<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20 Gateways with CME not supported? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169512#M608</link>
    <description>&lt;P&gt;We started supporting CPUSE upgrade for MDS/MGMT in AWS.&lt;/P&gt;
&lt;P&gt;Try with this:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk177714" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk177714&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jan 2023 09:33:32 GMT</pubDate>
    <dc:creator>Amir_Senn</dc:creator>
    <dc:date>2023-01-29T09:33:32Z</dc:date>
    <item>
      <title>R81.20 Gateways with CME not supported?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169112#M605</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we tried to deploy some new R81.20 gateways in a GWLB setup and failed with the CME setup. We've got the following setup:&lt;/P&gt;&lt;P&gt;Version of the MDS Server:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;CheckPoint R81.10 JHF 66&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;autoprov_cfg -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CME Version: Build: 991592204 Take: 222&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;parts of: &lt;FONT face="courier new,courier"&gt;autoprov_cfg show all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;controllers:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"aws_island":&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;access-key: xxxxxxxxxxxxxxxxxxxxxxx&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;class: AWS&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;regions:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;- eu-central-1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;- eu-south-1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;secret-key: "__protected__autoprovision/controllers/xxxxxxxxxxxxxxxxxx/secret-key"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;sync:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;gateway: true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;templates:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;- "aws_island_R8040"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;- "aws_island_R8120"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;templates:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"aws_island_R8120":&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;application-control: true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;health-check-ip-range: "10.123.0.0,10.123.255.255"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;identity-awareness: true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ips: true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;one-time-password: "__protected__autoprovision/xxxxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxxxx/one-time-password"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;policy: "AWS_Integration"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;send-alerts-to-server: fwlogxxxxxxxxxxxx&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;send-logs-to-server: fwlogxxxxxxxxxxxxxx&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;url-filtering: true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;version: "R81.20"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;----------------------------&lt;/P&gt;&lt;P&gt;cme.log shows:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;2023-01-24 15:30:56,437 CME_SERVICE INFO aws_island--i-000bbdec1f6babbd2--eu-central-1 state is changed to: ADDING&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2023-01-24 15:30:56,469 CME_SERVICE ERROR Failed to provision the Security Gateway instance aws_island--i-000bbdec1f6babbd2--eu-central-1.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error details: Management API failure (add-simple-gateway)..&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2023-01-24 15:30:56,480 CME_SERVICE ERROR Error traceback: Traceback (most recent call last):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/service/cme_service.py", line 536, in sync&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;instance, gw, auto_hf)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_autoprovision_handler.py", line 1755, in set_gateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;args = self.establish_gateway(instance, gw)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_autoprovision_handler.py", line 198, in establish_gateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;simple_gateway=simple_gateway)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_autoprovision_handler.py", line 244, in configure_gateway_metadata&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;remove_if_ip_exists_in_cpm=True)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_autoprovision_handler.py", line 286, in add_gateway_to_cpm&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;self.management(CPMCommand.ADD_SIMPLE_GATEWAY, gw)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_handler.py", line 177, in __call__&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;silent=silent)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;File "/opt/CPcme/cp_handlers/mgmt_api_handler.py", line 126, in __call__&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CMEExceptionCodes.MGMT_API, command=command)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cme_exceptions.cme_exceptions.ManagementApiException: Error Code: Management API error&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;API call failed with command: add-simple-gateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Payload: {'name': 'aws_island--i-000bbdec1f6babbd2--eu-central-1', 'ip-address': '10.123.242.12', 'interfaces': [{'name': 'eth0', 'ipv4-address': '10.123.242.12', 'ipv4-mask-length': 28, 'anti-spoofing': False, 'topology': 'internal'}],&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;*****, 'version': 'R81.20', 'comments': '{tags=managed-virtual-gateway}'}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error details: {'code': 'generic_err_invalid_parameter', 'message': 'Invalid parameter for [version]. &lt;FONT color="#FF0000"&gt;The invalid value [R81.20] should be replaced by one of the following values: [R75.40 and above]'&lt;/FONT&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;While R81.10 seems to work as version string, R81.20 does not ;-). Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 13:35:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169112#M605</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2023-01-25T13:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Gateways with CME not supported?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169183#M606</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8172"&gt;@Doeschi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Please see&amp;nbsp;J&lt;SPAN&gt;umbo Hotfix Accumulator for R81.10.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/Take_82.htm?tocpath=Previously%20Released%20Takes%7C_____2" target="_self"&gt;JHF take 82 note:&lt;/A&gt; Added ability for R81.10 Security Management and Multi-Domain Security Management Server to manage R81.20 Security Gateways. It Requires R81.10 SmartConsole Build 412 (or higher).&lt;/P&gt;
&lt;P&gt;You mentioned that your MDS version is R81.10 JHF 66, so you probably need to install JHF take 82 or higher.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Natanel&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 20:18:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169183#M606</guid>
      <dc:creator>natanelm</dc:creator>
      <dc:date>2023-01-25T20:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Gateways with CME not supported?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169243#M607</link>
      <description>&lt;P&gt;Thanks, must have missed that... will give it a try, upgrading our mds isn't a small task tho&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 08:17:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169243#M607</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2023-01-26T08:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Gateways with CME not supported?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169512#M608</link>
      <description>&lt;P&gt;We started supporting CPUSE upgrade for MDS/MGMT in AWS.&lt;/P&gt;
&lt;P&gt;Try with this:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk177714" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk177714&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 09:33:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R81-20-Gateways-with-CME-not-supported/m-p/169512#M608</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2023-01-29T09:33:32Z</dc:date>
    </item>
  </channel>
</rss>

