<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pushing Security Policy using autoconf.clish error in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86856#M3652</link>
    <description>&lt;P&gt;The policy is pushed when the autoconf.clish script runs. Nevertheless it creates a log file with this error message.&lt;/P&gt;&lt;P&gt;If I apply the configuration in clish I don't receive any error message.&lt;/P&gt;</description>
    <pubDate>Sun, 31 May 2020 10:22:11 GMT</pubDate>
    <dc:creator>Antonio_Martins</dc:creator>
    <dc:date>2020-05-31T10:22:11Z</dc:date>
    <item>
      <title>Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86420#M3636</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;Everytime I use autoconf.clish to load the policy I receive this kind of errors:&lt;/P&gt;&lt;P&gt;_________________________________________________________________________________&lt;/P&gt;&lt;P&gt;Installing Security Policy...&lt;/P&gt;&lt;P&gt;sfw_make_policy_id: Warning: returning a dummy policy ID.&lt;/P&gt;&lt;P&gt;[ 17610 1999798272]@GW000[21 May 17:44:16]&lt;/P&gt;&lt;P&gt;sfw_load: Error loading security policy&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Error loading policy.&lt;/P&gt;&lt;P&gt;sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/__tmp/FW1"'. rc=1, exit code =-1&lt;/P&gt;&lt;P&gt;Unable to install the Security Policy on the appliance&lt;/P&gt;&lt;P&gt;line 36: Autoconfiguration CLI script failed, clish return code = 1&lt;/P&gt;&lt;P&gt;_________________________________________________________________________________&lt;BR /&gt;Strangely the policy is fetched!&lt;/P&gt;&lt;P&gt;What can be wrong here?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 27 May 2020 00:44:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86420#M3636</guid>
      <dc:creator>Antonio_Martins</dc:creator>
      <dc:date>2020-05-27T00:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86754#M3650</link>
      <description>If you execute the precise command you've specified above in expert mode, does it work?</description>
      <pubDate>Fri, 29 May 2020 19:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86754#M3650</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-29T19:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86856#M3652</link>
      <description>&lt;P&gt;The policy is pushed when the autoconf.clish script runs. Nevertheless it creates a log file with this error message.&lt;/P&gt;&lt;P&gt;If I apply the configuration in clish I don't receive any error message.&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 10:22:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/86856#M3652</guid>
      <dc:creator>Antonio_Martins</dc:creator>
      <dc:date>2020-05-31T10:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87137#M3658</link>
      <description>&lt;P&gt;I have often used&amp;nbsp;autoconf.clish to configure IPs, Networks and WLAN, but these basic config never did push a security policy (as i did not define one in there). My questions:&lt;/P&gt;
&lt;P&gt;- in which state of the box&amp;nbsp;autoconf.clish is run (completely reset?)&lt;/P&gt;
&lt;P&gt;- is it locally or centrally managed ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 07:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87137#M3658</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-06-03T07:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87146#M3660</link>
      <description>&lt;P&gt;Yes, the gateway configuration was reverted to factory defaults before test.&lt;/P&gt;&lt;P&gt;The purpose is to automatically register it in Management Server (centrally managed).&lt;/P&gt;&lt;P&gt;I'm using this three commands at the end of the autoconf.clish:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set sic_init password &amp;lt;sic pass&amp;gt;&lt;BR /&gt;fetch certificate mgmt-ipv4-address &amp;lt;mgmt server ip&amp;gt; gateway-name &amp;lt;gateway name&amp;gt;&lt;BR /&gt;fetch policy mgmt-ipv4-address &amp;lt;mgmt server ip&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The script is working as the gateway is able to obtain the policy. I'm just curious about the error message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 08:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87146#M3660</guid>
      <dc:creator>Antonio_Martins</dc:creator>
      <dc:date>2020-06-03T08:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing Security Policy using autoconf.clish error</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87152#M3661</link>
      <description>&lt;P&gt;You are using clish commands, but these are calling others like:&lt;/P&gt;
&lt;TABLE class="tableintopic" border="0" width="636" cellspacing="0" cellpadding="2"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="221"&gt;
&lt;P class="tablebodytext"&gt;&lt;CODE class="monospace"&gt;fw fetch&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="415"&gt;
&lt;P class="tablebodytext"&gt;Fetch last policy&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="221"&gt;
&lt;P class="tablebodytext"&gt;&lt;CODE class="monospace"&gt;fw fetchdefault [-h]&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="415"&gt;
&lt;P class="tablebodytext"&gt;Fetch default policy&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="221"&gt;
&lt;P class="tablebodytext"&gt;&lt;CODE class="monospace"&gt;fw fetchlocal [-h]&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="415"&gt;
&lt;P class="tablebodytext"&gt;Fetch local policy&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Managed GWs, the GW will after reboot read both local policy and current policy from SMS; if they are the same, local copy will be installed, otherwise, fetched policy will be installed. Maybe when fetching policy from SMS, the unit found that the local policy is missing and issues an error - understandable after a reset to factory...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 08:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Pushing-Security-Policy-using-autoconf-clish-error/m-p/87152#M3661</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-06-03T08:42:33Z</dc:date>
    </item>
  </channel>
</rss>

