- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Unable to access new checkpoint gateway using ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unable to access new checkpoint gateway using WebUI
we can't access our new checkpoint gateway using WebUI from the management interface. when have configured the IP Address 192.168.1.2 255.255.255.0 on the computer, we tried to access https://192.168.1.1 on the browser but it's not working.
Note: Firewall Is disabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have an ARP entry and does ping work?
Any proxy settings in the browser that need to be bypassed, what browser is used?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have tried Firefox, Chrome, and Microsoft Edge. And we have changed the proxy setting to no proxy. Ping is working, but we can't browse.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello. Maybe you have another host with the same ip-address in your network? Why don't you try to reach SG via 192.168.1.2 (if you assigned this address to one of the interfaces)? Is it an appliance, right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, it's an appliance, but it doesn't work as you suggested.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I saw ping is OK, but it is not possible to ping firewall by default. How did you turn off the firewall?
Also I don't know anything about your network, maybe it's huge, with many hosts, and 192.168.1.1/2 is popular, maybe you pinged something else.
1) You can try to ping the your machine FROM the SG to make sure there is network availability.
2) You can check the states of interfaces (show interfaces all OR show interface eth0/mgmt/etc.). Maybe interface is down.
3) You can change ip-address to a less used one.
Also you didn't write what does "it's not working" mean. Error? Endless website loading? Just light-grey screen? 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First, I would ensure nothing else is conflicting with that IP address, as that definitely could be a possibility. When you run arp -a on the firewall, what do you see? Also, IF you changed default web UI port, then it wont work if you have default filter or initial policy loaded, so please run fw stat and see whats there. If it says one of 2 I mentioned, run fw unloadlocal and it will most likely work. K, let me rephrase that...even with initial policy, web UI would work, but ONLY on port 443, nothing else. Also check below commands from clish.
Hope that helps.
[Expert@quantum-firewall:0]# clish
squantum-firewall> show web daem
quantum-firewall> show web daemon-enable
WebDaemonEnable on
quantum-firewall> show web ssl-
quantum-firewall> show web ssl-port
web-ssl-port 4434
quantum-firewall>
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What precise appliance is this running what precise version of code?
Or if you installed in a VM, please specify the RAM/CPU/HDD used for the VM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is this a physical appliance? Can you connect a laptop configured with IP 192.168.1.2/24 directly to the management port (192.168.1.1) on the appliance and access the webUI?
Dave
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i met same situation, how to fix it bro? Please update information.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
One of my colleagues told me that customer had the issue after jumbo hotfix and point 11 from below sk fixed it. You may want to verify all of points listed to see what could apply to your case.
Andy
