- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello everyone,
I've just added Appliance 1900 R81.10.15 to a virtual Management Server R81.20 via Internet.
The Status of the Connection is ✅Connected
The Status in Management Console "➖" and I can't install any policies: Installation Policy Error 0-2000259.
Unfortunately I didn't find any Information about this Error.
Very appreciate any help!
Thats expected, since its mgmt cli command.
Andy
and what should I do? I have other firewalls that were configured before me and there is no such problem there.
When I try to fetch the policy in the CLI, it really tries to fetch it from the local IP address. So, somehow I need to tell FW to fetch from Public IP. I didn't find any keys for "fw fetch" to specify a remote server...
fw fetch
Fetching Security Policy from '10.10.XXX.XXX'
Reason: TCP connectivity failure ( port = 18191 )( IP = 10.10.XXX.XXX )[ error no. 10 ].
Security Policy Fetch Failed.
Unable to fetch the Security Policy from the Management Server
Warning: Attemped to fetch policy from an IP address that is different than the one used to fetch the certificate. Please check the management object's IP address in the SmartDashboard.
This points to a connectivity issue.
Confirm you can open a TCP connection on port 18191 (netcat "nc" can be used for this) from the gateway to the management.
Also, what is the relation between the IP listed in the error message versus the one listed in the Main tab of the Management object?
Yes, port is open. Do you see the destination IP?
Personally, ever since I been around CP back from R55 days, I had NEVER seen that error not be related to SIC issue. Now, here is the thing. Say you do SIC reset and it works and then you try push policy and it fails, its usually route missing somewhere along the lines, if you will.
Hope that helps.
Andy
Sure it is routing problem, because the security server in Internet tries to connect to another server in Internet via private IP... why?
Maybe verify NATing, as well as current routes. For example, do ip r g command to "affected" ip address. Something like ip r g 8.8.8.8, just change the IP address, to confirm if its correct.
Andy
check this one out:
How to configure Management behind NAT in Security Gateway - special for SPARK
https://support.checkpoint.com/results/sk/sk66381
thank you! it did help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY