<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CME can't scan for MIG gateway instances on GCP in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CME-can-t-scan-for-MIG-gateway-instances-on-GCP/m-p/149273#M6025</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I'm a newcomer to CME with GCP and I run into an issue that my on-premises MGMT can't find the cloudguards in GCP.&lt;BR /&gt;gcp deployment is handled by terraform scripts and I think I miss a piece of the puzzle so both sides can work together.&lt;BR /&gt;&lt;BR /&gt;in the cme log I get this error:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2022-05-23 16:58:59,083 CME_SERVICE INFO ********** Starting loop iteration number 523 for gateway instances *******&lt;BR /&gt;***&lt;BR /&gt;2022-05-23 16:59:00,783 CME_SERVICE INFO There are no gateways known by the management at the beginning of the iteration&lt;BR /&gt;2022-05-23 16:59:01,194 CME_SERVICE ERROR Error during synchronization with Security Gateways.&lt;BR /&gt;Error details: Failed to scan for gateway instances in the cloud account xxxxxxxxxxxxxxxxxxx..&lt;BR /&gt;2022-05-23 16:59:01,200 CME_SERVICE ERROR Error traceback: Traceback (most recent call last):&lt;BR /&gt;File "/opt/CPcme/service/cme_service.py", line 433, in sync&lt;BR /&gt;filtered_instances = controller.filter_instances()&lt;BR /&gt;cloud_connectors.gcp.HTTPException: Unexpected HTTP code: 404&lt;/P&gt;&lt;P&gt;During handling of the above exception, another exception occurred:&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/CPcme/service/cme_service.py", line 584, in loop&lt;BR /&gt;sync(c, management, gateways)&lt;BR /&gt;cme_exceptions.cme_exceptions.ControllerException: Error Code: Failed to scan for gateway instances&lt;/P&gt;&lt;P&gt;Failed to scan for gateway instances in the cloud account xxxxxxxxxxxxxxxxxxx.&lt;BR /&gt;2022-05-23 16:59:01,200 CME_SERVICE INFO&lt;BR /&gt;2022-05-23 16:59:01,485 CME_SERVICE INFO There are no gateways known by the management at the end of the iteration&lt;BR /&gt;2022-05-23 16:59:01,485 CME_SERVICE INFO ********** End of the iteration number 523 for gateway instances. Iteration time:&lt;BR /&gt;0:00:02.401860 **********&lt;BR /&gt;&lt;BR /&gt;has anybody encountered this issue?&lt;BR /&gt;&lt;BR /&gt;I followed these instructions to set it up:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?TocPath=CME%20Structure%20and%20Configurations%7C_____0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?TocPath=CME%20Structure%20and%20Configurations%7C_____0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_and_Above_CG_Autoscaling_Managed_Instance_Group_for_GCP/AdminGuide/Content/Topics-Google-Managed-Instance-Group/Configuring-GCP.htm#Deploying-the-Check-Point-Autoscaling-Managed-Instance-Group" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_and_Above_CG_Autoscaling_Managed_Instance_Group_for_GCP/AdminGuide/Content/Topics-Google-Managed-Instance-Group/Configuring-GCP.htm#Deploying-the-Check-Point-Autoscaling-Managed-Instance-Group&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/95584/FILE/CP_CloudGuard_Network_for_GCP_Autoscaling_Managed_Instance_Group_R80.30_and_Higher_AdminGuide.pdf" target="_blank" rel="noopener"&gt;https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/95584/FILE/CP_CloudGuard_Network_for_GCP_Autoscaling_Managed_Instance_Group_R80.30_and_Higher_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-GCP-auto-provisioning-error/m-p/85195#M531" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-GCP-auto-provisioning-error/m-p/85195#M531&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 20:31:21 GMT</pubDate>
    <dc:creator>Fednot</dc:creator>
    <dc:date>2022-05-23T20:31:21Z</dc:date>
    <item>
      <title>CME can't scan for MIG gateway instances on GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CME-can-t-scan-for-MIG-gateway-instances-on-GCP/m-p/149273#M6025</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I'm a newcomer to CME with GCP and I run into an issue that my on-premises MGMT can't find the cloudguards in GCP.&lt;BR /&gt;gcp deployment is handled by terraform scripts and I think I miss a piece of the puzzle so both sides can work together.&lt;BR /&gt;&lt;BR /&gt;in the cme log I get this error:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2022-05-23 16:58:59,083 CME_SERVICE INFO ********** Starting loop iteration number 523 for gateway instances *******&lt;BR /&gt;***&lt;BR /&gt;2022-05-23 16:59:00,783 CME_SERVICE INFO There are no gateways known by the management at the beginning of the iteration&lt;BR /&gt;2022-05-23 16:59:01,194 CME_SERVICE ERROR Error during synchronization with Security Gateways.&lt;BR /&gt;Error details: Failed to scan for gateway instances in the cloud account xxxxxxxxxxxxxxxxxxx..&lt;BR /&gt;2022-05-23 16:59:01,200 CME_SERVICE ERROR Error traceback: Traceback (most recent call last):&lt;BR /&gt;File "/opt/CPcme/service/cme_service.py", line 433, in sync&lt;BR /&gt;filtered_instances = controller.filter_instances()&lt;BR /&gt;cloud_connectors.gcp.HTTPException: Unexpected HTTP code: 404&lt;/P&gt;&lt;P&gt;During handling of the above exception, another exception occurred:&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/CPcme/service/cme_service.py", line 584, in loop&lt;BR /&gt;sync(c, management, gateways)&lt;BR /&gt;cme_exceptions.cme_exceptions.ControllerException: Error Code: Failed to scan for gateway instances&lt;/P&gt;&lt;P&gt;Failed to scan for gateway instances in the cloud account xxxxxxxxxxxxxxxxxxx.&lt;BR /&gt;2022-05-23 16:59:01,200 CME_SERVICE INFO&lt;BR /&gt;2022-05-23 16:59:01,485 CME_SERVICE INFO There are no gateways known by the management at the end of the iteration&lt;BR /&gt;2022-05-23 16:59:01,485 CME_SERVICE INFO ********** End of the iteration number 523 for gateway instances. Iteration time:&lt;BR /&gt;0:00:02.401860 **********&lt;BR /&gt;&lt;BR /&gt;has anybody encountered this issue?&lt;BR /&gt;&lt;BR /&gt;I followed these instructions to set it up:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?TocPath=CME%20Structure%20and%20Configurations%7C_____0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?TocPath=CME%20Structure%20and%20Configurations%7C_____0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_and_Above_CG_Autoscaling_Managed_Instance_Group_for_GCP/AdminGuide/Content/Topics-Google-Managed-Instance-Group/Configuring-GCP.htm#Deploying-the-Check-Point-Autoscaling-Managed-Instance-Group" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_and_Above_CG_Autoscaling_Managed_Instance_Group_for_GCP/AdminGuide/Content/Topics-Google-Managed-Instance-Group/Configuring-GCP.htm#Deploying-the-Check-Point-Autoscaling-Managed-Instance-Group&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/95584/FILE/CP_CloudGuard_Network_for_GCP_Autoscaling_Managed_Instance_Group_R80.30_and_Higher_AdminGuide.pdf" target="_blank" rel="noopener"&gt;https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/95584/FILE/CP_CloudGuard_Network_for_GCP_Autoscaling_Managed_Instance_Group_R80.30_and_Higher_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-GCP-auto-provisioning-error/m-p/85195#M531" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-GCP-auto-provisioning-error/m-p/85195#M531&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 20:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CME-can-t-scan-for-MIG-gateway-instances-on-GCP/m-p/149273#M6025</guid>
      <dc:creator>Fednot</dc:creator>
      <dc:date>2022-05-23T20:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: CME can't scan for MIG gateway instances on GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CME-can-t-scan-for-MIG-gateway-instances-on-GCP/m-p/150655#M6026</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;According to the logs you shared, it looks like a permission issue,&lt;BR /&gt;Please make sure you followed the&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_and_Above_CG_Autoscaling_Managed_Instance_Group_for_GCP/AdminGuide/Content/Topics-Google-Managed-Instance-Group/Configuring-GCP.htm#Creating-GCP-Service-Account" target="_self"&gt;Creating-GCP-Service-Account&lt;/A&gt;, and your service account has the right permissions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are still facing the issue, please follow the below and open a ticket:&amp;nbsp;&lt;/P&gt;
&lt;DIV id="FAQ7"&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Collect CME Log Collector file as described in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm" target="_blank" rel="noopener"&gt;Cloud Management Extension R80.10 and Higher Administration Guide&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Troubleshooting &amp;gt; CME Log Collector.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/support-services/contact-support/" target="_blank" rel="noopener"&gt;Contact Check Point support&lt;/A&gt;, and request to open a ticket that includes CME Log Collector file collected in the previous step.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Natanel&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 12 Jun 2022 16:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CME-can-t-scan-for-MIG-gateway-instances-on-GCP/m-p/150655#M6026</guid>
      <dc:creator>natanelm</dc:creator>
      <dc:date>2022-06-12T16:34:05Z</dc:date>
    </item>
  </channel>
</rss>

