All Apps and Add-ons

Checkpoint OPSEC LEA Error

robertgoolsby
Engager
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: rule not found.
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: finished successfully. 1st method = deny
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_choose: finished successfully. choose: DENY.
[ 32278 4158076608]@host[5 Dec 11:08:42] policy_choose: choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_negotiate_auth_method: policy choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] fwasync_mux_in: 10: handler returned with error
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_end_handler: for conn id = 10
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: connect failed (119)
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected:conn=(nil) opaque=0x8595218 err=0 comm=0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] comm failed to connect 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)
[ 32278 4158076608]@host[5 Dec 11:08:42] COM 0x858be20 got signal 131075
[ 32278 4158076608]@host[5 Dec 11:08:42] destroying comm 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying comm 0x858be20 with 1 active sessions
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying session (85a34f0) id 3 (ent=8595a18) reason=SIC_FAILURE
[ 32278 4158076608]@host[5 Dec 11:08:42] SESSION ID:3 is sending DG_TYPE=3

DEBUG: function get_fw1_logfiles_end
DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

We see Splunk and checkpoint talking but no logs are being added to the index.

0 Karma

rroussev_splunk
Splunk Employee
Splunk Employee

Please verify that the lea port is correct and check http://docs.splunk.com/Documentation/OPSEC-LEA/latest/Install/SetupSSLCAauthentication. If you're still having problems, please file a support ticket.

Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...