Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Paul_SecDevOps
Participant
Jump to solution

Generic Data Center Objects Not Updating in SmartConsole (Despite Successful Enforcement)

Hi everyone,
We’re seeing an unexpected and concerning behavior with Generic Data Center Objects (GDCO) in SmartConsole. In short: when the GDCO JSON file is updated, SmartConsole does not reflect those changes, even though enforcement on gateways works perfectly.

Why this matters:

For firewall admins and operations teams, visibility is critical. SmartConsole becomes an unreliable source of truth — admins cannot see which IPs are actually part of a GDCO, nor which ones were added or removed. This creates a real risk of human error when managing policy.

What works (and works great!)

Using CloudGuard, Check Point correctly detects GDCO JSON changes and applies them to all gateways within the configured 60-second update window — no Publish or Install required (as expected).   We also receive clear syslogs showing exactly which IPs changed. These logs are also visible in SmartConsole (blade:"CloudGuard").


This confirms:

  • The GDCO JSON file is valid and properly formatted
  • CloudGuard seems to be functioning correctly, recognizes changes to the GDCO file, logs the changes
  • Enforcement on gateways is accurate and immediate (within the 60 second timer set for the GDCO)

This part is fantastic!!!!

The problem

Despite successful detection, logging, and enforcement:

  • SmartConsole does not update the GDCO object
  • Newly added or modified IPs do not appear in the GDCO object in SmartConsole
  • Deleted/removed IPs still appear as if they’re active
  • Nothing resolves the issue:
    • stop/start of CMA, policy Publish, policy Install, re-configuring the GDCO on SmartConsole, re-importing the GDCO objects, even a reboot of CMA does _not_ correct the problem. 
    • The GDCO object _never updates again_, ever, despite multiple changes, uses, re-imports, none of these processes seems to resolve this issue.

So an admin opening the GDCO object in SmartConsole only sees the originally imported GDCO IPs — even when they’re no longer in policy. This is dangerous and misleading, as SmartConsole offers no visual way (other than logs) to validate the current GDCO state.    

Versions tested (issue is consistent and repeatable)

  • R81.20 build 057, Jumbo Hotfix Take 120   &&  SmartConsole 81.20.9700.674
  • R82 build 010, Jumbo Hotfix Take 44  &&  SmartConsole 82.0.9800.1059
  • NOTE:  The SmartConsole behavior not updating GDCO objects was also observed on earlier hotfixes.  So the lab was upgraded to the latest Jumbo Hotfixes, yet the issue persists.
SHOULD NOTE that Check Point seems to have acknowledged the issue  (though it appears unresolved).   
According to the R81.20 List of Resolved Issues for Jumbo HotFix Accumulator:
          (From: https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20-List-of-all-Resolved-Issues.htm )
  • Issue IDs:  
    • PRJ-61979
    • PRHF-40203
  • Product:
    • CloudGuard Network
  • Description:
    • Changes made to the JSON file of a Generic Data Center object may take a long time to appear in SmartConsole or the Management API, although enforcement on the Security Gateway functions as expected.

To reiterate, even with fixes claimed in R81.20 JH Take 115, (we applied this and the latest JH, as noted above) SmartConsole still does not reflect GDCO updates.

Questions for the community / Check Point

  • Is anyone else seeing this behavior?
  • Are there any workarounds to force SmartConsole to refresh GDCO contents?
  • Are there additional CloudGuard logs that explain why updates never reach SmartConsole?
  • Or… am I missing something obvious?


Thanks SO MUCH  in advance for any help, guidance, or insight on this — it’s a critical visibility issue for day-to-day firewall operations!!!   🙏

 

.

 

pj
0 Kudos
1 Solution

Accepted Solutions
Eliba
Employee
Employee

Hi @the_rock,@Paul_SecDevOps,

We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.

Eli
Check Point R&D

View solution in original post

21 Replies
the_rock
MVP Diamond
MVP Diamond

Hey PJ,

First, welcome to the community!

Excellent explanation, appreciated. Let me do some testing with this in my R82 lab and see the results. I will update you Saturday.

Best,
Andy
0 Kudos
the_rock
MVP Diamond
MVP Diamond

@Paul_SecDevOps 

Did some tests this morning...maybe someone else can confirm this, but I cant seem to find anywhere where it shows date when specific updatable object was update, though in smart console, they all show its dynamically updated, so maybe thats why. Let me see if there might be a file that would show that information.

Best,
Andy
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Just did some more testing...I see what you are saying, I have exact same issue.

Best,
Andy
Eliba
Employee
Employee

Hi @the_rock,@Paul_SecDevOps,

We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.

Eli
Check Point R&D

the_rock
MVP Diamond
MVP Diamond

Thanks Eli!

Best,
Andy
0 Kudos
Paul_SecDevOps
Participant

Hi @Eliba thank you very much for this news.   Also thanks @the_rock for validating the issue on your side.

  Curious if there is a rough timeframe when this hotfix might be expected.   

Also wondering why this thread was marked as "Resolved" when in-fact a patch is still being worked.  Thanks again for your consideration. 

pj

pj
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey PJ,

Usually people would mark an answer as solution in case like this where fix will be developed to correct the problem.

Best,
Andy
PhoneBoy
Admin
Admin

Solution refers to a (mostly) definitive answer to the original poster's question(s).
While this often is a workable solution, it also can refer to "not supported" and "known issue" type of answers.

Also note "Solutions" can be marked by anyone on the community, including the person who posted the post.
Admins will sometimes adjust these marks. 

 

0 Kudos
Paul_SecDevOps
Participant

Hi @Eliba hope all is well, just circling back to ask if there might be an SK number or Ticket number we can reference  - not just to try to escalate via our rep, but also to provide our management some confidence that this is being addressed.    If you happen to have any idea on a rough timeline for the release of a potential hotfix I'd also appreciate that.  Thanks so much! 

pj
0 Kudos
Eliba
Employee
Employee

Hi @Paul_SecDevOps, please follow ticket TM-91614.

Eli
Check Point R&D

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey Eli,

Is that info available publicly?

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

That looks like a CFG task opened through TAC.
They're internal.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Makes sense.

Best,
Andy
0 Kudos
Paul_SecDevOps
Participant

Hi Eli, hope you're well.  Any idea by when TM-91614 might be addressed in a HF or other update?  Thanks as always.

pj

pj
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey PJ,

I tested this in R82.10 and worked well, so must be fixed in newest version. 

Best,
Andy
0 Kudos
Paul_SecDevOps
Participant

Hi Andy!  Would you mind sharing what full version you're testing, CP version and SmartConsole version if you dont mind.  I'd like to test on the same if possible,  Thanks and happy Sunday!!! 🙂

pj
0 Kudos
the_rock
MVP Diamond
MVP Diamond
0 Kudos
Paul_SecDevOps
Participant

Hi Andy, sorry but those versions are not the ones being reported w/ the issue.  We're running R81.20  and R82  firewalls, not R82.10 which is what your link/versions are pointing to. My original problem report is specifically for the two versions mentioned, not R82.10.  Looking for a fix for R81.20 and R82 which does not yet look available  - LMK if im misunderstanding, however.  Thanks!!

pj

pj
0 Kudos
the_rock
MVP Diamond
MVP Diamond

I know exactly versions you mentioned : - )

What I said was that it worked for me in R82.10, thats all. In your case, maybe keep checking when fix will be ready.

Best,
Andy
0 Kudos
Paul_SecDevOps
Participant

Got it.  Thanks and that's good to know!  However too many firewalls on R81.20 and R82 showing this critical issue - and none of those will be upgraded anytime soon.  Thanks for the useful observation/possible workaround, however!!!!!  All the best!!! 🙂

pj
the_rock
MVP Diamond
MVP Diamond

Totally understood. I get the situation and no arguments there. I know R82.10 is brand new, so would be very difficult to get approvals to upgrade to that version, it may take some time until its officially recommended code.

Anywho, I hope fix for R82 and below will be ready soon.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.