- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: SSLVPN not connecting after installing Jumbo H...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSLVPN not connecting after installing Jumbo Hot Fix Accumulator Take 94
Good morning everyone.
We are in R81.10 with a cluster XL. The SMS is a VM on ESX.
Last Thursday, we installed the Jumbo Hotfix Accumulator Recommended Jumbo Take 94 to solve an issue with Identity Awareness.
The issue was fixed, but after doing that, our remote users can't connect through sslvpn. All other remote access methods work fine, however we have many clients using sslvpn who are unable to access. The connection process stays on the Connecting phase after enter the username and password.
Any advice will be appreciated.
Thanks.
Elfego
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did test for this in my lab and here are the results:
-upgrade to jumbo 94 from take 87 caused the issue
-after installing jumbo 95, though not officially recommended yet, all worked again
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you see any relevant logs in smart console? Have you tried doing zdebug for client external IP for example?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In Smartconsole I don't see any error. About the zdebug, I will be posting the results in a moment.
Thanks Andy for the suggestion.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What I meant was this, just to clarify. Say external client IP is 20.30.40.50, just run fw ctl zdebug + drop | grep 20.30.40.50 when they are trying to connect
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You've opened a TAC case on this, I presume?
https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I already asked the client to involve the TAC.
Thanks for yor answer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same issue when upgrading a customer's cluster from R81.10 T87 to T94, no reaction from the portal after logging in.
No time to troubleshoot unfortunately as the service had to be restored quickly, uninstalling to T87 and the portal works.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did test for this in my lab and here are the results:
-upgrade to jumbo 94 from take 87 caused the issue
-after installing jumbo 95, though not officially recommended yet, all worked again
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Would be fine if this was reported to CP 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im sure they can see it here and replicate it themselves, its not that hard lol
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for checking @the_rock , I will try again when Take 95 or above becomes recommended.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No worries, probably better to wait until its recommended, specially since its production.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
They will not see it here, i am sure - without drawing attention... But as TAC is already involved the customer can share the solution and CheckMates Link !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agree with that Guenther...since there is case already opened for it, @E_Islas would let them know all the findings from this post.
Have a nice weekend.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, Andy, for your research and suggestions. Since I don't have direct access to the SMS, I'm going to let the customer know what the situation is, and depending on the urgency, they can decide whether to install it or wait until it is officially recommended.
Again, thank you very much.
Elfego
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure, any time, glad it was helpful.
Have a nice weekend!
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats nice to know that - I was going with Take 94 in few days.
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I suspect Take 95 is going to be GA very soon now as it's been a month today since it was released.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think so.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would wait till 95 is recommended take.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @E_Islas 🙂
My name is Naama Specktor and I am Checkpoint employee ,
I will appreciate it if you will send me SR # , here or in PM.
Thank you,
Naama
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Naama... Of course. I sent to youy the SR# in PM
I'm sorry for my delayed answer.
Elfego
