<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error 'GW can not access updates.checkpoint.com' (but it can) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181334#M33175</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have an HA cluster in my lab (Gaia 80.40). Both nodes have access to the internet (ping 1.1.1.1 for example is successful).&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in Smart console I see an error on both nodes in the IPS and Anti-Bot&amp;amp;Anti-Virus sections (Gateways&amp;amp;Servers - Click on GW - Device&amp;amp;License information - Device status):&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;TABLE cellspacing="0" cellpadding="2"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="850px" height="68px"&gt;Error: Update failed. Contract entitlement check failed. Gateway can not access internet ("&lt;A href="https://updates.checkpoint.com/WebService/services/DownloadMetaDataService" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com/WebService/services/DownloadMetaDataService&lt;/A&gt;"). Check connectivity and proxy settings&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But&amp;nbsp;curl_cli -v -k &lt;A href="https://updates.checkpoint.com" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com&lt;/A&gt;&amp;nbsp;is successful on both nodes:&lt;/P&gt;&lt;P&gt;Trying 184.50.201.193...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to updates.checkpoint.com (184.50.201.193) port 443 (#0)&lt;BR /&gt;* ALPN, offering http/1.1&lt;BR /&gt;* *** Current date is: Thu May 18 13:45:43 2023&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* err is -1, detail is 2&lt;BR /&gt;* *** Current date is: Thu May 18 13:45:43 2023&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, CERT verify (15):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Finished (20):&lt;BR /&gt;* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Finished (20):&lt;BR /&gt;* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384&lt;BR /&gt;* ALPN, server accepted to use http/1.1&lt;BR /&gt;* servercert: Activated&lt;BR /&gt;* servercert: CRL validation was disabled&lt;BR /&gt;* Server certificate:&lt;BR /&gt;* subject: CN=*.checkpoint.com&lt;BR /&gt;* start date: Dec 21 12:11:27 2022 GMT&lt;BR /&gt;* expire date: Jan 22 12:11:26 2024 GMT&lt;BR /&gt;* issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020&lt;BR /&gt;* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.&lt;BR /&gt;* servercert: Finished&lt;BR /&gt;* TLSv1.3 (OUT), TLS app data, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS app data, [no content] (0):&lt;BR /&gt;&amp;lt; HTTP/1.1 200 OK&lt;BR /&gt;&amp;lt; Content-Type: text/html&lt;BR /&gt;&amp;lt; Server: Apache-Coyote/1.1&lt;BR /&gt;&amp;lt; Content-Length: 10&lt;BR /&gt;&amp;lt; Date: Thu, 18 May 2023 10:45:41 GMT&lt;BR /&gt;&amp;lt; Connection: keep-alive&lt;BR /&gt;&amp;lt;&lt;BR /&gt;status=OK&lt;BR /&gt;* Connection #0 to host updates.checkpoint.com left intact&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there are a lot of posts like mine, but usually there is no internet or service is really down. In my case GW has internet access and CP services are OK as far as I know.&lt;/P&gt;&lt;P&gt;Also I have tried to do this one:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250&lt;/A&gt; But I don't seem to have such directories..I have only &lt;EM&gt;&lt;STRONG&gt;opt/CPshared//5.0/tmp...&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas how to fix this? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 18 May 2023 11:27:59 GMT</pubDate>
    <dc:creator>EmilliXill</dc:creator>
    <dc:date>2023-05-18T11:27:59Z</dc:date>
    <item>
      <title>Error 'GW can not access updates.checkpoint.com' (but it can)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181334#M33175</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have an HA cluster in my lab (Gaia 80.40). Both nodes have access to the internet (ping 1.1.1.1 for example is successful).&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in Smart console I see an error on both nodes in the IPS and Anti-Bot&amp;amp;Anti-Virus sections (Gateways&amp;amp;Servers - Click on GW - Device&amp;amp;License information - Device status):&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;TABLE cellspacing="0" cellpadding="2"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="850px" height="68px"&gt;Error: Update failed. Contract entitlement check failed. Gateway can not access internet ("&lt;A href="https://updates.checkpoint.com/WebService/services/DownloadMetaDataService" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com/WebService/services/DownloadMetaDataService&lt;/A&gt;"). Check connectivity and proxy settings&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But&amp;nbsp;curl_cli -v -k &lt;A href="https://updates.checkpoint.com" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com&lt;/A&gt;&amp;nbsp;is successful on both nodes:&lt;/P&gt;&lt;P&gt;Trying 184.50.201.193...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to updates.checkpoint.com (184.50.201.193) port 443 (#0)&lt;BR /&gt;* ALPN, offering http/1.1&lt;BR /&gt;* *** Current date is: Thu May 18 13:45:43 2023&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* err is -1, detail is 2&lt;BR /&gt;* *** Current date is: Thu May 18 13:45:43 2023&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, CERT verify (15):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Finished (20):&lt;BR /&gt;* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Finished (20):&lt;BR /&gt;* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384&lt;BR /&gt;* ALPN, server accepted to use http/1.1&lt;BR /&gt;* servercert: Activated&lt;BR /&gt;* servercert: CRL validation was disabled&lt;BR /&gt;* Server certificate:&lt;BR /&gt;* subject: CN=*.checkpoint.com&lt;BR /&gt;* start date: Dec 21 12:11:27 2022 GMT&lt;BR /&gt;* expire date: Jan 22 12:11:26 2024 GMT&lt;BR /&gt;* issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020&lt;BR /&gt;* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.&lt;BR /&gt;* servercert: Finished&lt;BR /&gt;* TLSv1.3 (OUT), TLS app data, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS app data, [no content] (0):&lt;BR /&gt;&amp;lt; HTTP/1.1 200 OK&lt;BR /&gt;&amp;lt; Content-Type: text/html&lt;BR /&gt;&amp;lt; Server: Apache-Coyote/1.1&lt;BR /&gt;&amp;lt; Content-Length: 10&lt;BR /&gt;&amp;lt; Date: Thu, 18 May 2023 10:45:41 GMT&lt;BR /&gt;&amp;lt; Connection: keep-alive&lt;BR /&gt;&amp;lt;&lt;BR /&gt;status=OK&lt;BR /&gt;* Connection #0 to host updates.checkpoint.com left intact&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there are a lot of posts like mine, but usually there is no internet or service is really down. In my case GW has internet access and CP services are OK as far as I know.&lt;/P&gt;&lt;P&gt;Also I have tried to do this one:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Failure-to-fetch-updates-from-CheckPoint-servers/m-p/87250&lt;/A&gt; But I don't seem to have such directories..I have only &lt;EM&gt;&lt;STRONG&gt;opt/CPshared//5.0/tmp...&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas how to fix this? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 11:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181334#M33175</guid>
      <dc:creator>EmilliXill</dc:creator>
      <dc:date>2023-05-18T11:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'GW can not access updates.checkpoint.com' (but it can)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181370#M33183</link>
      <description>&lt;P&gt;I would ask the TAC to assist in troubleshooting here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 16:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181370#M33183</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-18T16:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'GW can not access updates.checkpoint.com' (but it can)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181373#M33185</link>
      <description>&lt;P&gt;Can you ensure this is checked in global properties?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20971i0B8EC0AAEC4D4BDB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 17:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181373#M33185</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-18T17:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'GW can not access updates.checkpoint.com' (but it can)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181375#M33186</link>
      <description>&lt;P&gt;You can also refer to below sk:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106251&amp;amp;srcFavorites=favorites" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106251&amp;amp;srcFavorites=favorites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 17:15:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181375#M33186</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-18T17:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'GW can not access updates.checkpoint.com' (but it can)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181628#M33244</link>
      <description>&lt;P&gt;Thanks everyone! The problem was solved itself, did nothing. Did not even reboot &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 09:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-GW-can-not-access-updates-checkpoint-com-but-it-can/m-p/181628#M33244</guid>
      <dc:creator>EmilliXill</dc:creator>
      <dc:date>2023-05-22T09:58:03Z</dc:date>
    </item>
  </channel>
</rss>

