Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
denbug
Participant

VPND is terminated

Hi CheckMates,

I'm facing an issue after patching my firewalls with JHF Take 141 (R81.20). Most of the firewalls upgraded successfully and are working, but 4 firewalls ran into an issue.

On 2 of the firewalls we were not able to access them through SSH, and when connecting via console, we noticed they were stuck in a bootloop. We raised a support case, where we were asked to factory reset the firewalls.

On the other 2 firewalls, we see that vpnd is terminated and we are unable to get it running again. We have tried cpstop/cpstart, and also manually tried to restart vpnd using the following commands:

cpwd_admin stop -name vpnd -path "$FWDIR/bin/vpnd" -command "vpnd"
cpwd_admin start -name vpnd -path "$FWDIR/bin/vpnd" -command "vpnd"

But nothing happens - and when trying again, we get an error saying the process vpnd fails to start.

Following a recommendation from Check Point, we also upgraded the 2 affected firewalls to R82 Take 103, but the issue persists and vpnd is still not starting.

Has anyone experienced these issues after applying Take 141 - or seen vpnd fail to start after upgrading to R82? Any suggestions on how to get vpnd running again would be much appreciated.

0 Kudos
2 Replies
denbug
Participant

add on information, the file we have seen an issue with in all 4 firewalls is libcptls.so - but i'm unsure whether this file has caused issues for the vpnd process.

0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

When a daemon fails to start or crashes constantly, the first thing is to check its log file to see if it barfed some kind of helpful error message before dying: $FWDIR/log/vpnd.elg.  fwd is the parent process for vpnd and will attempt to automatically respawn it, so also check $FWDIR/log/fwd.elg for any related error messages.

Next step is to start the vpnd daemon manually under debug and see what kind of errors happen: 

export VPND_DEBUG=1

export TDERROR_ALL_ALL=5

vpnd

unset VPND_DEBUG

unset TDERROR_ALL_ALL

Depending on how far the daemon got when trying to start, you'll either see the debugging output on your terminal, or you may need to check $FWDIR/log/vpnd.elg.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events