- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Dear Checkmates,
I'm studying for CCSA R80 and I have a lab setup in GNS3. I have installed Windows 10 VM and I have Checkpoint R80.10_T479(trial) installed as SMS in GNS3VM. The trial period is still available. I have the conectivity between Windows PC and SMS. I can do ssh and can also access WebGUI, but when I access via SmartConsole, I get 'operation timed out' message most of the time. Then I would restart the nodes, lab and VM. Sometimes it helps, but most of the time it fails. Then once when I rebooted the SMS, I got a message in CLI that I must reboot in maintenance mode, which I did. I see the file system is corrupt and it asked me to fix and I gave 'y' numerous times and finally it looked like the corrupt files and entries were fixed. Then the smart console was working for some time. Now the problem has started again. I don't know what to do now. Please guide me.
Thanks,
Hari
Thanks a lot for replying back. 😊
I guess your question of RAM answers my problem. I gave only 4GB, since I was running the lab in my laptop.
I now gave 6GB and running both SMS and GW and it works just fine, but slow sometimes. I would take your suggestion and try increasing the RAM. Also I would try installing the newer version.
One more question, probably should be in a different thread, but please guide me. Since I'm preparing for CCSA, will it have questions about R80.40 too?
Hi PhoneBoy,
Im reading the case, cause i have same issue. i already tryed sk165894 and still nothing, im running a SMS with 4 vCPU and 16 GB RAM and the issue is the same. the only thing it came to my mind is install the JHF that are availables for the SMS. other than that, what else could it be?
What does /opt/CPsuite-R80.40/fw1/scripts/cpm_status.sh say?
Have you checked that traffic reaches the VM using tcpdump or similar?
First output i get: Check Point Security Management Server is running and ready
and the tcpdump shows traffic going.
08:09:36.471504 IP 10.0.0.126.46322 > gw-mgmt-enel.set: Flags [.], seq 353449:354897, ack 1, win 15, options [nop,nop,TS val 940267858 ecr 931832977], length 1448
08:09:37.281438 IP 10.0.0.126.48458 > gw-mgmt-enel.ssh: Flags [.], ack 401328, win 1026, length 0
08:09:37.281461 IP gw-mgmt-enel.ssh > 10.0.0.126.48458: Flags [.], seq 403504:404814, ack 1, win 40, length 1310
^C
2356 packets captured
2356 packets received by filter
0 packets dropped by kernel
so ill try install the JHF.
All that's showing is ssh, not any attempts to connect on port 443, 18190, and 19009.
Which suggests you didn't capture this while you're trying to connect to SmartConsole, you're not connecting to the right IP, or something is blocking that communication.
This could also be related to using GNS3. Please see the following case:
Thank you so much for the link, I will try downgrading the GNS3 version and shall see how it works. I shall keep this thread updated with my findings.
Hi Everyone,
Sorry for delay. Meanwhile I passed CCSA and also moved to a new job 😁
I gave up with GNS3 and started using Eve-NG for the Lab setup, it works very well for me. I think, Eve-NG is more stable than GNS3. GNS3 was also getting updated every now and then and it kind of annoys me.
Once again thanks for helping😊
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY