<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CA Issues on AWS R81.20 Manager in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206764#M4617</link>
    <description>&lt;P&gt;No hot fixes applied. Booted straight from AMI R81.20-BYOL Management. Runs first time wizard with config from cloud-init/cloud_config&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 22:44:38 GMT</pubDate>
    <dc:creator>cdav</dc:creator>
    <dc:date>2024-02-21T22:44:38Z</dc:date>
    <item>
      <title>CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206762#M4615</link>
      <description>&lt;P&gt;I have deployed an EC2 manager from market place image in AWS. I keep running into an issue where it would appear the CA services on the host are not running. Connecting via SmartConsole errors with "Failed to download CRLs". No service appears to be listening on 18264. For example if i attempt to curl google I cannot validate TLS. The same completes if i ignore TLS errors.&lt;/P&gt;&lt;P&gt;The instance is deployed via terraform albeit not directly from the CheckPoint supplied template. It has been extracted but gets passed all the correct and relevant parameters. The cloud_config.log and var/log/messages indicate boot and auto config ok.&lt;/P&gt;&lt;P&gt;[Expert@CP-Management:0]# curl_cli &lt;A href="https://www.google.ocm" target="_blank" rel="noopener"&gt;https://www.google.ocm&lt;/A&gt;&lt;BR /&gt;curl: (6) Couldn't resolve host '&lt;A href="http://www.google.ocm" target="_blank" rel="noopener"&gt;www.google.ocm&lt;/A&gt;'&lt;BR /&gt;[Expert@CP-Management:0]# curl_cli &lt;A href="https://www.google.com" target="_blank" rel="noopener"&gt;https://www.google.com&lt;/A&gt;&lt;BR /&gt;curl: (60) SSL certificate problem: unable to get local issuer certificate&lt;BR /&gt;More details here: &lt;A href="https://curl.haxx.se/docs/sslcerts.html" target="_blank" rel="noopener"&gt;https://curl.haxx.se/docs/sslcerts.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl failed to verify the legitimacy of the server and therefore could not&lt;BR /&gt;establish a secure connection to it. To learn more about this situation and&lt;BR /&gt;how to fix it, please visit the web page mentioned above.&lt;/P&gt;&lt;P&gt;Does anyone have any suggestions?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206762#M4615</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2024-02-21T22:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206763#M4616</link>
      <description>&lt;P&gt;Is it the base R81.20 or with some Jumbo take applied?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206763#M4616</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-21T22:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206764#M4617</link>
      <description>&lt;P&gt;No hot fixes applied. Booted straight from AMI R81.20-BYOL Management. Runs first time wizard with config from cloud-init/cloud_config&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:44:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206764#M4617</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2024-02-21T22:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206765#M4618</link>
      <description>&lt;P&gt;I did this twice on aws, but mind you from actual cp template and all worked fine. Not sure, but seems the way you did it definitely differs.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 00:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206765#M4618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T00:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206766#M4619</link>
      <description>&lt;P&gt;I'd suggest applying the latest recommended JHF and if the problem persists consulting TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 01:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206766#M4619</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-22T01:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206769#M4621</link>
      <description>&lt;P&gt;Agree, good point.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 01:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/206769#M4621</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T01:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207045#M4631</link>
      <description>&lt;P&gt;To add to this I have now deployed from the CheckPoint provided TF template for management instance and run into the same error.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 18:29:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207045#M4631</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2024-02-23T18:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207047#M4632</link>
      <description>&lt;P&gt;If thats the case, may need to open TAC case to check.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 18:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207047#M4632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T18:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207067#M4633</link>
      <description>&lt;P&gt;You need to open more ports. Check it out here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk119134" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk119134&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 21:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207067#M4633</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-23T21:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: CA Issues on AWS R81.20 Manager</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207080#M4636</link>
      <description>&lt;P&gt;Hi Lesly,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have looked at this article but it doesnt fit. Security groups for the mgmt ec2 are deployed as per template and have the 3 required ports open. Instance used to connect via SC is in the same subnet as Mgmt EC2 and has access on all ports to Mgmt host.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@mgmt-tf:0]# ss -ntlp | grep '18264\|19009\|18190'&lt;BR /&gt;LISTEN 0 20 *:18190 *:* users:(("fwm",pid=5517,fd=42))&lt;BR /&gt;LISTEN 0 5 *:18264 *:* users:(("cpca",pid=8137,fd=11))&lt;BR /&gt;LISTEN 0 50 *:19009 *:* users:(("java",pid=5802,fd=462))&lt;/P&gt;&lt;P&gt;[Expert@mgmt-tf:0]# curl_cli &lt;A href="https://checkpoint.com" target="_blank"&gt;https://checkpoint.com&lt;/A&gt;&lt;BR /&gt;curl: (60) SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;More details here: &lt;A href="https://curl.haxx.se/docs/sslcerts.html" target="_blank"&gt;https://curl.haxx.se/docs/sslcerts.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl failed to verify the legitimacy of the server and therefore could not&lt;BR /&gt;establish a secure connection to it. To learn more about this situation and&lt;BR /&gt;how to fix it, please visit the web page mentioned above.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2024 11:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CA-Issues-on-AWS-R81-20-Manager/m-p/207080#M4636</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2024-02-24T11:30:22Z</dc:date>
    </item>
  </channel>
</rss>

