Mumbai Security and Compliance User Group

 View Only
  • 1.  Checkpoint issue

    Posted Apr 27, 2012 02:46 AM

    Hello Friends,

    I am trying to figure out one Checkpoint integration......but always i am getting following error.

     

    ERROR   2012-04-27 11:12:28,341 Collectors.3120.wGroup.[workinggroup0].Sensor.[XX.XX.XX.XX]     Thread-2419     OpsecLeaSensor(XX.XX.XX.XX) error in readDevice( ). Sensor will be reopened. Details: OPSEC MainLoop has being terminated with errors: Both Security and Audit sessions were ended because The SIC infrastructure was unable to establish the connection to OPSEC Server [SIC_FAILURE]. SIC Error for lea: Peer sent wrong DN: CN=cp_mgmt_XXXXX,O=XXXXXX..XXXX.
    WARN   
    2012-04-27 11:12:28,341 Collectors.3120.wGroup.[workinggroup0].SensorThread  Thread-2419     [Sensor: XX.XX.XX.XX]   Exception in Sensor thread while     reading device. Details:
    java.lang.Exception: OpsecLeaSensor(XX.XX.XX.XX) error in readDevice(). Sensor will be reopened. Details: OPSEC MainLoop has being terminated with errors: Both     Security and Audit sessions were ended because The SIC infrastructure was unable to establish the connection to OPSEC Server [SIC_FAILURE]. SIC Error for lea: Peer sent wrong DN: CN=cp_mgmt_XXXXX,O=XXXXXX..XXXX.
            at com.symantec.cas.ucf.sensors.Opsec.OpsecLeaSensor.readDevice(OpsecLea Sensor.java:379)
            at com.symantec.cas.ucf.collector.SensorJob.pollSensor(SensorJob.java:212)
            at com.symantec.cas.ucf.collector.SensorJob.run(SensorJob.java:292)
            at java.lang.Thread.run(Thread.java:662)
    WARN    2012-04-27 11:12:28,341 Collectors.3120.wGroup.[workinggroup0].SensorThread     Thread-2419     [Sensor: XX.XX.XX.XX]   Restarting the sensor... 

     

    Please refer this forum for more details on my issue...

    https://www-secure.symantec.com/connect/forums/checkpoint-collector-0

     



  • 2.  RE: Checkpoint issue

    Posted Apr 30, 2012 09:54 AM

    Are you using 4.3 or 4.4 version of the collector?



  • 3.  RE: Checkpoint issue

    Posted Apr 30, 2012 11:41 AM

    Hey Avkash, I believe I had this problem before.

     

    There is a certain command to enter in the Checkpoint platform to view all the available SIC entities (however, indeed cp_mgmt is the default one).

    I will try to find that command.



  • 4.  RE: Checkpoint issue

    Posted Apr 30, 2012 02:17 PM

    Article URL http://www.symantec.com/docs/TECH180284

    Try to run the “cpca_client lscert –kind SIC” and see if it matches your sensor SIC name settings



  • 5.  RE: Checkpoint issue

    Posted May 01, 2012 11:28 PM

    Hi Olaf,

    I am using 4.3 collector.