Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
biskit
Advisor
Jump to solution

There is no policy found

Hi all,

R77.30 Endpoint Management running on Windows (yes, I know...)

Everything was perfect just before Christmas.  But today I've logged in to add a newer Endpoint client and push it out (because of the 1st Jan issue). 

Today I have "There is no policy found" on a couple of my rules.  Most are populated correctly, but a couple show "no policy".  I'm also not sure why some actions are highlighted in bold as there have been no other changes made.  Maybe it's related to the other problem?

I've done sk128052 and it didn't work - no change.  I've seen sk137312 which says contact TAC for help.  Which obviously I can't do as it's R77.30.

Does anyone have any thoughts on how to fix this?  Obviously up against the clock a little with 1st Jan looming 🙄

Capture.PNG

 

 

Thanks,

Matt

0 Kudos
1 Solution

Accepted Solutions
Eyal_Magidish
Employee
Employee

No need to panic, older versions are not affected (epklib.sys doesn't exist).

If you want to fix FW policy, please open a service request to TAC so they will help you with the database corruption (best efforts).

View solution in original post

8 Replies
the_rock
Legend
Legend

Hi Matt,

Im definitely way more of a firewall guy that endpoint, but let me try my best to help you out. Yes, I know, R77.30, so totally understandable why you are apprehensive to contact TAC. By the way, please message me privately and we can certainly do remote session Thursday morning if you are free (Im EST time zone). So, looking at that error, Im 90% sure it has something to do with the corrupt files in $FWDIR/conf directory...Im assuming this is the same server managing your gateways as well? Not sure if you might have another R77.30 server that you can navigate to that directory and copy the whole content into the problematic one (after you back up all the files first, of course : ), because from what I recall, I had never seen an option in the endpoint server to do database revision control like you can in regular dashboard, but I will double check. Sadly, I dont have any R77.30 machines in my lab, as you cant even get the file on CP site any longer, since it has been unsupported for 1.5 years now.

0 Kudos
PhoneBoy
Admin
Admin

TAC will generally still help you on R77.30 on a best-effort basis. Don’t expect new hotfixes, of course.

0 Kudos
Eyal_Magidish
Employee
Employee

Hi,

It is a known issue with CPMI files corruption, see sk128052.

R77.30 is out of support, Our suggestion is to upgrade to R81.

See, https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowupgradewizard

 

BR,

Eyal

0 Kudos
the_rock
Legend
Legend

Eyal, if you read Matt's post carefully, he already tried sk you mentioned and it did not work and yes, he knows R77.30 is not supported, thats why he probably came here first : )

0 Kudos
biskit
Advisor

Haha, yes, exactly.

To throw another spanner in the works, the customer is running client E80.32.  The SK for the issue states clients E80.61 to E81.10 are affected.  What about client versions older than E80.61????  Apparently the epklib.sys file doesn't even exist on those clients.

With the server screwed, the only slight hope I've got is a standalone package to run locally.  But sk110420 says I can't go straight from E80.32 to E81.20.  There are 3 hops.  We're never going to get nearly 700 laptops done in time.  Really panicking at the moment.

0 Kudos
Eyal_Magidish
Employee
Employee

No need to panic, older versions are not affected (epklib.sys doesn't exist).

If you want to fix FW policy, please open a service request to TAC so they will help you with the database corruption (best efforts).

biskit
Advisor

Thanks.  We've done some testing, rolling the laptop date forwards and rebooting.  The old client still works and logs in to VPN.  Pheww!  

So old that even a legacy bug doesn't affect them.  They dodged a huge bullet.

the_rock
Legend
Legend

Awesome news Matt...well, as we discussed, I guess time for them to hopefully realize its time for upgrade, hehe. Happy New Year mate!!

 

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events