<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-WAN Failed to enforce new policy in SD-WAN</title>
    <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194324#M153</link>
    <description>&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;i would like to take a look and investigate it,&lt;/P&gt;
&lt;P&gt;Please send me an email to: amirar@checkpoint.com&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2023 14:42:09 GMT</pubDate>
    <dc:creator>AmirArama</dc:creator>
    <dc:date>2023-10-05T14:42:09Z</dc:date>
    <item>
      <title>SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194264#M147</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running a PoC in a customer enviroment for Quantum-SDWAN. We are testing WAN connectivity between a central 5600 cluster (R81.20 jumbo 24) and a branch cluster with 2 X SMB 1600 gateways version R81.10.08. All the enrollment went ok but at some point the SMB cluster stopped updating SDWAN policy. We get this error on /var/log/nano_agent/cp-nano-sdwan.dbg:&lt;/P&gt;
&lt;P&gt;Failed to load gateway database: Got error running cpsdwan command /opt/fw1/bin/cpsdwan get_data Failed to enforce new policy.(Return code: 5).&lt;/P&gt;
&lt;P&gt;I have tried reinstalling the nano agent, fetching new sdwan policy manually and upgrading the gateways (before they were in version R81.10.07) but no luck.&amp;nbsp;sk181147 suggests to contac TAC, but this is a PoC so no valid license for SD-WAN rigth now. Maybe some hint to fix this?&amp;nbsp; Management is running R81.20 jumbo take 24. Thanks in advance.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 20:29:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194264#M147</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-04T20:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194287#M148</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please see about reestablishing SIC as is suggested below...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SIC.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22692i2DF7158A6B6FA5A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SIC.png" alt="SIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks. O&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 07:41:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194287#M148</guid>
      <dc:creator>orlib</dc:creator>
      <dc:date>2023-10-05T07:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194295#M149</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It seems I responded with image, but this needs approval, so in any case...&lt;/P&gt;
&lt;P&gt;This may mean that the connection between the Mgmt. and GW is not properly initialized, as perhaps something was done along the way. Please check the SIC status, and in case SIC not properly working, see about resetting the SIC in the SMC, and installing policy, and see if this resolves the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should also see in the Infinity Portal Events, the reason for the policy failure, and a suggested remediation for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let us know if this helps. Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 09:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194295#M149</guid>
      <dc:creator>orlib</dc:creator>
      <dc:date>2023-10-05T09:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194307#M150</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/100784"&gt;@orlib&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for the suggestion. As you said, Infinity portal showed that recommnedation "&lt;SPAN&gt;Reset the Security Gateway SIC via the SmartConsole management UI, and install Policy to apply the changes.If the issue persists, contact Check Point Support.&lt;/SPAN&gt;" but SIC was working Ok and we are able to push policy without problems. I tried reset SIC on standby member to test and after reset SIC, SD-WAN policy is still on version 11 (current version is 14). Also tried cpsdwan fetch_new, it ends with a success message, but policy version is still 11.&lt;/P&gt;
&lt;P&gt;[Expert@hostname02]# cpsdwan fetch_new&lt;BR /&gt;Fetch new policy succeeded&lt;BR /&gt;[Expert@hostname02]# cpsdwan stat&lt;BR /&gt;SD-WAN Policy Status:&lt;BR /&gt;Policy Version: 11&lt;BR /&gt;SD-WAN Policy ID: 1692836744&lt;BR /&gt;SD-WAN Steering Policy ID: 7270678452947124226 (2)&lt;BR /&gt;Policy Installation Date and Time: 05/10/2023 08:37:49.657&lt;BR /&gt;[Expert@hostanem02]#&lt;/P&gt;
&lt;P&gt;It is strange that it worked ok until version 11, something happened after that but i can't imagine what.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 12:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194307#M150</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-05T12:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194314#M151</link>
      <description>&lt;P&gt;could you please share the output of cpnano -s&lt;BR /&gt;and the content of the following file:&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider dy bbp bbq bbr bbs bbt bbu bbv bbw bbx bby bbz bca bcb bcc bcd bce bcf bcg bch bci bcj bck bcl bcm bcn bco bcp bcq bcr bcs bct bcu bcv bcw"&gt;cat /etc/cp/conf/orchestration/orchestration.policy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 13:07:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194314#M151</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-05T13:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194318#M152</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Output of those two commands below:&lt;/P&gt;
&lt;P&gt;[Expert@hostname01]# cpnano -s&lt;BR /&gt;---- Check Point Nano Agent ----&lt;BR /&gt;Version: 1.2338.677606&lt;BR /&gt;Status: Running&lt;BR /&gt;Last update attempt: 2023-10-05T10:16:24.934415&lt;BR /&gt;Last update status: Succeeded&lt;BR /&gt;Last update: 2023-10-05T10:16:25.003476&lt;BR /&gt;Last manifest update: 2023-10-04T14:05:13.718521&lt;BR /&gt;Policy version:&lt;BR /&gt;Last policy update: 2023-10-05T10:16:25.003566&lt;BR /&gt;Last settings update: 2023-10-04T14:03:56.617593&lt;BR /&gt;Upgrade mode: automatic&lt;BR /&gt;Fog address: &lt;A href="https://inext-agents-us.cloud.ngen.checkpoint.com" target="_blank"&gt;https://inext-agents-us.cloud.ngen.checkpoint.com&lt;/A&gt;&lt;BR /&gt;Registration status: Succeeded&lt;BR /&gt;Registration details:&lt;BR /&gt;Name: hostname01&lt;BR /&gt;Type: Quantum&lt;BR /&gt;Platform: smb_thx_v3&lt;BR /&gt;Architecture: aarch64&lt;BR /&gt;Agent ID: 97a53f35-20a6-4f00-be0f-5a17e0a32500&lt;BR /&gt;Profile ID: dcc34cf1-aad7-2a9a-d258-23b43342580f&lt;BR /&gt;Tenant ID: e9b926cc-e662-4853-8909-4b9322282c24&lt;BR /&gt;Manifest status: Succeeded&lt;BR /&gt;Service policy:&lt;BR /&gt;registration-data: /etc/cp/conf/registration-data/registration-data.policy&lt;BR /&gt;sdwan: /etc/cp/conf/sdwan/sdwan.policy&lt;BR /&gt;versions: /etc/cp/conf/versions/versions.policy&lt;BR /&gt;Service settings:&lt;/P&gt;
&lt;P&gt;---- Check Point Orchestration Nano Service ----&lt;BR /&gt;Type: Public, Version: 1.2338.677606, Created at: 2023-09-18T13:49:18+0300&lt;BR /&gt;Status: Running&lt;/P&gt;
&lt;P&gt;---- Check Point SD-WAN Nano Service ----&lt;BR /&gt;Type: Public, Version: 1.2338.677606, Created at: 2023-09-18T13:49:18+0300&lt;BR /&gt;Status: Running&lt;/P&gt;
&lt;P&gt;---- Check Point SD-WAN Logger Nano Service ----&lt;BR /&gt;Type: Public, Version: 1.2338.677606, Created at: 2023-09-18T13:49:18+0300&lt;BR /&gt;Status: Running&lt;/P&gt;
&lt;P&gt;---- Check Point Cpview Metric Provider Nano Service ----&lt;BR /&gt;Type: Public, Version: 1.2338.677606, Created at: 2023-09-18T13:49:18+0300&lt;BR /&gt;Status: Running&lt;/P&gt;
&lt;P&gt;+--------------------------------------+--------------------------------+---------+&lt;BR /&gt;| ID | Name | Version |&lt;BR /&gt;+--------------------------------------+--------------------------------+---------+&lt;BR /&gt;| | | v |&lt;BR /&gt;+--------------------------------------+--------------------------------+---------+&lt;BR /&gt;[Expert@hostname01]#&lt;/P&gt;
&lt;P&gt;[Expert@hostname01]# cat /etc/cp/conf/orchestration/orchestration.policy&lt;BR /&gt;{"fog-address":"&lt;A href="https://inext-agents-us.cloud.ngen.checkpoint.com" target="_blank"&gt;https://inext-agents-us.cloud.ngen.checkpoint.com&lt;/A&gt;","pulling-interval":30,"error-pulling-interval":30}[Expert@hostname01]#&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 14:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194318#M152</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-05T14:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194324#M153</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;i would like to take a look and investigate it,&lt;/P&gt;
&lt;P&gt;Please send me an email to: amirar@checkpoint.com&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 14:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194324#M153</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-05T14:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194333#M154</link>
      <description>&lt;P&gt;Issue was due to SMC topology misconfiguration.&amp;nbsp;&lt;BR /&gt;Issue solved.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 18:07:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/194333#M154</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-05T18:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN Failed to enforce new policy</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/271566#M360</link>
      <description>&lt;P&gt;Hello , ¿wich problem? , please explain , regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Feb 2026 06:31:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-Failed-to-enforce-new-policy/m-p/271566#M360</guid>
      <dc:creator>emonteagudo</dc:creator>
      <dc:date>2026-02-22T06:31:20Z</dc:date>
    </item>
  </channel>
</rss>

