Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

SIC - License

Hi Mates!!
Quick question:
If I reset the SIC on the firewall, could this cause any issues with the licenses?
Or are licenses completely independent from the SIC?

0 Kudos
3 Solutions

Accepted Solutions
_Val_
Admin
Admin

This really depends.

If you are using a central license, it will remain intact on the management, but may need to be reassigned to the GW after setting new SIC.

If the license is local, it will remain on the GW.

In either case, resetting SIC on the GW side will revert GW to the initial policy state.

View solution in original post

the_rock
MVP Platinum
MVP Platinum

Hey brother,

Put it this way. That would not do anything to the license...resetting SIC actually loads initial policy, so you need to install correct policy afterwards to get thigs working. Regardless of license type, it will stay there, wont be removed.

Best,
Andy

View solution in original post

0 Kudos
NicklasBargell
Employee Employee
Employee

Please bear in mind that when SIC reset is performed the firewall will not process traffic according to your policy, it will be processed according to what we call the "initial policy": The Initial Policy.

This can cause a traffic interruption if not done in the correct order. Here is some useful information: sk65764 - How to reset SIC

Regards,

Nicklas

View solution in original post

12 Replies
_Val_
Admin
Admin

This really depends.

If you are using a central license, it will remain intact on the management, but may need to be reassigned to the GW after setting new SIC.

If the license is local, it will remain on the GW.

In either case, resetting SIC on the GW side will revert GW to the initial policy state.

RemoteUser
Advisor

thanks @_Val_ 

0 Kudos
NicklasBargell
Employee Employee
Employee

Please bear in mind that when SIC reset is performed the firewall will not process traffic according to your policy, it will be processed according to what we call the "initial policy": The Initial Policy.

This can cause a traffic interruption if not done in the correct order. Here is some useful information: sk65764 - How to reset SIC

Regards,

Nicklas

the_rock
MVP Platinum
MVP Platinum

One way to get around it is to use below method, reset sic without cprestart, that would not load initial policy.

https://korkutozcan.com/how-to-reset-sic-without-restarting-check-point-gw/#:~:text=The%20normal%20w....

Best,
Andy
0 Kudos
_Val_
Admin
Admin

The post is very old, the rest is irrelevant and proven incorrect.

I have to say, this hack is absolutely NOT SUPPORTED and is essentially very old in the first place. Mentioning of obsolete appliances would be the first sign

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Ohhh...honestly, had no idea. I had given it to few people recently, worked really well, even in brand new versions. Anyway, good to know.

Best,
Andy
0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold
the_rock
MVP Platinum
MVP Platinum

Thanks for confirming Bob!

Best,
Andy
0 Kudos
_Val_
Admin
Admin

@Bob_Zimmerman, that's fair. I did not look it up. I modified my original response to make sure there is no confusion.

0 Kudos
PhoneBoy
Admin
Admin

There's an actual SK on resetting SIC without restarting: https://support.checkpoint.com/results/sk/sk86521 
Believe it's the same commands as mentioned in this post. 

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey brother,

Put it this way. That would not do anything to the license...resetting SIC actually loads initial policy, so you need to install correct policy afterwards to get thigs working. Regardless of license type, it will stay there, wont be removed.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

@RemoteUser 

If you feel more comfortable, we can do quick remote and I can demonstratre this in the lab on one of my R82 firewalls.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events