[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW-1] Trouble installing policy, NG-FP2/IPSO
Title: RE: [FW-1] Trouble installing policy, NG-FP2/IPSO check the fwm.elg log, that may give you a clue as to why it is failing. It may be that the new policy file is just big enough to fill the filesystem when it is trying to save, check how much space you have free and if possible clean up some of the old stuff and then try it again. -----Original Message-----
Hello. I'm having trouble installing a policy from the NT GUI client to my firewall-1 management instance. It fails every time, while saving, with a dialog box stating: "The changes could not be saved. Please make sure that all Firewall-1 services are up and running. For more information use the Status Manager application." I can load, edit, and verify the policy with no trouble. I am not using QoS. Also, saving and installing the /unmodified/ policy works flawlessly (if uselessly.) Status manager reports 'Ok' status for all FW1 services (FireWall-1, SVN Foundation, Management, VPN-1) except for Floodgate-1, which we have never run. The Management service shows only the GUI client I am using as connected, with the only lock on the database. This is cleared correctly if I exit the GUI client from which I am trying to install the policy. The firewall is up and running, and performing beautifully - this is a production cluster. The security policy is being enforced correctly. Also, the policy itself is rather small - only ~25 rules, and NAT (22 NAT rules.) This is a standalone configuration - the management and enforcement modules reside together on the single nokia. This setup has worked up until this week. The last time I installed a policy was Jul 10, and no upgrades, patches, or OS-level changes have been made since then. I am running checkpoint NG FP2 (build 52213) standalone on a nokia IP330 running IPSO 3.5-FCS6. Disk and memory utilization are fine. I am not able to get a connection to the terminal without being onsite. Any help or pointers would be appreaciated, thanks! ::ja =================================================
|