Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cdooer
Participant

Changing IP on management server - How long do I have before I have to redo SIC

Hey everyone, We need to change the IP on our management server, and had initially been told by TAC that reestablishing SIC wouldn't be required, since the certificate was based on DNS name, which wasn't changing. Now I'm reading that SIC does need to be reestablished, since the management server IP is stored in the $CPDIR/registry/HKLM_registry.data file. BUT...the documentation also says this;

Symptoms
- SIC establishment is lost between gateway and mgmt server over time.
- No SIC connectivity to gateway

Since it says "over time", does anyone know what the trigger is that will cause SIC to start failing? Trying to plan this out, want to make sure I know exactly what's going to happen, and when. 

Thx,
dp

0 Kudos
16 Replies
PhoneBoy
Admin
Admin

Where precisely are you seeing this "over time" statement?

You should be able to re-establish SIC with the relevant gateways after changing the IP on the management by performing an Install Policy action to all gateways.
This will update the management IP on all the relevant gateways and re-establish connectivity.

Remember that the management is also the Internal Certificate Authority.
Part of that functionality is gateways checking on the validity of certificates issued by the ICA.
If the IP is different, then the Certificate Revocation List is not available.
At least for VPN, this will cause VPNs to start failing after 24 hours or so.

0 Kudos
Jim_Holmes
Employee Alumnus
Employee Alumnus

I have personally never seen this happen, not that it means it doesn't happen. I just always make sure to do an install database before I push the policy. It was my understanding that the Masters was all it was checking, and that is object-based. @PhoneBoy isn't the CRL pulled from the VPN certificate and not the SIC certificate? 

Aka, Chillyjim
0 Kudos
cdooer
Participant

They state this in this article, https://support.checkpoint.com/results/sk/sk103356

sssa.JPG

So are we all in agreement that SIC will automatically happen after I change the management IP, install database, then push a policy? Wondering if that file on the gateway automatically updates itself with the new IP?

0 Kudos
the_rock
Legend
Legend

Thats my experience, BUT, that does not always guarantee SIC wont need to be reset.

0 Kudos
Bob_Zimmerman
Authority
Authority

I suspect the "over time" might be talking about automatic renewal of the SIC certificates. Eventually, the cert will get close to expiring and will try to renew itself. Not sure which method it uses to get the management's IP to try to renew the cert, but if it doesn't try the new IP, the SIC cert will eventually expire. Doesn't disrupt traffic, but it does prevent policy installation and other things which depend on SIC.

0 Kudos
the_rock
Legend
Legend

You are referring to below:

https://support.checkpoint.com/results/sk/sk103356

In my experience, last time I did this, worked fine, no SIC reset, but then 3 times before that, it was needed...so, I have no clue in the world why its inconsistent : - )

0 Kudos
cdooer
Participant

I did just have a look on one of my VPN gateways, and that HKLM_registry.data file shows that it was updated 20 mins ago, even though no policy was pushed to it. Wonder if that file automatically updates on a certain interval, as the gateway is communicating with the management server?

0 Kudos
the_rock
Legend
Legend

Thats most likely true...I will let someone else confirm, but it would make logical sense.

 

Andy

0 Kudos
the_rock
Legend
Legend

Just checked my lab and though I never modified this file, shows today's date, so Im 100% sure its all automatic. Never knew that was the case, so thank you for bringing that point up 👍

Andy

[Expert@quantum-firewall:0]# cd /opt/CPshrd-R81.20/registry/
[Expert@quantum-firewall:0]# stat HKLM_registry.data
File: 'HKLM_registry.data'
Size: 143613 Blocks: 288 IO Block: 4096 regular file
Device: fc01h/64513d Inode: 35062378 Links: 1
Access: (0660/-rw-rw----) Uid: ( 0/ admin) Gid: ( 0/ root)
Access: 2023-07-20 10:06:59.652972485 -0400
Modify: 2023-07-20 10:06:59.482972476 -0400
Change: 2023-07-20 10:06:59.503972477 -0400
Birth: -
[Expert@quantum-firewall:0]#

0 Kudos
the_rock
Legend
Legend

I verified 100% based on test on 4 different VMs and 4 different CP versions *R80.30, R80.40, R81.10 and R81.20) that HKLm_registry.data file gets "refreshed" every 60 seconds...thats what it shows when I ran watch -d stat command on the file

Not sure if TAC would have any other official answer, but thats result I get.

Andy

0 Kudos
JozkoMrkvicka
Authority
Authority

can you try to cut the connection between gateway and management? Wondering if that file is refreshed only in case there is communication between GW and management.

Do you also see if there is some difference in regards to content of the file ? Is the content always the same, or some timestamps are updated within the file itself ? You can use "diff" command to compare the file before refresh (make a copy) and after refresh.

Kind regards,
Jozko Mrkvicka
0 Kudos
the_rock
Legend
Legend

Content is exactly the same every time I check it.

Andy

0 Kudos
cdooer
Participant

Hmm...what happens when you change the IP on your management server? Hehehe

0 Kudos
the_rock
Legend
Legend

I did that test today in my lab and all worked fine, no need to even do SIC reset. File content was the same.

0 Kudos
cdooer
Participant

That file contains the IP of the management server though, so I assume that this entry at least changed?

0 Kudos
the_rock
Legend
Legend

Yes...I changed it back since and its updated accordingly

Andy

[Expert@quantum-firewall:0]# grep -i 172.16.10.203 /opt/CPshrd-R81.20/registry/HKLM_registry.data
:ICAip (172.16.10.203)
[Expert@quantum-firewall:0]#

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events