Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Askey_oot
Contributor

error establishing trust

Hi All, 

I'm trying to connect two Checkpoint Spark devices locally manage into one cluster HA, both hardware platform running the same firmware version, license, with GAiA Embedded 81.10.17. I'm getting an "error establishing trust" message on secondary device. Both devices are connected directly to each other with a short patchcord cable LAN2<>LAN2

Example error when click Establish trust:

ss.png
 
 

 

0 Kudos
5 Replies
Tom_Hinoue
Advisor
Advisor

Are your firewall settings on both members set to strict? If so, you will need an incoming policy rule to allow ccp packets (UDP/8116) to communicate with each other.

0 Kudos
Askey_oot
Contributor

First device call as primary have an strict mode firewall with  two manual create policy incoming/outgoing beetwen sync IP address and service ALL with action accept . Second device working firewall blade with standard mode but i create the same firewall 2 manual policy as primary . Same issue without changes

fw ctl zdebug + drop, that show massive logs on secondary device :

 

handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;

0 Kudos
the_rock
MVP Gold
MVP Gold

Run fw stat, make sure its not showing initial policy or default filter, if so, just run fw unloadlocal.

Best,
Andy
0 Kudos
Askey_oot
Contributor

Hi the_rock,

on secondary device i run these commands fw stat and fw unloadlocal then reebot device and get same logs:

 

@;14756;[cpu_14];[fw4_0];fw_log_drop_ex: Packet proto=6 172.29.149.1:39577 -> 172.29.149.2:18208 dropped by vpnktcpt_erase_model Reason: vpnk_tcpt erasing model;
@;14760;[cpu_14];[fw4_2];fw_log_drop_ex: Packet proto=6 172.29.149.1:18210 -> 172.29.149.2:59467 dropped by vpnktcpt_erase_model Reason: vpnk_tcpt erasing model;
@;14760;[cpu_14];[fw4_3];fw_log_drop_ex: Packet proto=6 172.29.149.1:18210 -> 172.29.149.2:32991 dropped by vpnktcpt_erase_model Reason: vpnk_tcpt erasing model;
@;14764;[cpu_14];[fw4_14];fw_log_drop_ex: Packet proto=6 172.29.149.1:45961 -> 172.29.149.2:18208 dropped by vpnktcpt_erase_model Reason: vpnk_tcpt erasing model;
@;14764;[cpu_14];[fw4_15];fw_log_drop_ex: Packet proto=6 172.29.149.1:33301 -> 172.29.149.2:18208 dropped by vpnktcpt_erase_model Reason: vpnk_tcpt erasing model;
@;14764;[cpu_22];[SIM74122841];handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;
@;14764;[cpu_22];[SIM74122841];handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;
@;14764;[cpu_22];[SIM74122841];handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;
@;14764;[cpu_22];[SIM74122841];handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;
@;14764;[cpu_22];[SIM74122841];handle_packet_do: invalid interface -1, conn <0.0.0.0,8116,172.29.149.0,8116,17>, type/state Network/Network, vsid 0, pkt_offset 14, protocol 0x0800;

0 Kudos
the_rock
MVP Gold
MVP Gold

Dont reboot, just run fw stat and IF it shows initial or defaultfilter policy, then run fw unloadlocal and try again.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events