- CheckMates
- :
- Products
- :
- Developers
- :
- API / CLI Discussion
- :
- SIC Communication Between two Nodes
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SIC Communication Between two Nodes
If SIC communication is lost between Security management and security gateway, does it impact traffic?
And for how long can a SIC communication be lost between the two nodes?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, it does not, your Management server can't communicate with the node i.e. push the policy and get information from it (logs, SmartviewMonitor etc) but if the node has already installed Security Policy it will continue working.
As regards to the traffic passing the node there is no time limit - the Policy will not expire , it will not get AV/IPS updates / contract files/ new licenses but the status quo will remain as is.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It will impact your VPN traffic if the Security Management can't talk to it's Gateways for too long. When this impact happens depends on your settings. Default is 24 hours. Normal Non-VPN traffic wont't be affected.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right, certificate-based VPNs (which are typically Intranet VPNs) will die after about 24 hours if the CRL cannot be retrieved. VPN tunnels using a pre-shared key for authentication will not be affected.
Another consequence of SIC being broken is that the logs being generated by the firewall cannot be sent to the SMS, so they will be written to the firewall's local hard drive. If this goes on for long enough it could potentially run the firewall out of disk space which will cause some rather nasty problems.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
CET (Europe) Timezone Course Scheduled for July 1-2
