- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Generic Data Center Objects Not Updating in Sm...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Generic Data Center Objects Not Updating in SmartConsole (Despite Successful Enforcement)
Hi everyone,
We’re seeing an unexpected and concerning behavior with Generic Data Center Objects (GDCO) in SmartConsole. In short: when the GDCO JSON file is updated, SmartConsole does not reflect those changes, even though enforcement on gateways works perfectly.
Why this matters:
For firewall admins and operations teams, visibility is critical. SmartConsole becomes an unreliable source of truth — admins cannot see which IPs are actually part of a GDCO, nor which ones were added or removed. This creates a real risk of human error when managing policy.
What works (and works great!)
Using CloudGuard, Check Point correctly detects GDCO JSON changes and applies them to all gateways within the configured 60-second update window — no Publish or Install required (as expected). We also receive clear syslogs showing exactly which IPs changed. These logs are also visible in SmartConsole (blade:"CloudGuard").
This confirms:
- The GDCO JSON file is valid and properly formatted
- CloudGuard seems to be functioning correctly, recognizes changes to the GDCO file, logs the changes
- Enforcement on gateways is accurate and immediate (within the 60 second timer set for the GDCO)
This part is fantastic!!!!
The problem
Despite successful detection, logging, and enforcement:
- SmartConsole does not update the GDCO object
- Newly added or modified IPs do not appear in the GDCO object in SmartConsole
- Deleted/removed IPs still appear as if they’re active
- Nothing resolves the issue:
- stop/start of CMA, policy Publish, policy Install, re-configuring the GDCO on SmartConsole, re-importing the GDCO objects, even a reboot of CMA does _not_ correct the problem.
- The GDCO object _never updates again_, ever, despite multiple changes, uses, re-imports, none of these processes seems to resolve this issue.
So an admin opening the GDCO object in SmartConsole only sees the originally imported GDCO IPs — even when they’re no longer in policy. This is dangerous and misleading, as SmartConsole offers no visual way (other than logs) to validate the current GDCO state.
Versions tested (issue is consistent and repeatable)
- R81.20 build 057, Jumbo Hotfix Take 120 && SmartConsole 81.20.9700.674
- R82 build 010, Jumbo Hotfix Take 44 && SmartConsole 82.0.9800.1059
- NOTE: The SmartConsole behavior not updating GDCO objects was also observed on earlier hotfixes. So the lab was upgraded to the latest Jumbo Hotfixes, yet the issue persists.
SHOULD NOTE that Check Point seems to have acknowledged the issue (though it appears unresolved).
According to the R81.20 List of Resolved Issues for Jumbo HotFix Accumulator:
(From: https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20-List-of-all-Resolved-Issues.htm )
- Issue IDs:
- PRJ-61979
- PRHF-40203
- Product:
- CloudGuard Network
- Description:
- Changes made to the JSON file of a Generic Data Center object may take a long time to appear in SmartConsole or the Management API, although enforcement on the Security Gateway functions as expected.
To reiterate, even with fixes claimed in R81.20 JH Take 115, (we applied this and the latest JH, as noted above) SmartConsole still does not reflect GDCO updates.
Questions for the community / Check Point
- Is anyone else seeing this behavior?
- Are there any workarounds to force SmartConsole to refresh GDCO contents?
- Are there additional CloudGuard logs that explain why updates never reach SmartConsole?
- Or… am I missing something obvious?
Thanks SO MUCH in advance for any help, guidance, or insight on this — it’s a critical visibility issue for day-to-day firewall operations!!! 🙏
.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.
Eli
Check Point R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey PJ,
First, welcome to the community!
Excellent explanation, appreciated. Let me do some testing with this in my R82 lab and see the results. I will update you Saturday.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did some tests this morning...maybe someone else can confirm this, but I cant seem to find anywhere where it shows date when specific updatable object was update, though in smart console, they all show its dynamically updated, so maybe thats why. Let me see if there might be a file that would show that information.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just did some more testing...I see what you are saying, I have exact same issue.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.
Eli
Check Point R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Eli!
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Eliba thank you very much for this news. Also thanks @the_rock for validating the issue on your side.
Curious if there is a rough timeframe when this hotfix might be expected.
Also wondering why this thread was marked as "Resolved" when in-fact a patch is still being worked. Thanks again for your consideration.
pj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey PJ,
Usually people would mark an answer as solution in case like this where fix will be developed to correct the problem.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Solution refers to a (mostly) definitive answer to the original poster's question(s).
While this often is a workable solution, it also can refer to "not supported" and "known issue" type of answers.
Also note "Solutions" can be marked by anyone on the community, including the person who posted the post.
Admins will sometimes adjust these marks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Eliba hope all is well, just circling back to ask if there might be an SK number or Ticket number we can reference - not just to try to escalate via our rep, but also to provide our management some confidence that this is being addressed. If you happen to have any idea on a rough timeline for the release of a potential hotfix I'd also appreciate that. Thanks so much!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Paul_SecDevOps, please follow ticket TM-91614.
Eli
Check Point R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Eli,
Is that info available publicly?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That looks like a CFG task opened through TAC.
They're internal.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Makes sense.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Eli, hope you're well. Any idea by when TM-91614 might be addressed in a HF or other update? Thanks as always.
pj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey PJ,
I tested this in R82.10 and worked well, so must be fixed in newest version.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Andy! Would you mind sharing what full version you're testing, CP version and SmartConsole version if you dont mind. I'd like to test on the same if possible, Thanks and happy Sunday!!! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Happy Sunday 🙂
Here you go:
https://support.checkpoint.com/results/download/135254
https://support.checkpoint.com/results/download/140673
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Andy, sorry but those versions are not the ones being reported w/ the issue. We're running R81.20 and R82 firewalls, not R82.10 which is what your link/versions are pointing to. My original problem report is specifically for the two versions mentioned, not R82.10. Looking for a fix for R81.20 and R82 which does not yet look available - LMK if im misunderstanding, however. Thanks!!
pj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know exactly versions you mentioned : - )
What I said was that it worked for me in R82.10, thats all. In your case, maybe keep checking when fix will be ready.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Got it. Thanks and that's good to know! However too many firewalls on R81.20 and R82 showing this critical issue - and none of those will be upgraded anytime soon. Thanks for the useful observation/possible workaround, however!!!!! All the best!!! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Totally understood. I get the situation and no arguments there. I know R82.10 is brand new, so would be very difficult to get approvals to upgrade to that version, it may take some time until its officially recommended code.
Anywho, I hope fix for R82 and below will be ready soon.
Andy


