Ayden, >From your log info, I can see "cn=cp_mgmt,o=Grandpa-Simpson..vspwti" is your management server, but it seems you have wrong SIC name for your Webtrend LEA service. This should be looking like "cn=XXXXX,o=Grandpa-Simpson..vspwti".
Also, it seems that your policy setting has a little issue, and I am not sure what is happening unless you modify your policy to deny LEA service. However, I don't think so. It should have an entry to allow any lea client to access lea service by using the default comm mode, sslca. Xiaodong -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ayden Nash Sent: Sunday, July 18, 2004 10:01 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] OPSEC LEA Hi Xiaodong, I received the error; [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] policy_query: src : cn=cp_mgmt,o=Grandpa-Simpson..vspwti dst : opsecWT [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] call_handlers_list: no conversion done, set opsecWT as sic name [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] PM_session_init: given session I(cn=cp_mgmt,o=Grandpa-Simpson..vspwti;opsecWT;181 84;lea). [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] PM_policy_query: input session I(cn=cp_mgmt,o=Grandpa-Simpson..vspwti;opsecWT;181 84;lea). [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] dn_explode_prefix: DN ended abruptly [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] sicobj_resolve_by_opsec: No object found with SIC name 'opsecWT' [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] dn_explode_prefix: DN ended abruptly [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] dn_explode_prefix: DN ended abruptly [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] PM_policy_query: rule not found. [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] PM_policy_query: finished successfully. 1st method = deny [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] fwasync_mux_in: 78: read: Connection reset by peer [FWD 936 [EMAIL PROTECTED] Jul 11:44:56] opsec_new_auth_conn_to_server: conn from 10.25.25.211 to entity lea_server (0xde5 a60) failed (0) No SIC error message I see that it doesn't like the CN of opsecWT which is the name of the LEA object; objects.C: : (opsecWT objects.C: :sic_name ("CN=opsecWT,O=Grandpa-Simpson..vspwti") objects_5_0.C: : (opsecWT objects_5_0.C: :sic_name ("CN=opsecWT,O=Grandpa-Simpson..vspwti") It appears when you configure WebTrends LEA service it asks for the CN for the management server and the LEA connection. I assumed the management server used cp-mgmt and the CN from the initialised and trusted SIC CN for the OPSEC object: opsecWT. What's next? Thanks and regards, Ayden -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Xiaodong Lin Sent: Saturday, July 17, 2004 5:29 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] OPSEC LEA Ayden, However, the SIC trust between webtrends and the management server doesn't guarantee your wentrend LEA client service is able to fetch Firewall log successfully, and something, such as your webtrend box wrong date & time, can also be an issue for your failure. First of all, you have to make sure that you do see firewall log in your management server log viewer. If not, go check the connection between your management server and firewall. If yes, do they both use the same communication mode, such as sslca, auth_opsec, ...? They have to use the same mode in order to make your webtrend to receive events. You can turn on your server side fw log by "fw debug fwd on OPSEC_DEBUG_LEVEL=3". Then, you start your webtrend, and wait for a few minutes. You stop debugging by running "fw debug fwd off OPSEC_DEBUG_LEVEL=0". Afterwards, you can review fwd.elg under $FWDIR/log. If you want, you can send me this log file, and I can take a look at it. Xiaodong -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ayden Nash Sent: Friday, July 16, 2004 2:42 AM To: [EMAIL PROTECTED] Subject: [FW-1] OPSEC LEA Hi all, I am trying to use webtrends to generate reports on fw-1 traffic. I am able to establish SIC trust between webtrends and the management server however the logs directory is not being populated. I see the reporting server use FW1_LEA to connect to the management server every 5 minutes and that traffic is allowed, but no logs seem to be obtained. Any ideas are appreciated. Thanks and regards, Ayden ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
