Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
62742738
Participant

Cannot establish SIC between VSX gateway and SMS in ElasticXL VSNext setup R82

Hi, has anyone here experienced the same issue?

Setup: ElasticXL VSNext

Models: QF9400 and QF9100

I successfully established SIC between VS0 and the SMS on both devices. However, when adding VS1 and VS2, I always receive the error: "Failed to connect to the Security Gateway." I have attached a screenshot for reference.

We were initially running R82 JHF Take 60, then later upgraded to Take 91 (since it worked in lab simulation), but we are still experiencing the same issue.

I also tried resetting SIC via cpconfig, but it still did not resolve the problem.

0 Kudos
3 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There's no cpconfig for VSs in VSNext, so I think you reset SIC for VS0 when you did that. When you created the VS on the gateway, did you add a new interface to the management VSwitch or are you using a separate one? Does it have the right routes to the management server?

Editing for future historians: The cpconfig menu from the VS context is the correct place to reset SIC for a VS when using VSNext. I regret the error. 

0 Kudos
62742738
Participant

Hi @emmap ,

This is what I did to reset SIC for the VSs:

#vsenv 1

#cpconfig

then selected (5) Secure Internal Communication and input the SIC activation key. Then I tried to re-establish SIC in smartconsole but still fails.

we didn't configure a separate mgmt vswitch, we just used the default one. as for the routes, they are all in the same segment so there should be no problem.

we will try to rebuild it and see if we will encounter the same issue. 

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

OK so, earlier I was wrong, resetting SIC in cpconfig menu after setting your VS context is the right way to reset SIC, so you're good there. It sounds then more like you have a network connectivity issue - can the management server ping both VS0 and VS1? Can it resolve ARP for their IP addresses? Is the switch between them OK with having two different IPs and MAC addresses on the port facing the gateway?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events