<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIC issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17581#M93401</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;honestly I’d re-do ClusterXL from scratch otherwise you may look 7 days for causes and end up nowhere.  Hard time for you mate hit truth is that investigation may take you days if nit weeks ...&lt;/P&gt;&lt;P&gt;Follw the sk’s and rebuild HA. Easiest option imho.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Aug 2018 13:54:36 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2018-08-10T13:54:36Z</dc:date>
    <item>
      <title>SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17559#M93379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a cluster of 2 5000 Appliances, running R80.10.&lt;/P&gt;&lt;P&gt;My trooble is one of the member, the standby, has lost SIC with the SMS. The Active is running well, but i can't push new policies.&lt;/P&gt;&lt;P&gt;I tried 30 times to reset SIC between the standby and the SMS, but always got error (300, 148).&lt;/P&gt;&lt;P&gt;So about 30 revoked certs on the SMS ...&lt;/P&gt;&lt;P&gt;My question is : must i reset both gateways SIC (even the active) ?&lt;/P&gt;&lt;P&gt;If so, as i can't push policies, what would happen for the active GW ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17559#M93379</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-09T08:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17560#M93380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First question would be to determine why a standby member is not able to maintain SIC.&lt;/P&gt;&lt;P&gt;there is no basically no need to reset it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please elaborate architecture first: FULL HA or Distributed ?&lt;BR /&gt;&lt;BR /&gt;Once SIC is establish, you can push once and then you are blocked? &lt;BR /&gt;New installation ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:11:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17560#M93380</guid>
      <dc:creator>Anthony_Joubai1</dc:creator>
      <dc:date>2018-08-09T08:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17561#M93381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Anthony (french?)&lt;/P&gt;&lt;P&gt;The cluster was working well since February. There is no Nat (Lan firewalling), and is in Active/Passive mode with HA.&lt;/P&gt;&lt;P&gt;Both GW are on the same vlan but not on the same as SMS but as i said, active one works well. I can ping SMS from active and standby, and GW from SMS.&lt;/P&gt;&lt;P&gt;Ports 18191,18192 are Listen on the standby GW.&lt;/P&gt;&lt;P&gt;I started having problem when i pushed a modified policy. I ran into an error of services port conflict (Uncheck match for any checkbox ...).&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:43:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17561#M93381</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-09T08:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17562#M93382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you run the following commands, &lt;BR /&gt;fw ctl zdebug drop | grep &amp;lt;SmartcenterIP&amp;gt; on both firewalls. and try to check SIC status on the object. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We may have the answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the cluster objects, which IP are used for cluster member (private/public)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would be delighted to discuss about this case in the french section &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/groups/checkmates-en-français" title="https://community.checkpoint.com/groups/checkmates-en-fran%C3%A7ais"&gt;CheckMates en Français&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17562#M93382</guid>
      <dc:creator>Anthony_Joubai1</dc:creator>
      <dc:date>2018-08-09T08:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17563#M93383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i'd also prefer move to french section. How can we do ?&lt;/P&gt;&lt;P&gt;Let's talk about my IP :&lt;/P&gt;&lt;P&gt;Active GW : 10.30.255.241&lt;/P&gt;&lt;P&gt;Standby GW : 10.30.255.243&lt;/P&gt;&lt;P&gt;SmartCenter : 10.33.1.130&lt;/P&gt;&lt;P&gt;The results of the command :&lt;/P&gt;&lt;P&gt;On the active GW :&lt;/P&gt;&lt;P&gt;Packet proto=6 10.33.1.130:55216 -&amp;gt; 10.30.255.243:18192 dropped by fw_tcp_state_update Reason: Illegal post SYN packet;&lt;/P&gt;&lt;P&gt;On the standby GW : nothing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 09:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17563#M93383</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-09T09:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17564#M93384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Solution could be on both member to &lt;/P&gt;&lt;P&gt;On the fly :&lt;BR /&gt;# fw ctl set int fwha_forw_packet_to_not_active 1&lt;/P&gt;&lt;P&gt;doesn't survive reboot&lt;/P&gt;&lt;P&gt;If it correct the problem, we will add it to the fwkern.conf.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 09:35:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17564#M93384</guid>
      <dc:creator>Anthony_Joubai1</dc:creator>
      <dc:date>2018-08-09T09:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17565#M93385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If were&amp;nbsp; in your shoes and have had such circumstance I would have first determine all the aspects of the routing between the CoreXL Cluster and SMS/MDS then troubleshoot the SIC issue but narrowing the protocol flow by fw monitor. It may occure sometimes that one of the HA memebers lost SIC but essentially when it does the HA has no Management capabilities at all as you cannot push policy to one member only can you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if the certs can be removed from the none-working member first and then try to re-establish a SIC with the Cluster instead of the none working member (cpconfig on Active member).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if not - seek sk in Support Center - there was something about it ... let me try to locate it myself just now ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 09:47:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17565#M93385</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-09T09:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17566#M93386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk62873 then sk30579&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 09:49:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17566#M93386</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-09T09:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17567#M93387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, here are the latest news: &lt;/P&gt;&lt;P&gt;@Anthony : fwha_forw_packet_to_not_active 1 : didn't solved.&lt;/P&gt;&lt;P&gt;@Jerry : couldn't find a way to remove the GW certificates.&lt;/P&gt;&lt;P&gt;In the ICA WebGUI (Management Tool), are all the revoked certificates for the non-working GW. I think i can delete them (confirm ?). There is also the valid one for the active GW, which is valid.&lt;/P&gt;&lt;P&gt;I found this : &lt;A class="link-titled" href="https://www.empirion.co.uk/checkpoint/regenerate-the-internal-ca-without-breaking-sic/" title="https://www.empirion.co.uk/checkpoint/regenerate-the-internal-ca-without-breaking-sic/"&gt;Regenerate the Internal CA Without Breaking SIC&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could it be useful ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 12:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17567#M93387</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-09T12:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17568#M93388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fw debug cpca on TDERROR_ALL_ALL=5 &lt;/P&gt;&lt;P&gt;might be interesting as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 12:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17568#M93388</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2018-08-09T12:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17569#M93389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes indeed you can (just check the issue date beforehand) &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;reg. Regenerate - indeed that may come helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;you’re the man, best of luck !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 12:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17569#M93389</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-09T12:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17570#M93390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Judging from logs traffic from mgmt arrives on different interface (not 10.30.255.x) so you can try /32 routing solution provided here in case packets are not forwarded to standby member correctly. It's more to the end of the thread.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/message/13561-re-problem-accessing-standby-cluster-member-from-non-local-network?commentID=13561" target="_blank"&gt;https://community.checkpoint.com/message/13561-re-problem-accessing-standby-cluster-member-from-non-local-network?commentID=13561&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:07:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17570#M93390</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-21T09:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17571#M93391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fw unloadlocal on problematic node during issue to see if this is rulebase related ?&lt;/P&gt;&lt;P&gt;Also, did you try "fw ctl zdebug + drop | grep &amp;lt;SMS_IP&amp;gt;" as was suggested ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 18:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17571#M93391</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-09T18:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17572#M93392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;Seems to be endless problem. I've tried all you suggested me, but with no luck.&lt;/P&gt;&lt;P&gt;I think factory-default is the next step. As it's the first time for me, i'm a little bit confused &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Will i be able to reattach the GW to the cluster after that ?&lt;/P&gt;&lt;P&gt;Are there some actions to do before factory-default ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17572#M93392</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-10T07:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17573#M93393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;don’t do defaulting just re-do full HA SIC again (yes, from scratch) - unless you don’t have console/mgmt access to the ClusterXL HW (VM/APPL).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do the SIC again with the Management but first, make sure you’ve got IP connectivity with the MGMT server and HA memebers can individually reach out to the SMS host/s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what about the routing table ? did you compare the routing tables from BOTH HA members?&lt;/P&gt;&lt;P&gt;I have had such case where both Members have had DIFFERENCES between themselves. It might be the case of simply connectivity or ... NIC associations?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17573#M93393</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-10T07:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17574#M93394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agree with Jerry, don't Reset the box, as long as the source problem is not identified.&lt;/P&gt;&lt;P&gt;Please contact your support &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;A quick remote and the problem will be solved without Reset the Box. &lt;BR /&gt;&lt;BR /&gt;regards,&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17574#M93394</guid>
      <dc:creator>Anthony_Joubai1</dc:creator>
      <dc:date>2018-08-10T07:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17575#M93395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;agree with Anthony, call the Support, unless you’ve got no valid contract (valid support) with the Vendor. If you don’t then ... you may need to digg into the details of the design mate &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17575#M93395</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-10T07:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17576#M93396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jerry, what do you mean by "re-do full HA SIC again (yes, from scratch)" ?&lt;/P&gt;&lt;P&gt;Do you speak about &lt;A class="" href="https://www.empirion.co.uk/checkpoint/regenerate-the-internal-ca-without-breaking-sic/" rel="nofollow"&gt;Regenerate the Internal CA Without Breaking SIC&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;It's the only thing i haven't done yet (too scared to loose the working box !)&lt;/P&gt;&lt;P&gt;About connectivity, both GWs can ping the SMS, but they don't ping each other.&lt;/P&gt;&lt;P&gt;SMS can ping both GWs.&lt;/P&gt;&lt;P&gt;Routing table are the same on both GWs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 08:36:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17576#M93396</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-10T08:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17577#M93397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in that case yes, I think this is the only way to regenerate a SIC with CA without breaking the communication entirely, however I would be careful though if something bad happen so that I&amp;nbsp;can still securely access Management IPs from the HA members.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 11:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17577#M93397</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-08-10T11:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: SIC issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17578#M93398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found something strange in the smartcenter logs : &lt;/P&gt;&lt;P&gt;from SMS to non-working GW : DROP/&amp;nbsp; CDP_amon (18192) / Data received before SYN was acknowledged. Stripping all packet data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIC-issue/m-p/17578#M93398</guid>
      <dc:creator>GUEYDON_Olivier</dc:creator>
      <dc:date>2018-08-10T12:08:18Z</dc:date>
    </item>
  </channel>
</rss>

