Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jerry
Mentor
Mentor

new MLM Domain hook-up issue (despite R81.10)

hi guys, quick one:

my customer got an error when adding new Domain to the MLM:

"Failed to send request to remote MDS"

this happens when they add new Domain Server's Domain, provide Configuration Name: + IPv4 (type Log Server).

any ideas why "Create Domain Server Task fails with the above error? highly appreciate if you know that "zonk" from the MDS 🙂

ps. NAT's and Comms works, IP wise all is sorted, the CMA as well as MDS can reach the new Domain eth0:1 etc. and hit-counts on NAT's are increasing just fine except I cannot figure it out based on netstat's and pcap's what is wrong.

 

 

 

 

Jerry
0 Kudos
21 Replies
the_rock
Legend
Legend

I've never been P-1 guru by any means, have not worked on it since R77.30, but maybe @PhoneBoy & @Timothy_Hall can chime in. I will also ask around, see if any of my colleagues might have some idea and keep you posted.

Cheers mate.

Andy

0 Kudos
Jerry
Mentor
Mentor

cheers mate much appreciate it!

Jerry
0 Kudos
the_rock
Legend
Legend

For you bro, no charge, except iphone charge ; - ). Anyway, I found below, just going through it now to see if any of scenarios might be related.

Andy

https://support.checkpoint.com/results/sk/sk98768

0 Kudos
Jerry
Mentor
Mentor

sadly I do know that SK, it is little bit irrelevant though as I'm not facing mirroring MDS's issue but MLM Domain Server CMA-based Logging server creation issues. MLM itself is just fine, SIC'ed and all works between the MDS, Global and the MLM (all 2 MDS's and MLM shows on MDS HA as Sync'd so this isn't an issue mate really.

Jerry
0 Kudos
the_rock
Legend
Legend

K, thats fair, understood. If I find anything else, will update you.

Andy

0 Kudos
Jerry
Mentor
Mentor

our famous on-hand toolbox called ATRG

https://community.checkpoint.com/t5/General-Topics/ATRG-Ultimate-list/m-p/184397/thread-id/30711

also didn't manage to convince me we've got that issue documented within ANY of our ATRG docs 😞

Jerry
0 Kudos
Jerry
Mentor
Mentor

ps. I went through majority of the SK's we've got as well as CheckMates posts and still struggled to find the answers, really not an easy case to solve 😞 

Jerry
0 Kudos
the_rock
Legend
Legend

Dont despair, we will solve it! You know this community, people always come together to find an answer. I am fairly available today, so have time to research and help. 

the_rock
Legend
Legend

Hey brother...I asked around and sadly, no one knows, as we dont have any customers running P-1 (MDS) product, BUT, I wont give up, Im very persistent person.

I will update you at 12 pm est, 5 pm UK time.

Cheers,

Andy

0 Kudos
Jerry
Mentor
Mentor

Cheers bud I have an update for you as well:

 

Valid Licence Check

There is a mismatch between the installation type of the machine and the type of licence key installed on it. Contact Check Point Support for a fix.

 

 

WARNING

 

BASH COMMAND RESULT

--> This MLM machine does not have a CPSB-MLOGS licence installed.

Jerry
0 Kudos
the_rock
Legend
Legend

Never been a license expert, but I assume regular eval license would cover this?

0 Kudos
Jerry
Mentor
Mentor

CPSB-MLOGS

Jerry
0 Kudos
Jerry
Mentor
Mentor

and another one from CPMDoctor:

 

--> Error - in /opt/CPshrd-R81.10/registry/HKLM_registry.data_cust file the 'SIC' field is not empty

Jerry
0 Kudos
the_rock
Legend
Legend

Hey all,

Just to give quick update on this issue. Jerry and I connected offline and we are fairly confident the reason why this fails, at least based on all the errors and messages, is that proper license is missing, as its looking for cpsb-mlogs and eval only shows cpsb-logs string. Lets see if we can figure it out Monday.

Andy

0 Kudos
andrewb
Participant

Hi, is there a solution on this issue as we are also encountering the same error - new MDM HA

0 Kudos
the_rock
Legend
Legend

Licensing problem?

Andy

0 Kudos
andrewb
Participant

Hi, 

Im thinking of this, did Jerry resolved the issue with license also?

 

Thanks

0 Kudos
the_rock
Legend
Legend

He is in UK, so its almost 10 pm there now, so I asked him via email, as I have his contact.

But, lets see if he responds  to this tomorrow : - )

@Jerry ...was this solved on your end last year?

Best,

Andy

0 Kudos
andrewb
Participant

Thank you for this 🙂

 

0 Kudos
the_rock
Legend
Legend

For you mate, no charge ; - )

0 Kudos
the_rock
Legend
Legend

Sorry for late reply @andrewb ...Jerry got back to me, said Sales and Account services solved the issue by providing proper license.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events