- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Management Server Is not able to login via IPs...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Management Server Is not able to login via IPsec Tunnel
Hello Team,
Two checkpoint 6200-P Quantum firewall is configured in cluster, and management server is configured in local vm-appliance and IPsec tunnel is configured between checkpoint and sophos firewall.
But when we are trying to access the management server behind the sophos firewall, i am getting the errror below.
Unable to connect the management server.
Management server and both firewall is reachable behind the sophos firewall, I have allowed 19009 port also into sophos policy for VPN traffice but still the error is same.
I have tried to capture the tcpdump but was not able to understand why management server is not rechable.
I have also attached the tcpdump logs file.
Please help me to get it resolved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some topology diagrams and details about Sophos VPN might help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I dont have topology diagram right now but i have attached logs for refrence.
it will help to you?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, logs you are attached are not helping at all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Whats failing? ssh, console, web ui? Can you swnd output of api status and cpwd_admin list if ssh is accessible?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, I am not able to login into smart console.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
On what device this tcpdump is made?
Looks like there is a route incorrect. This looks like return traffic. I do not see initial traffic in capture meaning it comes in on ETHX and it replies on ETHY this will be out of state.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tcpdump is made on the primary gateway,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Note that management traffic does NOT go over VPN by design.
Not sure if this applies here since it's not clear where all the components sit in relation to each other.
A simple network diagram would help tremendously.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Are Implied Rules enabled? If so, SmartConsole traffic might hit rule number 0 and will not pass via the VPN tunnel.
I had the same with one of our customer and needed to exclude SmartConsole traffic from the Implied Rules.
Please check sk105719.
Regards,
Martijn