Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
win2kshahid
Participant

Admin session is hanged and locked out in the MDS

An admin was trying to update a VPN ipsec certificate on the MDS for a specific fw domain.
It was interrupted due to network issues..

I can see the lock sign on it and the user who has the session cannot do anything.

MDS R82

Now the following has happened :

 

1. We cannot take over the session of the user or terminate the session.

2. We cannot edit anything regarding that specific Fw domain.

3. We tried to do mds stop and mds start, then we did a hardware reboot of the MDS, Mds stop/start of that specific fw.
Nothing is helping.

 

Take over does not work.
Discard changes dont work either.

 

Any ideas how we can terminate the user and get it back to normal ?

 

0 Kudos
13 Replies
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

Have you tried locating the Session and Discarding it using mgmt_cli?

There are several SKs on the issue but in most cases they suggest contacting TAC:
https://support.checkpoint.com/results/sk/sk167354

https://support.checkpoint.com/results/sk/sk133872

 

0 Kudos
win2kshahid
Participant

Thanks asked the engineer to try them now.

0 Kudos
win2kshahid
Participant

The page does not seem to show anything ?
Both of them besides mentioning the SK numbers.
How to know what do in the CLI ?

 

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

To view SKs you need to be logged in with your Product Center (User Center) / Support username

For CLI refer to:

https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-sessions~v2.0.1%20

 

There are other relevant topics before and after this one

0 Kudos
Vincent_Bacher

Without having a look at the SK articles i would do following using mgmt_cli
Having a look at the user's sessions and some info.

(echo "UID STATE MODE LOCKS CHANGES"; mgmt_cli -r true show sessions details-level full -f json | jq -r '.objects[] | select(.["user-name"] == "usename") | "\(.uid) \(.state) \(.["connection-mode"]) \((.locks|length)) \((.changes|length))"') | column -t



to delete all sessions of a user

mgmt_cli -r true show sessions details-level full -f json | jq -r '.objects[] | select(.["user-name"] == "username") | .uid' | xargs -I {} mgmt_cli -r true disconnect uid "{}"

 

But since the GUI does nothing other than make such API calls, I doubt that it will work for you.



and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Platinum
MVP Platinum

You need valid support account to view those SKs. 

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

0 Kudos
win2kshahid
Participant

Hi, it did not work. It kicked out all of the connected users but not the one we wanted to disconnect.

0 Kudos
Vincent_Bacher

Did you try cpstop and cpstart ?

cpstop ; cpstart


If yes, this is the point where i would recommend logging a sr at uc.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
the_rock
MVP Platinum
MVP Platinum

Since you said even reboot failed to solve this, definitely open TAC case.

Best,
Andy
0 Kudos
win2kshahid
Participant

Is it possible to install vpn certificate on the fw domain through CLI or is it locked to the same user in CLI as well ?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

My logical assumption would be its most likely locked as well.

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

No, because the underlying session is still locked.
The session must be published or discarded.

If you cannot do this through the standard mechanisms, then you will need TAC to assist you in removing it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events