
      <description>&lt;P&gt;Is it only a particular segment that’s having an issue or from anywhere?&lt;BR /&gt;Is the Platform Portal port in the Cluster object to to use port 4434?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 13:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190736#M35200</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-28T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190749#M35202</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This behavor is from anywhere. Yes, in the Platform Portal it is configured to use port 4434.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:20:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/190749#M35202</guid>
      <dc:creator>eltonsimoes</dc:creator>
      <dc:date>2023-08-28T14:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/197539#M36902</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/57113"&gt;@eltonsimoes&lt;/a&gt;&amp;nbsp; is it resolved. we are facing same issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 05:47:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/197539#M36902</guid>
      <dc:creator>vishnusecurrent</dc:creator>
      <dc:date>2023-11-09T05:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/198336#M37117</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69542"&gt;@vishnusecurrent&lt;/a&gt;not yet!&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2023 13:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/198336#M37117</guid>
      <dc:creator>eltonsimoes</dc:creator>
      <dc:date>2023-11-18T13:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/202812#M38161</link>
      <description>&lt;P&gt;Did you managed to resolve? Found same problem on 6200 cluster on 81.10JHF110&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 10:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/202812#M38161</guid>
      <dc:creator>LadaNemecek</dc:creator>
      <dc:date>2024-01-11T10:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203367#M38297</link>
      <description>&lt;P&gt;I have the same issue with a 3600 running with R81.10 JHF41&lt;BR /&gt;netstat -a&amp;nbsp;shows no listener on port 4434 which is set correctly.&amp;nbsp;&lt;BR /&gt;the other cluster member runs fine&lt;/P&gt;&lt;P&gt;when restarting the service, this could be seen in&amp;nbsp;httpd2_error_log:&lt;BR /&gt;[ssl:warn] [pid 508] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]&lt;BR /&gt;&amp;nbsp;but&amp;nbsp;&lt;BR /&gt;--&amp;gt; LoadModule socache_shmcb_module modules/libmod_socache_shmcb.so - is active in httpd2.conf&lt;/P&gt;&lt;P&gt;and&lt;BR /&gt;AH00558: httpd2: Could not reliably determine the server's fully qualified domain name, using 172.xxx,xxx.3 Set the 'ServerName' directive globally to suppress this message&lt;BR /&gt;and&lt;BR /&gt;[mime_magic:error] [pid 508] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic&lt;/P&gt;&lt;P&gt;on the running member the correct lines follow and the service starts:&lt;BR /&gt;[ssl:warn] [pid 10019] AH01906: 172.xx.xxx.2:4434:0 server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)&lt;BR /&gt;[ssl:warn] [pid 10019] AH01909: 172.xx.xxx.2:4434:0 server certificate does NOT include an ID which matches the server name&lt;BR /&gt;we follow sk84561 up to step 12, but no deeper hints found&lt;/P&gt;&lt;P&gt;kernel debug I want to take tommorow&lt;BR /&gt;&lt;BR /&gt;any ideas ? TAC case needed ?&lt;/P&gt;&lt;P&gt;best regards&lt;BR /&gt;Gero&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 15:32:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203367#M38297</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2024-01-17T15:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203373#M38300</link>
      <description>&lt;P&gt;when searching inet I would like to check thisout:&lt;BR /&gt;when there is a&amp;nbsp;&lt;SPAN&gt;httpd-ssl.conf&lt;/SPAN&gt;&lt;BR /&gt;adding this line&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;SSLSessionCache "shmcb:logs/ssl_scache(512000)"&lt;/SPAN&gt;&lt;BR /&gt;tomorrow I will have a new session with my customer to try out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;best regards&lt;BR /&gt;Gero&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 15:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203373#M38300</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2024-01-17T15:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203376#M38302</link>
      <description>&lt;P&gt;But I found this by investigating the cpinfo&amp;nbsp;&lt;BR /&gt;in /tmp/cpinfo_hcp_log&lt;BR /&gt;+------------------------------------------------------------------------------------------------------------------------------------+&lt;BR /&gt;| Gaia OS/General/HTTPD SSL CONF FILE |&lt;BR /&gt;+------------------------------------------------------------------------------------------------------------------------------------+&lt;BR /&gt;| Result: ERROR |&lt;BR /&gt;| |&lt;BR /&gt;| Description: Verify httpd-ssl.conf.templ is correct |&lt;BR /&gt;| |&lt;BR /&gt;| Summary: File httpd-ssl.conf.templ may be empty or corrupted! |&lt;BR /&gt;| |&lt;BR /&gt;| Finding: |&lt;BR /&gt;| File httpd-ssl.conf.templ may be empty or corrupted! |&lt;BR /&gt;| |&lt;BR /&gt;| Suggested solutions: |&lt;BR /&gt;| - Replace file /web/templates/httpd-ssl.conf.templ with the one in /web/templates/httpd-ssl.conf.templ.bak |&lt;BR /&gt;| you may run the following: |&lt;BR /&gt;| 1. /usr/bin/cp /web/templates/httpd-ssl.conf.templ.bak /web/templates/httpd-ssl.conf.templ |&lt;BR /&gt;| 2. /bin/template_xlate : /web/templates/httpd-ssl.conf.templ /web/conf/extra/httpd-ssl.conf &amp;lt; /config/active |&lt;BR /&gt;| 3. tellpm process:httpd2 |&lt;BR /&gt;| 4. tellpm process:httpd2 t |&lt;BR /&gt;| |&lt;BR /&gt;| |&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So I like to follow up this, because all files are generated by templates and should not be manipulated manualy&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;so far&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Gero&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this correlates to&amp;nbsp;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180829" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180829&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;lets see tomorrow.....&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 16:38:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/203376#M38302</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2024-01-17T16:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205675#M38826</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/22723"&gt;@Gero_Stolle&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Was the problem resolved by applying sk180829? Thanks for sharing!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Elton Simões&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2024 05:40:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205675#M38826</guid>
      <dc:creator>eltonsimoes</dc:creator>
      <dc:date>2024-02-11T05:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205706#M38832</link>
      <description>&lt;P&gt;That seems like a resonable process to try.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 00:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205706#M38832</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-12T00:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205715#M38833</link>
      <description>&lt;P&gt;Yes, following &lt;A href="https://support.checkpoint.com/results/sk/sk180829" target="_blank" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk180829&lt;/A&gt;&lt;BR /&gt;was successful, webgui accessible again. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 07:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205715#M38833</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2024-02-12T07:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia WebUI connection reset</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205749#M38834</link>
      <description>&lt;P&gt;Excellent!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 12:07:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-WebUI-connection-reset/m-p/205749#M38834</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-12T12:07:33Z</dc:date>
    </item>
  </channel>
</rss>

