NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] FW-1 4.1 MOTIF Policy Editor problem / show stopper



Thanks for your reply.
I've reconfigured the firewall with the earlier Sun version and it is
running well enough, for now. I will address this again next week when the
support crews return from Las Vegas, Hawaii, or wherever I should also be...

Chuck Sterling
System / Network Administrator
NASA White Sands Test Facility
Las Cruces, New Mexico, USAMagic is REAL, unless declared INTEGER

> ----------
> From:         Shelton, Raymond A.[SMTP:[email protected]]
> Reply To:     Mailing list for discussion of Firewall-1
> Sent:         Saturday, December 29, 2001 10:51 AM
> To:   [email protected]
> Subject:      Re: [FW-1] FW-1 4.1 MOTIF Policy Editor problem / show
> stopper
>
> Don't go further in this direction.
> Change the fw's IP and put it on your network with an eval/temp lic from
> your VAR.
> Then you won't waste time when things like DNS or hostnames aren't
> resolving, or
> the mere annoyance that you can't get your GUI's to connect to it via a
> hub
> or some
> other simple lab network arrangement...make sense?
>
> -----Original Message-----
> From: Sterling, Chuck [mailto:[email protected]]
> Sent: Saturday, December 29, 2001 11:27 AM
> To: [email protected]
> Subject: [FW-1] FW-1 4.1 MOTIF Policy Editor problem / show stopper
> Importance: High
>
>
> I just completed a new install of FW-1 4.1 with SP2 on a Sun Ultra-10
> running Solaris 2.6 5/98.
> I intended to do an upgrade from Sun Solstice FW-1 3.0b, however that was
> unsuccessful, and now I am trying a new install. To keep our site running,
> I
> have reconfigured an older machine as our production firewall, using the
> original firewall system's ip addresses, but it is overloaded and
> unreliable. The machine I'm installing to uses the same ip addresses, but
> is
> currently disconnected from any LAN so that I can complete the
> configuration
> offline. This means, I think, that I have to use the Motif fwpolicy
> program
> to configure the system, since it is inaccessible over the LAN from my
> WinNT
> system. However, I cannot get the fwpolicy program to run.
>
> In the text below, the machine name and what might be sensitive numbers in
> the program list have been altered for privacy.
>
> When I start "fwpolicy" on the U10, in a normal terminal window, there is
> no
> response for just over five minutes, then the following error displays:
> Wind/U Error (247): Failed to connect to the registry on server morton
>
> Other programs such as admintool open immediately from the same window.
>
> The programs running after rebooting, as far as the firewall is concerned,
> at least those I know about, according to ps are:
>
> /opt/CPfw1-41/bin/ela_proxy
> /etc/fw.boot/fwboot bootd
> /bin/csh -fb /opt/CPfw1-41/bin/runELA_Proxy /minInterval 60 -maxRetries 1
> /opt/
> alertd -A -l
> fwm
> fwd
>
> After starting fwpolicy, these two programs are also running:
>
> /opt/CPfw1-41/clients/bin/fwui
> /opt/CPfw1-41/clients/bin/windu_clientd
>
> Two minutes after starting fwpolicy, the following program also starts:
>
> windu_registryd42 -vers 2 -prog 803502675 -d / -k
>
> Five minutes, ten seconds after starting fwpolicy, the error displays
> (repeated from above):
>
> Wind/U Error (247): Failed to connect to the registry on server morton
>
> I have gone over these known possible problems with our vendor:
>
> 1.
> Licenses were accepted and no error messages about missing licenses are
> displayed, either with the firewall module, mgmt, or gui. When I run fw
> printlic, two valid Motif licenses are displayed, along with the license
> for
> module and mgmt. I have the two Motif licenses, and tried one with no
> improvement, then added the second with no change.
>
> 2.
> I have run, in /.cshrc:
> unsetenv LC_TIME
> unsetenv LC_CTYPE
> unsetenv LC_NUMERIC
> setenv LANG C
>
> 3.
> We are using the default color scheme in the Sun CDE interface
>
> So. Can anyone assist on this problem? I am pretty much up against the
> wall
> here, and may have to revert to the Sun 3.0b version I am trying to
> upgrade
> from.
>
> Thanks,
> Chuck Sterling
>
> Chuck Sterling
> System / Network Administrator
> NASA White Sands Test Facility
> Las Cruces, New Mexico, USA
>>
> Magic is REAL, unless declared INTEGER
>
> =================================================
> To set vacation, Out Of Office, or away messages,
> send an email to [email protected]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [email protected]
> =================================================
>
> =================================================
> To set vacation, Out Of Office, or away messages,
> send an email to [email protected]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [email protected]
> =================================================
>

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.