<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error: Update failed. Contract entitlement check failed on VSX deployment in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207555#M34433</link>
    <description>&lt;P&gt;On VSX and on VS...&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 12:46:06 GMT</pubDate>
    <dc:creator>SinisaZG</dc:creator>
    <dc:date>2024-03-01T12:46:06Z</dc:date>
    <item>
      <title>Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207552#M34430</link>
      <description>&lt;P&gt;A few days ago an error appeared on one of the two VSX gateways ( one is fine, no errors):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Status Failed (Anti-bot, anti-virus)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Description Update failed. Contract entitlement check failed. Could not reach "updates.checkpoint.com". Check DNS and Proxy configuration on the gateway. &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Next update The next try will be within one hour&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;three virtual systems -&amp;nbsp;an error is displayed on all of them.&lt;/P&gt;&lt;P&gt;I tried to reboot the VSX gateway&amp;nbsp;several times &amp;nbsp;on which the problem is present - no luck&lt;/P&gt;&lt;P&gt;I tried to deinstall/install Anti-virus, Anti-bot - no&amp;nbsp; luck&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output of command&amp;nbsp;&lt;SPAN&gt;curl_cli -v -k&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://updates.checkpoint.com/WebService/services/DownloadMetaDataService" target="_blank" rel="noopener noreferrer"&gt;https://updates.checkpoint.com/WebService/services/DownloadMetaDataService&lt;/A&gt;&amp;nbsp;;&lt;/P&gt;&lt;P&gt;* Trying 23.212.89.172...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to updates.checkpoint.com (23.212.89.172) port 443 (#0)&lt;BR /&gt;* ALPN, offering http/1.1&lt;BR /&gt;* *** Current date is: Fri Mar 1 13:11:27 2024&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* err is -1, detail is 2&lt;BR /&gt;* *** Current date is: Fri Mar 1 13:11:27 2024&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, CERT verify (15):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Finished (20):&lt;BR /&gt;* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Finished (20):&lt;BR /&gt;* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384&lt;BR /&gt;* ALPN, server accepted to use http/1.1&lt;BR /&gt;* servercert: Activated&lt;BR /&gt;* servercert: CRL validation was disabled&lt;BR /&gt;* Server certificate:&lt;BR /&gt;* subject: CN=*.checkpoint.com&lt;BR /&gt;* start date: Dec 31 11:43:57 2023 GMT&lt;BR /&gt;* expire date: Jan 31 11:43:56 2025 GMT&lt;BR /&gt;* issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020&lt;BR /&gt;* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.&lt;BR /&gt;* servercert: Finished&lt;BR /&gt;* TLSv1.3 (OUT), TLS app data, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, [no content] (0):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;* TLSv1.3 (IN), TLS app data, [no content] (0):&lt;BR /&gt;&amp;lt; HTTP/1.1 200 OK&lt;BR /&gt;&amp;lt; Content-Type: text/xml;charset=UTF-8&lt;BR /&gt;&amp;lt; Content-Length: 410&lt;BR /&gt;&amp;lt; Server: Apache-Coyote/1.1&lt;BR /&gt;&amp;lt; Date: Fri, 01 Mar 2024 12:11:27 GMT&lt;BR /&gt;&amp;lt; Connection: keep-alive&lt;/P&gt;&lt;P&gt;System is on R81.20, Take 38&lt;BR /&gt;I know there are a lot of posts like mine and&amp;nbsp; I have tried everything from similar posts listed&lt;/P&gt;&lt;P&gt;I'm out of ideas.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207552#M34430</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-01T12:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207553#M34431</link>
      <description>&lt;P&gt;Looks like there is an issue with the certificate validation. Please open a TAC ticket for this.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:41:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207553#M34431</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-01T12:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207554#M34432</link>
      <description>&lt;P&gt;Are you talking about an error on VSX itself or on the VS?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207554#M34432</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-01T12:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207555#M34433</link>
      <description>&lt;P&gt;On VSX and on VS...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:46:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207555#M34433</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-01T12:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207556#M34434</link>
      <description>&lt;P&gt;Thank you Val,&amp;nbsp;I will do so.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207556#M34434</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-01T12:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207557#M34435</link>
      <description>&lt;P&gt;Is the error on gateway, mgmt or both?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 13:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207557#M34435</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-01T13:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207558#M34436</link>
      <description>&lt;P&gt;You got me thinking.... you mean when I try command&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;curl_cli -v -k ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just tried to do this on a VSX GTW that is ok and&amp;nbsp; on a management server.... the output is the same on&amp;nbsp;all three examples regarding&amp;nbsp;&amp;nbsp;the certificate validation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;servercert: Activated&lt;BR /&gt;* servercert: CRL validation was disabled&lt;BR /&gt;* Server certificate:&lt;BR /&gt;* subject: CN=*.checkpoint.com&lt;BR /&gt;* start date: Dec 31 11:43:57 2023 GMT&lt;BR /&gt;* expire date: Jan 31 11:43:56 2025 GMT&lt;BR /&gt;* issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020&lt;BR /&gt;* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Issue is only with&amp;nbsp;Anti-bot, Anti-virus Blades only on one&amp;nbsp; VSX gateway in Cluster ( other is fine)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 13:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207558#M34436</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-01T13:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207560#M34437</link>
      <description>&lt;P&gt;I mean the update failed error. You see it on gateway or mgmt or both?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the certificate error is not related to this issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;also assume the issue is only on the standby member? If you do failover the problem then moves to other new standby member?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 13:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207560#M34437</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-01T13:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207571#M34438</link>
      <description>&lt;P&gt;Update failed error is related only to Anti-bot, Anti-virus Blades - Gateway Blades. Everything else is fine.&lt;/P&gt;&lt;P&gt;You are right. The issue is with the "standby" member, (it's not classic HA because of the VSLS and a customer who often uses its features.)&lt;/P&gt;&lt;P&gt;I will test with failover and try to see the results.... thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 17:27:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/207571#M34438</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-01T17:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/208080#M34479</link>
      <description>&lt;P&gt;I did a failover, I tested with different options&amp;nbsp;&lt;SPAN&gt;vsx_util vsls,&amp;nbsp;admin up|down,&amp;nbsp;cphastop|start.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error is present only on one gateway (no matter if it is a active or standby) and is now&amp;nbsp;present in two out of three virtual systems just for&amp;nbsp;Anti-Virus Update Status . Anti-Bot Update Status is ok now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So far it has been a problem with all three virtual systems (Anti-Virus&amp;amp;Anti-Bot)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Before failover I also tested connection with&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# curl_cli -v -1 --cacert $CPDIR/conf/ca-bundle.crt &lt;A href="https://updates.checkpoint.com" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl_cli -v -1 --cacert $CPDIR/conf/ca-bundle.crt &lt;A href="https://secureupdates.checkpoint.com" target="_blank" rel="noopener"&gt;https://secureupdates.checkpoint.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl_cli -v &lt;A href="http://cws.checkpoint.com" target="_blank" rel="noopener"&gt;http://cws.checkpoint.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105757" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk105757&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and checked status of&amp;nbsp;parameter 'fwha_forw_packet_to_not_active' and its set to 1&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk43807" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk43807&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Right now it's quite confusing and I'm out of ideas so&amp;nbsp;&lt;SPAN&gt;I am waiting for feedback from TAC&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 13:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/208080#M34479</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-03-07T13:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/208092#M34480</link>
      <description>&lt;P&gt;I would say this might be worth TAC case, as you also rebooted the gateway, but no luck.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 13:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/208092#M34480</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-07T13:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/212934#M35222</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we said, it was worth getting TAC involved...&lt;/P&gt;&lt;P&gt;I will try to be as clear as possible:&lt;/P&gt;&lt;P&gt;The TAC team could not find anything that would cause the issues.&amp;nbsp;&lt;BR /&gt;Before engaging the R&amp;amp;D team, we decided to update the system to the latest version first. (Take 38&amp;nbsp;was present.)&lt;BR /&gt;After updating the system, the error disappeared on all virtual systems except VS0, where it was replaced with the error "database version unknown" (IPS).&lt;BR /&gt;It has been confirmed that it is a bug in the system, and we are waiting for the R&amp;amp;D&amp;nbsp; team to make a hotfix.&lt;BR /&gt;Apparently, the same error occurs on older versions of the system, where it was solved by applying a hotfix.&lt;BR /&gt;In the meantime, while we were waiting for a hotfix from the R&amp;amp;D team, the problem resolved itself.&lt;BR /&gt;There are no more errors on the VSX system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/212934#M35222</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2024-05-02T12:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Error: Update failed. Contract entitlement check failed on VSX deployment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/212935#M35223</link>
      <description>&lt;P&gt;Thanks for the update!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Error-Update-failed-Contract-entitlement-check-failed-on-VSX/m-p/212935#M35223</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-02T12:11:55Z</dc:date>
    </item>
  </channel>
</rss>

