All Apps and Add-ons

Checkpoint OPSEC LEA Error

robertgoolsby
Engager
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: rule not found.
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: finished successfully. 1st method = deny
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_choose: finished successfully. choose: DENY.
[ 32278 4158076608]@host[5 Dec 11:08:42] policy_choose: choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_negotiate_auth_method: policy choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] fwasync_mux_in: 10: handler returned with error
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_end_handler: for conn id = 10
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: connect failed (119)
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected:conn=(nil) opaque=0x8595218 err=0 comm=0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] comm failed to connect 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)
[ 32278 4158076608]@host[5 Dec 11:08:42] COM 0x858be20 got signal 131075
[ 32278 4158076608]@host[5 Dec 11:08:42] destroying comm 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying comm 0x858be20 with 1 active sessions
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying session (85a34f0) id 3 (ent=8595a18) reason=SIC_FAILURE
[ 32278 4158076608]@host[5 Dec 11:08:42] SESSION ID:3 is sending DG_TYPE=3

DEBUG: function get_fw1_logfiles_end
DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

We see Splunk and checkpoint talking but no logs are being added to the index.

0 Karma

rroussev_splunk
Splunk Employee
Splunk Employee

Please verify that the lea port is correct and check http://docs.splunk.com/Documentation/OPSEC-LEA/latest/Install/SetupSSLCAauthentication. If you're still having problems, please file a support ticket.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...