- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Checkpoint management server - lost access aft...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint management server - lost access after license expiry
Dear Experts,
The license had expired on our in production Checkpoint R77.30 management server and while we were in the process of acquiring a new license, a power outage occurred. After which the MS and the smart dashboard is no longer accessible. Smartdashboard stops at 5% and MS cli SSH connections are also rejected.
Is this normal behaviour ? How will I be able to update the license once I have it ?
Any help on this would be greatly appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is not the normal behavior after a license expiration and restart of a Check Point system.
Once you got the new license you should always be able to open SmartUpdate in order to attach the license to your Check Point systems.
R77 Management licenses typically don't 'expire', they just run out of support and you need to renew them (see Contract tab within SmartUpdate -> should always be 'Yes'). Your system doesn't just stop after the support contract expired.
However, do you have a cplic print or screenshot of your license within your UserCenter account available?
Your management server issue most likely results from the power outage. As you are also unable to login via SSH, you'll need to start troubleshooting the system in order to get it up an running again. Are there any error messages shown during start startup of the management server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Mr. Jung, appreciate the quick response. Will rebooting the MS again help ? or will it break anything ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What type of system is this, a VMware host, Open Server or Check Point Appliance?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Management server is hosted on a VM and the gateways are 5200 cluster.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As it's a VM, can you login to the console of the Management system or is this also failing like SSH?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Console login was also not possible. Found another problem from the VM. Problem: filesystem is corrupt or not found. Trying to restore the VM from backup.
Any further advices ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have certificate based VPNs you need to get your Management system back up and working within the next 20ish hours. If your VM backup doesn't work, check if your have any recent migrate exports you could import into a fresh install of the management server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please see this thread for instructions on how to execute system repair on VM Gaia:
https://community.checkpoint.com/thread/6439-report-server-wont-boot-cant-get-into-maintenance-mode
Had to do this myself recently after accidental power interruption to the server at one of my clients.
In general, I suggest changing boot parameters for virtual systems before you proceed with their configuration.
Bottom line, create another Linux VM, attach Gaia's disk to it, edit boot parameters, dismount the Gaia drive and boot it up.
You'll now have option available to perform filesystem repair.
Cheers,
Vladimir
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try to think to deploy redundancy of management.
In case redundant MS is available, such issues will never happen.
Disaster recovery scenario in PRODUCTION environment is a must nowadays...
Jozko Mrkvicka
