Checkpoint virtual contexts stay blue (initial) in CA Spectrum
search cancel

Checkpoint virtual contexts stay blue (initial) in CA Spectrum

book

Article ID: 8946

calendar_today

Updated On:

Products

CA Spectrum

Issue/Introduction

When modeling Checkpoint virtual contexts, they are not contactable by Spectrum and stay in the Initial (blue) state.

Environment

Release: SDBSFO99000-10.2-Spectrum-Device Based Suite-Server FOC
Component:

Cause

The problem is that the virtual switching is not turned on at the firewall.

Resolution

You need to make sure there is an SNMPv3 profile configured AND that the vs mode has been enabled.  Here are sample commands:

 

Sample commands: 

            > add snmp usm user admin security-level authNoPriv auth-pass-phrase abcd1234 

            > set snmp mode vs 

            > set snmp agent on

 

Make sure that SNMPv3 profile exists in CA Spectrum.

If the Checkpoint Firewall is already modeled in CA Spectrum you will need to destroy and recreate the model after the above commands have been run.

Verify the contexts are modeled with the SNMPv3 community string with the context name:  #v3/P:auth:priv/contextname/username