<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem to install policy in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73686#M2887</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot deploy new policies on our series 1400 too.&lt;/P&gt;&lt;P&gt;We updated our manager server to the latest 80.10 Hotfix (take 249).&lt;/P&gt;&lt;P&gt;Now I get the error on all my 1400 checkpoints:&lt;BR /&gt;cannot access /opt/CPSFWR77CMP-R80//CONF/lsm_cluster_subnet_override.xml: no such file or directory&lt;/P&gt;&lt;P&gt;I don't know why there are 2 // in the path.&lt;BR /&gt;&lt;BR /&gt;The folder /opt/CPSFWR77CMP-R80/ is present on our management server but not on 1400 devices.&lt;/P&gt;&lt;P&gt;Also /opt/CPSFWR77CMP-R80/conf is there (for sure with one /) but the file lsm_cluster_subnet_override.xml is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I tried to install the RPM package and I have the folder /sysimg/CPwrapper/linux/CPsfwr77cmp on my management, but the folder is empty.&lt;/P&gt;&lt;P&gt;What now?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 15:41:38 GMT</pubDate>
    <dc:creator>Lars_S_</dc:creator>
    <dc:date>2020-01-29T15:41:38Z</dc:date>
    <item>
      <title>Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22766#M927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to install a policy on my 1430/1450 GW with Smart Console. When i try to install the policy for gateway VPNbox1 I get the following error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway: VPNbox1&lt;BR /&gt;Policy: Policy_VPNBox1&lt;BR /&gt;Status: Failed&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;- Compatibility package is not properly installed or configured.&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Gateways are according to the picture bellow:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62040_pastedImage_1.png" style="width: 620px; height: 82px;" /&gt;&lt;/P&gt;&lt;P&gt;On my 1430/1450 unit I get an error when I try to fetch the policy.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62041_pastedImage_2.png" style="width: 620px; height: 482px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that theses two errors is related?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a policy so the DCP traffic allowed in the gw-833ff3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the fw monitor i get traffic between the eth interfaces on i,I,o and O&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gw-833ff3&amp;gt; fw monitor -e "host(XXX.XXX.XXX.XXX), accept;"&lt;BR /&gt;&amp;nbsp;monitor: getting filter (from command line)&lt;BR /&gt;&amp;nbsp;monitor: compiling&lt;BR /&gt;monitorfilter:&lt;BR /&gt;Compiled OK.&lt;BR /&gt;&amp;nbsp;monitor: loading&lt;BR /&gt;&amp;nbsp;monitor: monitoring (control-C to stop)&lt;BR /&gt;[vs_0][fw_1] eth5:i[60]: XXX.XXX.XXX.XXX -&amp;gt; XXX.XXX.XXX.XXX (TCP) len=60 id=16128&lt;BR /&gt;TCP: 50078 -&amp;gt; 18191 .S.... seq=bb411dba ack=00000000&lt;BR /&gt;[vs_0][fw_1] eth5:I[60]: XXX.XXX.XXX.XXX -&amp;gt; XXX.XXX.XXX.XXX (TCP) len=60 id=16128&lt;BR /&gt;TCP: 50078 -&amp;gt; 18191 .S.... seq=bb411dba ack=00000000&lt;BR /&gt;[vs_0][fw_1] eth5:o[60]: XXX.XXX.XXX.XXX -&amp;gt; XXX.XXX.XXX.XXX (TCP) len=60 id=0&lt;BR /&gt;TCP: 18191 -&amp;gt; 50078 .S..A. seq=d491f51f ack=bb411dbb&lt;BR /&gt;[vs_0][fw_1] eth5:O[60]: XXX.XXX.XXX.XXX -&amp;gt; XXX.XXX.XXX.XXX (TCP) len=60 id=0&lt;/P&gt;&lt;P&gt;And alot more packages that i are not including&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2018 16:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22766#M927</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-12T16:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22767#M928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are very much related.&lt;/P&gt;&lt;P&gt;SMB gateways require a different policy compilation process than a regular appliance.&lt;/P&gt;&lt;P&gt;This is provided through means of a compatibility package.&lt;/P&gt;&lt;P&gt;Because the system is not finding the correct compatibility package, no policy can be compiled for the gateway.&lt;/P&gt;&lt;P&gt;When the gateway tries to fetch said policy, it fails because none could be successfully compiled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's puzzling to me is why this isn't already installed as it should be by default.&lt;/P&gt;&lt;P&gt;You can verify it is installed by running the command from expert mode:&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;rpm -q CPSFWR77CMP-R80&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;If this returns "package is not installed" then&amp;nbsp;the package did not get installed.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;While you may be able to mount an installation CD/ISO, find the RPM, and install it using rpm -i,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;I suspect you'd be better off doing a fresh install on your 3000 series appliance.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Jan 2018 01:38:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22767#M928</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-13T01:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22768#M929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please make sure that you have a Check Point Support Request for it. We would like to have our future versions more clear when policy installations fail, and I agree with you that this message isn't very clear.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Jan 2018 07:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22768#M929</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-01-14T07:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22769#M930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed! Something isn't right with your SMS. I never needed to install anything else for R80.10 to work with the 1400 appliances. Are you running the latest version R77.20.70 on them?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 11:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22769#M930</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-01-17T11:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22770#M931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did not have &lt;STRONG&gt;&lt;SPAN class=""&gt;CPSFWR77CMP-R80&lt;/SPAN&gt;&lt;/STRONG&gt; installed on my system. After installed this on my server it is working as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 11:58:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22770#M931</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-17T11:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22771#M932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of our customers&amp;nbsp;just had the same issue today - after inline CPUSE upgrade of SMS from R77.30 to R80.20 (including&amp;nbsp;&lt;SPAN style="font-size: 11.0pt;"&gt;R80 Upgrade Verification and Environment Simulation), policy install on SMB devices show the error: compatibility package is not properly installed. Strange that this rpm is not installed...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;And the real bad thing is that this error is only found in&amp;nbsp;sk37720 and this sk speaks of SPLAT only, but not of&amp;nbsp;CPSFRW77CMP-R80.(20 )&amp;nbsp;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/plain.png" /&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2019 13:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/22771#M932</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-15T13:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/55396#M2150</link>
      <description>&lt;P&gt;Same issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;upgraded manager to R80.20 H47 from r77.30 uing installer upgrade command t101 package&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Push policy to R77.20.75 1400 gateway error:&amp;nbsp;&lt;SPAN&gt;Compatibility package is not properly installed or configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ON manager:&amp;nbsp;&lt;/P&gt;&lt;P&gt;cd&amp;nbsp;/sysimg/CPwrapper/linux/CPsfwr77cmp&lt;/P&gt;&lt;P&gt;rpm -ivh&amp;nbsp; CPSFWR77CMP-R80.20-00.i386.rpm&lt;/P&gt;&lt;P&gt;cpstop;cpstart&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy push succeeds&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 01:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/55396#M2150</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-06-10T01:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73686#M2887</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot deploy new policies on our series 1400 too.&lt;/P&gt;&lt;P&gt;We updated our manager server to the latest 80.10 Hotfix (take 249).&lt;/P&gt;&lt;P&gt;Now I get the error on all my 1400 checkpoints:&lt;BR /&gt;cannot access /opt/CPSFWR77CMP-R80//CONF/lsm_cluster_subnet_override.xml: no such file or directory&lt;/P&gt;&lt;P&gt;I don't know why there are 2 // in the path.&lt;BR /&gt;&lt;BR /&gt;The folder /opt/CPSFWR77CMP-R80/ is present on our management server but not on 1400 devices.&lt;/P&gt;&lt;P&gt;Also /opt/CPSFWR77CMP-R80/conf is there (for sure with one /) but the file lsm_cluster_subnet_override.xml is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I tried to install the RPM package and I have the folder /sysimg/CPwrapper/linux/CPsfwr77cmp on my management, but the folder is empty.&lt;/P&gt;&lt;P&gt;What now?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73686#M2887</guid>
      <dc:creator>Lars_S_</dc:creator>
      <dc:date>2020-01-29T15:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73720#M2901</link>
      <description>Beat to engage with TAC on this issue.</description>
      <pubDate>Thu, 30 Jan 2020 04:28:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73720#M2901</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-30T04:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem to install policy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73750#M2906</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I managed it on my own with the help of&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14416"&gt;@Ryan_Ryan&lt;/a&gt;&amp;nbsp;post.&lt;/P&gt;&lt;P&gt;I am using R80.10 installation so I needed the package&amp;nbsp;&lt;SPAN&gt;CPSFWR77CMP-R80.00.i386.rpm&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I downloaded the iso file and mounted it on my management server.&lt;BR /&gt;Trying to install the file like with&amp;nbsp;rpm -ivh&amp;nbsp; CPSFWR77CMP-R80.00-00.i386.rpm I got "already installed".&lt;BR /&gt;So I forced the installation&lt;BR /&gt;rpm -ivh&amp;nbsp; CPSFWR77CMP-R80.20-00.i386.rpm --force&lt;BR /&gt;The package installed successful and now the policy installation on my 1400 checkpoints works again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 08:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Problem-to-install-policy/m-p/73750#M2906</guid>
      <dc:creator>Lars_S_</dc:creator>
      <dc:date>2020-01-30T08:55:15Z</dc:date>
    </item>
  </channel>
</rss>

