Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gemechisd
Contributor
Jump to solution

Ping not working for Newly installed SMS Server

I have installed checkpoint R81.10 SMS for test purpose on Nutanix AHV. Now I can access the installed SMS server through SSH & Browser. But can not able to ping or login through smart console. 

0 Kudos
1 Solution

Accepted Solutions
HeikoAnkenbrand
Champion Champion
Champion

1) I think this is a layer 2 problem. Can you see the MAC address?
 # arp -an | grep 10.1.75.76

2) If the IP address 10.1.75.76 is a firewall module, a default security policy is installed as long as you have not yet installed a access policy. This means that you cannot ping the fw but you can uninstall the firewall policy and then you can ping the firewall.
# fw unloadlocal

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

View solution in original post

0 Kudos
(1)
13 Replies
Franktum
Contributor

Hi,

If you have SSH you can launch tcpdump on SMS in order to see whether the ICMPs and SmartConsole traffic are arriving to the machine. In this way you can narrow down the problem.

Regards

0 Kudos
gemechisd
Contributor

@Franktum 

I have captured any ping traffic using tcpdump on the Newly configured SMS Server. But the ping is not replying

Kindly, check the attached screenshot

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

1) I think this is a layer 2 problem. Can you see the MAC address?
 # arp -an | grep 10.1.75.76

2) If the IP address 10.1.75.76 is a firewall module, a default security policy is installed as long as you have not yet installed a access policy. This means that you cannot ping the fw but you can uninstall the firewall policy and then you can ping the firewall.
# fw unloadlocal

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
0 Kudos
(1)
Lesley
Leader Leader
Leader

Machines seem to be in the same network and I see arp request and reply in the capture. 

Are we sure mgmt has been installed and not gateway? What does cpstat mg output show? 

Maybe check with cpconfig -> check GUI clients and option 8

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

Very good point about running cpstat mg

0 Kudos
gemechisd
Contributor

@HeikoAnkenbrand 

Thank you. It worked for me after executing the commands you have sent me.

0 Kudos
the_rock
Legend
Legend

I agree with @HeikoAnkenbrand , you should check those things for sure.

Best,

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

Run fw stat.  If it says anything other than "Local Host is not a Firewall Module", you accidentally configured it as a standalone SMS/firewall, and the firewall default InitialPolicy is blocking your ping and SmartConsole connectivity.  If this is the case you will need to reload and answer correctly with only "Management Server" during the first-time wizard.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
the_rock
Legend
Legend

Definitely valid point.

Andy

0 Kudos
gemechisd
Contributor

@Timothy_Hall 

The ping is working for me. But I can't able to login through Smart Console. Check the attached screenshot for fwstat

Our SMS in installed on nutanix AHV with .qcow2 file from checkpoint. 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Which image / file from sk158292 did you use and which ftw selections were made?

CCSM R77/R80/ELITE
0 Kudos
Timothy_Hall
Legend Legend
Legend

You have accidentally configured it as a Security Gateway as well as Security Management Server (standalone) as I guessed earlier.  You need to reload and make sure that Security Gateway is unchecked during the first-time wizard.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
the_rock
Legend
Legend

100% no doubt about it, you configured it as standalone (fw + mgmt as one machine)

If it was ONLY mgmt, it would show below.

Andy

[Expert@cpazuremgmt:0]# fw stat
Local host is not a FireWall-1 module
[Expert@cpazuremgmt:0]#

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events