Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sorin_Gogean
Advisor

Issue with SmartConsole access "Unknown Administrator"

Hope that you are OK nowadays, so I’m coming to you with a weird problem we’re facing since few days ( from last Thursday actually).

 

Since Thursday, we started to have issues with some users authenticating to CheckPoint SmartConsole , no matter if they were local (CKP Password) or AD (TACACS) and we ended up that since yesterday we can’t log-in with any account into SmartConsole  .

We had opened a case with CheckPoint (SR#6-0002999378), and this Sunday they collected all details and debugs, and hopefully they could get a way for us to regain access.

 

To summarize the issue, whenever someone tries to login to SmartConsole, with whatever user, it’s getting this error message “Authentication to server failed” and in Logs we were seeing “Unknown Administrator whateverusername” . We created some users with cpconfig, no luck with those and also added the OS admin account to SmartConsole (by cpconfig) and that is not working either.

 

Sorin_Gogean_0-1633336511192.jpeg

 

image.png

 

 

 

As far as we know, the CKP Cluster Gateways are working fine, but currently we can’t see any Logs or to change policies.

 

More than that as we were planning to migrate to R81, new management servers, we’re somehow stuck in the process, as we can’t get the CKP Cluster Gateways to talk to the new manager, without unloading the current policy in order to do the move without service interruption. (the new management server is not present in the old policies, so in order to have a smooth migration, we will have to get the old manager accessible) So we’re keeping that as a last resort.

 

So if you have any idea, or if you can have a look on the case and ask the support to brainstorm for a way to get this fixed, would be wonderful.

 

Thank you and have a nice week,

PS: thinking it over this morning, since the Management is a VM, I would create a snapshot and then try to get the latest JHF (maybe will trigger something) or if still not, then either an in-place upgrade to R81, or a redeploy of the R80.40 (just to get access back so we can move to new Management)

0 Kudos
2 Replies
G_W_Albrecht
Legend
Legend

Saw the same kind of issue at a customer with R81 JT 29 - turned out to be some database corruption afaik and was resolved during a RAS...

CCSE CCTE CCSM SMB Specialist
0 Kudos
Sorin_Gogean
Advisor

Thank you G_W, I hope for some similar thing, as there was nothing changed prior to this issue to start showing.

(glad we're not the only ones that special 😁 )

 

PS: while facing this issue, we bumped in another problem, for exporting the Rulebase from the Manager and having them somewhere. We manage to do an migrate_export and they imported fine in another temp management, but still, that is not a solution to "archive or back-up" the rulebase. I know about the python script, and we used it last year, but these days it failed on us on the NAT policies 😫

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events