Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gaurav_Pandya
Advisor

Firewall database corruption. Getting error 0-2000030 while installing policy

I had database corruption issue and got below error while installing policy.

Data corruption.png

I followed the procedure below to resolve the issue and thought of sharing it here so that it may be helpful to others as well.

Procedure: Clearing State and Database
On the Cluster Members
•cpstop both members
•cd to /var/log/, and create a directory called statebackup (mkdir statebackup)
•cd to $FWDIR/state and copy with "cp -R $FWDIR/state/* /var/statebackup/"
•Verify that the backup is there
•Go back to $FWDIR/state and issue command "rm -R $FWDIR/state/*"
•This deletes the contents of the state directory but not the directory itself
•Follow the same steps with each cluster member

On the SmartCenter Server
•cpstop SmartCenter
•cd to /var/log/, and create a directory called statebackup (mkdir statebackup)
•cd to $FWDIR/state/<name of firewall>/ and copy with "cp -R * /var/log/statebackup/"
•Verify that the backup is there
•Go back to $FWDIR/state and issue command "rm -R $FWDIR/state/*"
•This deletes the contents of the state directory but not the directory itself
•Follow the same steps with the database directory, $FWDIR/database/
•cpstart the SmartCenter Server first
•cpstart both members (they will come back with a message such as unable to fetch security policy)
•Issue "fw unloadlocal" on both members from the command line
•Install policy from the SmartCenter

You can refer sk33328 for more details

0 Kudos
4 Replies
the_rock
MVP Diamond
MVP Diamond

Hey Gaurav,

Seems like you had done lots of right steps already. Just curious, do you have working database revision you can try reverting to?

Best,
Andy
0 Kudos
Gaurav_Pandya
Advisor

Hi Andy,

It might be worth trying, but since everything is up and running now, I’d prefer not to risk disrupting anything.
0 Kudos
the_rock
MVP Diamond
MVP Diamond

K, perfect, then those steps are super helpful in case anyone else runs into the same issue. EXCELLENT work @Gaurav_Pandya 

Best,
Andy
Martijn
Advisor
Advisor

Hi,

Did you check sk154435? The code is mentioned there. Cause: Some policy files are corrupted on the Security Gateway / Cluster Member.

sk154435 - "Policy installation failed on gateway. If the problem persists contact Check Point suppo...

1. Connect to the command line on the Security Gateway / problematic Cluster Member.

2. Log in to the Expert mode.

3. Copy the temporary policy files to the relevant directory:

5. cp -v $FWDIR/state/__tmp/AMW/* $FWDIR/state/local/AMW/

6. In SmartConsole, install the policy.

Martijn





0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events