- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Firewall Checkpoint L50 won't start
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Firewall Checkpoint L50 won't start
I reset the firewall to factory settings but it won't boot up properly and it doesn't show up in network resources or even its IP address. How can I solve this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why was the device reset, was it not functioning correctly prior?
Have you attempted to access the device serial console?
Alternatively imaging the appliance via USB could be an option if you have the necessary files / entitlements.
Note 600 / 1100 series devices are no longer supported.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have console to it? If so, you can try hard reset it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't have the usb console cable and adapter to see it how can I get around it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have usb to RJ45 cable? Thats console cable...I always use one they gave me at Fortinet conference ages ago and works 100% of the time.
Andy
Like one below:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what software should I use? or do I go SSH with Putty?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Lesley is correct, if you factory reset, you can connect to LAN1 and get a DHCP IP.
From there, connect to https://192.168.1.1:4434
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You open putty, select serial and then go to control panel, check device manager and verify what COM its using.
Andy
Or, as @Alex- suggested, configure your laptop to use any IP from 192.168.1.0/24 subnet, leave D as blank and it should connect to https://192.168.1.1:4434
But again, if NOT, then console is your only option, sorry mate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Able to connect with default IP?
Identity the network interface marked as LAN1. This
interface is preconfigured with the IP address 192.168.1.1.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is situation with led Firewall.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And this box still has support and services ? Looks like an old 600, long gone 8)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is a bug in older firmware that prevents the device from starting after a factory reset.
The only way to recover from this is upgrading to the latest firmware vua USB.
Please download the latest firmware from here (I believe the L50 is a 700 series): https://support.checkpoint.com/results/sk/sk137212#Downloads
Install via a FAT32 USB drive per: https://support.checkpoint.com/results/sk/sk107592
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is situation I cannot check via console yet whether the firmware update was successful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When the lights stop flashing on the unit, it should be updated.
You can then power cycle and reboot.
If the update was successful, you should get assigned a DHCP address after reboot.
You can manage the unit with a web browser (https://192.168.1.1:4434) and/or ssh.
Most likely, you can use Firewall/VPN functionality without an additional license as that typically is a perpetual license.
However, note it is an End of Support device.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wait...is the console plug in the back? I dont know where you live, but Im sure any electronics computer store would have console cable like the one I sent you the link via Amazon.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's a 600, so this is the latest.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm waiting for the console cable to arrive and then I want to figure out with what software can I check it for errors?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First check the license - you only have Firewall, IPSec VPN, QoS and Identity Awareness as unlimited blades, you will need a contract for TP, IPS & co.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have no license as the firewall was used by another colleague so it is free I think it is limited
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So how do you plan to use it ? IPS / TP mostly is the important part, without you have only features from e.g. iptables.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just want to administer it and manage it as iptables and filtering mode nothing more but if I can't get into it, I'm asking what software do I get into management with?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
WinSCP + Putty
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
this is the situation how can I solve it now?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you see what IP is there? It should have 192.168.1.1 Im pretty sure...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
127.0.0.1 this is. in boot logs not present ip 192.168.1.1
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I hate to say this, but I think its "toast", sorry. If you only see loopback IP address, not much you can do, plus if ICA is destroyed (as per screenshot you posted before), I have a gut feeling the only way to try fix this is to get console cable and try do hard reset, ie as you are powercycling the box, hold the metal pin for few seconds, release it, hope it comes back okay, so you can log into https://192.168.1.1:4434
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will not help - it is the ICA issue from sk123499 after 1.1.2018...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is not true - the SMB licence depends on the device MAC, not IP, so the license has the MAC at the end as CK-00-1C-7F-xx-yy-zz and it looks like 127.0.0.1 never CPAP-AP1570 CPWIFI-EU CPSB-FW CPSG-C-4-U CPSB-VPN ... CK-00-1C-7F-xx-yy-zz
So this is the source of using loopback IP, but i do not think this would work for eval as you need to use the head IP...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That may be the case, but not sure it matters if the box does not even start properly...
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The license is the least of our worries here.
The only way to get the box to start properly is to load the box with fixed firmware (done via USB drive) or to backdate the appliance as described by @G_W_Albrecht
