All Apps and Add-ons

Checkpoint OPSEC LEA Error

robertgoolsby
Engager
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: rule not found.
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: finished successfully. 1st method = deny
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_choose: finished successfully. choose: DENY.
[ 32278 4158076608]@host[5 Dec 11:08:42] policy_choose: choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_negotiate_auth_method: policy choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] fwasync_mux_in: 10: handler returned with error
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_end_handler: for conn id = 10
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: connect failed (119)
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected:conn=(nil) opaque=0x8595218 err=0 comm=0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] comm failed to connect 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)
[ 32278 4158076608]@host[5 Dec 11:08:42] COM 0x858be20 got signal 131075
[ 32278 4158076608]@host[5 Dec 11:08:42] destroying comm 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying comm 0x858be20 with 1 active sessions
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying session (85a34f0) id 3 (ent=8595a18) reason=SIC_FAILURE
[ 32278 4158076608]@host[5 Dec 11:08:42] SESSION ID:3 is sending DG_TYPE=3

DEBUG: function get_fw1_logfiles_end
DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

We see Splunk and checkpoint talking but no logs are being added to the index.

0 Karma

rroussev_splunk
Splunk Employee
Splunk Employee

Please verify that the lea port is correct and check http://docs.splunk.com/Documentation/OPSEC-LEA/latest/Install/SetupSSLCAauthentication. If you're still having problems, please file a support ticket.

Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...