> Source: [sk123849](https://support.checkpoint.com/results/sk/sk123849)

# sk123849 - 'Unable to reconnect' Status in Correlation sessions in Multi-Domain Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk123849 |
| Date Created | 2018-04-02 |
| Last Modified | 2018-04-09 |
| Technical Level | Advanced |
| Products | Multi-Domain Security Management Server |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |

## Symptoms

- * All the Eventia Reporter consolidation sessions are in "Trying to reconnect" status.

* There was an unsuccessful attempt to upgrade to R80.10, and a roll-back was performed.

* Restarting the sessions, a reboot and conventional actions, only 1 is processing logs.

* Verifying connectivity to log servers using "$RTDIR/log_consolidator_engine/bin/log_consolidator -L -s X.X.X.X -g YYY-YYYYY", you receive:  

  `[Date/Time] ### LEA end reason:SIC_FAILURE (SIC problem with the LEA Server) `  
  `[Date/Time][LogConsolidator] ### LEA end reason:SIC_FAILURE (SIC problem with the LEA Server) `  
  `[Date/Time][LogConsolidator] Error:failed to get logs information from log server. There are SIC configuration problems `  
  `[Date/Time][LogConsolidator] Check that: `  

  `1) The file $FWDIR/conf/fwopsec.conf contains no rows that refer to lea_server.`  
  `2) The file $CPDIR/conf/sic_policy.conf was not modified in a way that would block LEA connections from the log consolidator to SmartCenter or Log server.`  
  `3) Verify that lea_settings section in $RTDIR/log_consolidator_engine/conf/^Log server IP^/lc_rt.conf is configured correctly (specifically lea_is_auth_port and lea_log_server_port values, lea_is_auth_port should usually be ^false^ for local log server and ^true^ for remote). `  

  `[Date/Time][LogConsolidator] Error: failed to run log_consolidator -L`  
  `[Date/Time][LogConsolidator] Waiting for the DB writer thread to exit!!`  
  `[Date/Time][LogConsolidator] ### log_consolidator -L exit with error (code 3)`

## Cause

The roll-back corrupted the CRL's of the consolidation sessions servers.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
