Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MINHYEOK2487
Explorer

Gaia WebUI becomes inaccessible when URL Filtering is enabled (SMS without internet access)

Environment:

  • Appliance: Quantum Security Gateway 9000 series
  • Version: (R82.0 / Take 39)
  • SMS: No external internet connectivity

Issue: When URL Filtering blade is enabled on a 9000-series gateway, the Gaia Web UI becomes completely inaccessible.

Suspected cause: I suspect this may be related to the URL Filtering categorization database update process. Since the SMS has no external internet access, the gateway may fail to reach the Check Point cloud for DB updates, and this failure might somehow block or interfere with Gaia WebUI access.

Questions:

  1. Is there a known dependency between URL Filtering DB fetch and Gaia WebUI availability?
  2. Is there a way to pre-download the URL Filtering DB offline, or disable the cloud lookup while keeping the blade active?

Any guidance or relevant SKs would be appreciated. Thank you.

0 Kudos
5 Replies
Martijn
MVP
MVP

Hi,

Can you tell us a little bit more about your setup? Which web GUI is inaccessible? Gateway or SMS?
Is this connection going through the gateway?

Please take a look at: 

sk92743 - ATRG: URL Filtering

The URL Filtering database is a online service the gateways connect to and get the correct category for a URL.
The result is cached for future lookups.

Unless you have a Private Threat Cloud appliance, to my knowledge there is no offline database.

What do you see in the logging?

Regards,
Martijn

0 Kudos
MINHYEOK2487
Explorer

Hi Martijn,

Thank you for your response.

  1. The Gaia WebUI on the gateway becomes inaccessible — not the SMS.
  2. Even when connecting through the UTP MGMT interface, the WebUI is still inaccessible.

Thank you.

0 Kudos
Martijn
MVP
MVP

Hi,

- Is there an access rule blocking web traffic to the gateway?
- Is SSH access possible?
- Is the web portal configured to listen on another port? You can check with show web ssl-port
- Is there by accident a NAT rule configured for the IP you are connecting to?
- Is your IP in the list of allowed hosts within the Gaia configuration? show allowed-clients all

Have you made a trace with tcpdump to see if traffic is coming in and is answered?

Unlikely URL Filtering is causing this issue. 

If all of the above is OK, I would follow the advice and open a case with TAC.

Martijn

the_rock
MVP Diamond
MVP Diamond

If you have any relevant logs you can attach, it would definitely help.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
PhoneBoy
Admin
Admin

URL Filtering is handled through cloud-based lookups and doesn't have an offline database to download.
No idea why it would cause issues with the Gaia WebUI; suggest opening a TAC case.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events