<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File-System read-only on 1530 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212985#M10580</link>
    <description>&lt;P&gt;Just spun up R81.10.10 smb lab and I dont see the option from sk126372 there at all.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25496i68F7849DB837B158/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2024 14:33:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-05-02T14:33:41Z</dc:date>
    <item>
      <title>File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212941#M10561</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;We have a customer running about 60 SMB appliances, all of them using R77.20.x (1430) or R81.10.x (1530).&lt;/P&gt;
&lt;P&gt;(Yes, the customer knows that the 1430s have to be replaced in the next months.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;)&lt;/P&gt;
&lt;P&gt;My problem is with the 1530s. At the moment I have 4 of them where I cannot install policy. If I do a "fw fetch" on them I get this:&lt;/P&gt;
&lt;PRE&gt;[Expert@cp-xxx01]# &lt;STRONG&gt;fw fetch&lt;/STRONG&gt;&lt;BR /&gt;ndb_open : failed for /opt/fw1/database/fwauth.NDB: &lt;STRONG&gt;Read-only file system&lt;/STRONG&gt;&lt;BR /&gt;fwa_db_init: fwdab_init failed&lt;BR /&gt;fwd_reload_database: Error loading from fwauth.NDB&lt;BR /&gt;Fetching Security Policy from 'aaa.bbb.ccc.ddd'&lt;BR /&gt;&lt;BR /&gt;Local Security Policy is Up-To-Date.&lt;BR /&gt;&lt;BR /&gt;Error: Failed to run policy installation wrapper.&lt;BR /&gt;sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/local/FW1"'. rc=1, exit code =-1&lt;BR /&gt;Unable to install the Security Policy on the appliance&lt;BR /&gt;[Expert@cp-xxx01]# &lt;/PRE&gt;
&lt;P&gt;All of these appliances are running&amp;nbsp;R81.10.00 - Build 575. I know that R81.10.08 - Build&amp;nbsp;&amp;nbsp;683 is recommended release. Update is planned but it will take a serious amount of time, because update has to be coordinated with every single location.&lt;/P&gt;
&lt;P&gt;So, at the moment I have to deal with R81.10.00. I found out that other 1530s with this version have no problems. And I know that there exists a problem with partition /pfrm2.0 filled above 85 % on R77.20.x (&lt;A href="https://support.checkpoint.com/results/sk/sk126372" target="_blank" rel="noopener"&gt;sk126372&lt;/A&gt;). I cannot find a SK with this limitation for R81.10.x.&lt;/P&gt;
&lt;P&gt;But I found that all 1530s with problems have /pfrm2.0 filled above 85 %, the ones working are below this watermark. Since I have problems to get reboot clearance for the systems I would like to know…&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;… if anybody there had the same problem with R81.10.x on SMB and solved the problem with reboot – and if only for the moment.&lt;/LI&gt;
&lt;LI&gt;… if anybody knows if the workaround from&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105217" target="_blank" rel="noopener"&gt;sk105217&lt;/A&gt;&amp;nbsp;(fiddeling with IPS protections) will do the job. I have little doubt on this because other 1530s are running without implementing the workaround and I do not want to weaken IPS.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;… if anybody knows if the workaround from&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk126372" target="_blank" rel="noopener"&gt;sk126372&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;(setting a link for&amp;nbsp;$FWDIR/state/__tmp/FW1 to /storage partition) will also work for R81.10.x. The parameter in the advanced settings exists but the SK only mentions R77.20. I implemented this to all 1430s.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Any help will be appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Oliver&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212941#M10561</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2024-05-02T12:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212979#M10577</link>
      <description>&lt;P&gt;Hey Oliver,&lt;/P&gt;
&lt;P&gt;Personally, I would call TAC and ask them to confirm, because that sk126372 states that if running R77.20.80 or higher, it would apply. Let me build quick SMB lab and see if the option is even there, will let you know.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 14:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212979#M10577</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-02T14:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212985#M10580</link>
      <description>&lt;P&gt;Just spun up R81.10.10 smb lab and I dont see the option from sk126372 there at all.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25496i68F7849DB837B158/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 14:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/212985#M10580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-02T14:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213049#M10584</link>
      <description>&lt;P&gt;Got a possibility to reboot one of the failing appliances. That fixes the problem. Now /pfrm2.0 is at 81 % and writable again. So I am looking for a permanent fix…&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 06:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213049#M10584</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2024-05-03T06:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213050#M10585</link>
      <description>&lt;P&gt;Maybe it is the correct way to ask TAC. In the past, I got faster answers here from Check Point employees several times.&lt;BR /&gt;&lt;BR /&gt;You are right that&amp;nbsp;&lt;SPAN&gt;sk126372 states that you do not need a customer hotfix for R77.20.80 and higher. But the SK ist limited to R77.20. Such, I guess they are talking about the version up to R77.20.87.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 07:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213050#M10585</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2024-05-03T07:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213051#M10586</link>
      <description>&lt;P&gt;I have no R81.10.10 avaible, but where still able to find this option in R81.10.08. I did some more research an found this in the &lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/set-additional-management-settings-install-temporary-policy-to-storage.htm?tocpath=Additional%20Management%20Settings%7C_____1" target="_blank" rel="noopener"&gt;&lt;EM&gt;R81.10.x&amp;nbsp;Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances CLI Reference Guide&lt;/EM&gt;&lt;/A&gt;:&lt;/P&gt;
&lt;H3 class="lia-indent-padding-left-30px"&gt;set additional-management-settings install-temporary-policy-to-storage&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;In the R81.10.X releases, this command is available starting from the R81.10.00 version.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Configure additional management settings.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Syntax&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;set additional-management-settings advanced-settings install-temporary-policy-to-storage { true | false }&lt;/P&gt;
&lt;P&gt;I think, I will give this a try.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 07:27:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213051#M10586</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2024-05-03T07:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213052#M10587</link>
      <description>&lt;P&gt;Seems to be the same as in Web GUI and is also available in R77.20.87…&lt;/P&gt;
&lt;P&gt;(But I do not see any hint that a reboot is necessary.)&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 07:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213052#M10587</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2024-05-03T07:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213061#M10590</link>
      <description>&lt;P&gt;Yes, does not hurt to attempt it.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 11:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213061#M10590</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-03T11:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: File-System read-only on 1530</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213062#M10591</link>
      <description>&lt;P&gt;Check out this post where TAC advised of a fix for it in R81.10.10&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/Could-not-set-administrator-password-Field-must-have-a-value/m-p/212951#M10562" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/Could-not-set-administrator-password-Field-must-have-a-value/m-p/212951#M10562&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I logged a call and support kindly pointed me at :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181134" target="_blank" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk181134&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Where it states from Build 996002845 of R81.10.10:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;SMBGWY-7083&lt;/TD&gt;
&lt;TD&gt;General&lt;/TD&gt;
&lt;TD&gt;The Quantum Spark appliance automatically removes files from the "/tmp" partition if the file becomes full.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 03 May 2024 11:32:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/File-System-read-only-on-1530/m-p/213062#M10591</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-03T11:32:58Z</dc:date>
    </item>
  </channel>
</rss>

