<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MDS R81.20 on KVM, fresh install broken. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228860#M64170</link>
    <description>&lt;P&gt;I suspect these qcow images are not set up to run MDS, which has different requirements than a regular SMS (more disk/RAM, NIC configuration).&lt;BR /&gt;What are the specs on the VM you’re attempting to deploy this on? (RAM/CPUs/Disk/NICs)&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 13:27:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-03T13:27:18Z</dc:date>
    <item>
      <title>MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228830#M64169</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm unable to get an MDS install working using &lt;A href="https://support.checkpoint.com/results/download/133476" target="_self"&gt;this&lt;/A&gt; qcow2 image. I've been using this image for Gateway and SMS for a couple of months in my lab, everything seems to work fine. With MDS, the first symptom I noticed is I can't connect with Smart Console. SSH and Web to Gaia work fine though.&lt;/P&gt;&lt;P&gt;When I tried to run `api status` I would get an error about the missing file&amp;nbsp;/opt/CPsuite-R81.20/fw1/conf/cpmServerSettings.props. I copied this from an SMS server to get past that error.&lt;/P&gt;&lt;P&gt;I also tried updating with the latest Take, but the Gaia web gui errors and suggests running `cpstop` but that doesn't work on an MDS server.&amp;nbsp;&lt;BR /&gt;I've tried about 5 times with a fresh VM, now I'm tearing my hair out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some probably relevant outputs that might help:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@cp-mds:0]# mdsstat

CPM: Check Point Security Management Server is not running

+------+--------------------+-----------------+-------------+-------------+-------------+-------------+-------------+
| Type | Name               | IP address      | FWM         | FWMHA       | FWD         | CPD         | CPCA        |
+------+--------------------+-----------------+-------------+-------------+-------------+-------------+-------------+
| MDS  |          -         | 172.30.32.10    | down        | down        | down        | down        | down        |
+------+--------------------+-----------------+-------------+-------------+-------------+-------------+-------------+
Total Domain Management Servers checked: 0     0 up   0 down
Tip: Run mdsstat -h for legend&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;[Expert@cp-mds:0]# mdsstart 
Starting cpWatchDog
Starting CPM Server ...
[1] 8715
CPM Server is running.
Start Search Infrastructure...
index mode was set to true
startsearch: dbsync does not run on Multi-Domain Security Management
cpwd_admin: 
Process SOLR started successfully (pid=9230) 
Starting RFL ...
cpwd_admin: 
Process RFL started successfully (pid=9262) 
Starting SmartView ...
Starting SmartView...
cpwd_admin: 
Process SMARTVIEW started successfully (pid=9311) 
Start Log Indexer...
cpwd_admin: 
Process INDEXER started successfully (pid=9594) 
Start SmartLog Server... 
cpwd_admin: 
Process SMARTLOG_SERVER started successfully (pid=9806) 

No need to run Adjuster Service - no clients were found
Starting Log Indexer...
[1]  + Done                          /opt/CPsuite-R81.20/fw1/scripts/ngm_start.sh
/opt/CPmds-R81.20/customers: No such file or directory.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@cp-mds:0]# api status

API Settings:
---------------------
Accessibility:                      Unknown
Automatic Start:                    Unknown

Processes:

Name      State     PID       More Information
-------------------------------------------------
API       Stopped   0         
CPM       Stopped   0         
FWM       Stopped   0         
APACHE    Started   8507      

Port Details:
-------------------
JETTY Internal Port:               0
JETTY Documentation Internal Port: 0
APACHE Gaia Port:                  443

Profile:
-------------------
Machine profile:                   Medium env resources profile
CPM heap size:                     1280m

                          Apache port retrieved from: httpd-ssl.conf


--------------------------------------------
Overall API Status: The API Server Is Not Running!
--------------------------------------------

API readiness test FAILED. The server is down and unable to receive connections!

Notes:
------------
To collect troubleshooting data, please run 'api status -s &amp;lt;comment&amp;gt;'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 08:20:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228830#M64169</guid>
      <dc:creator>LukeDRussell1</dc:creator>
      <dc:date>2024-10-03T08:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228860#M64170</link>
      <description>&lt;P&gt;I suspect these qcow images are not set up to run MDS, which has different requirements than a regular SMS (more disk/RAM, NIC configuration).&lt;BR /&gt;What are the specs on the VM you’re attempting to deploy this on? (RAM/CPUs/Disk/NICs)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 13:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228860#M64170</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-03T13:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228906#M64171</link>
      <description>&lt;P&gt;It will be easy enough for me to give it more resources. I can't remember where I found the requirements, but I'm currently running 4vCPU, 6 GB, virtio NICs. I'm not sure how big the disks were. One attempt I set the data disk to 100 GB manually.&lt;/P&gt;&lt;P&gt;I'd be happy to take a suggestion on sizing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 21:13:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228906#M64171</guid>
      <dc:creator>LukeDRussell1</dc:creator>
      <dc:date>2024-10-03T21:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228907#M64172</link>
      <description>&lt;P&gt;To me, that does not look like the right image for eve-ng. Did you follow below link to make sure naming is right? I know for mds, you would use same image as you were installing regular mgmt. I tested that before in eve-ng, no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.eve-ng.net/index.php/documentation/qemu-image-namings/" target="_blank"&gt;https://www.eve-ng.net/index.php/documentation/qemu-image-namings/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 21:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228907#M64172</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-03T21:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228908#M64173</link>
      <description>&lt;P&gt;I'm not using eve-ng.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 22:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228908#M64173</guid>
      <dc:creator>LukeDRussell1</dc:creator>
      <dc:date>2024-10-03T22:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228909#M64174</link>
      <description>&lt;P&gt;That's barely enough to run a gateway.&lt;BR /&gt;MDS needs a lot more resources (at least 32GB RAM, 8 Cores).&lt;BR /&gt;Refer to the requirements here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Open-Server-Hardware-Requirements.htm?TocPath=Open%20Server%20Hardware%20Requirements%7C_____0#Open_Server_Hardware_Requirements" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Open-Server-Hardware-Requirements.htm?TocPath=Open%20Server%20Hardware%20Requirements%7C_____0#Open_Server_Hardware_Requirements&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 22:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228909#M64174</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-03T22:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228910#M64175</link>
      <description>&lt;P&gt;I increased the specs in line with the &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RN/Topics-RN/Open-Server-Hardware-Requirements.htm" target="_self"&gt;Open Server minimums&lt;/A&gt;&amp;nbsp;for MDS (8c, 32GB, 150 GB disk) and it works immediately!&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 22:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228910#M64175</guid>
      <dc:creator>LukeDRussell1</dc:creator>
      <dc:date>2024-10-03T22:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228911#M64176</link>
      <description>&lt;P&gt;Sorry my bad for assuming so. Glad you got it working.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 00:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228911#M64176</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-04T00:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: MDS R81.20 on KVM, fresh install broken.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228913#M64177</link>
      <description>&lt;P&gt;I'm using Cisco Modelling Labs, which is built on top of KVM.&lt;/P&gt;&lt;P&gt;I also contributed some configs to &lt;A href="https://github.com/CiscoDevNet/cml-community/tree/master/virl-base-images/check-point" target="_self"&gt;CML-Community repo&lt;/A&gt; in case anyone else wants to run it. I'll add notes in that about increasing the resources for MDS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 03:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-R81-20-on-KVM-fresh-install-broken/m-p/228913#M64177</guid>
      <dc:creator>LukeDRussell1</dc:creator>
      <dc:date>2024-10-04T03:19:19Z</dc:date>
    </item>
  </channel>
</rss>

