- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
I am running R82 in my Check Point Firewall. I want to download hotfix via CPuse, but then this warning prompts at the top of webui and the "Check for Updates" is not working, I am sure that my gateway has internet connection, but my gateway can't resolve ping using domain like ping yahoo.com, I also can't ping the checkpoint.com. But I can ping to 8.8.8.8. Has anyone experienced the same issue?
Hello,
I have the same problem with updates via CPUSE.
I planned to upgrade from R81.20 take 113 to R82 take 60 today.
I got the error mentioned in this post. There are no problems with DNS.
The log /opt/CPInstLog/DeploymentAgent.log shows that the problems started on 01/03/2026.
I think this problem is somehow related to sk184766/
I have the same issue on R81.20 and have a ticket open with TAC.
R&D have responded there is a new Deployment Agent due to at the weekend for this issue.
There has been no mention thus far this is anything to do with the R82 CRL issue.
hi,
Havent applied any hotfix reg this and today everything is working as attended. No issues with CPuse either.
CP service health degradation in middle east maybe did an impact.
Hi,
I'm glad for you. Could you check if Deployment Agent [DA] has been updated at this time?
As sk92449 wrote yesterday, a new version 2742 has been released.
I still have the problem.
i have Deployment Agent version: Build 2672
Latest recommended. There is no newer version release or recommended.
sk92449 - Check Point Upgrade Service Engine (CPUSE) - Gaia Deployment Agent
I applied the appropriate HF to all our CP Devices. All our 3920's now show the: Failed to receive updates from Check Point Download Center. Please verify a valid license is configured as well as Proxy, DNS and routing.
Connection Error, FDT - Unexpected error code.
Current DA is 2672. I see SK92440 lists the 2742 but provides no link to manually download to apply. So how is DA going to update if the CP devices are showing this error about not being able to connect to CP Cloud download site? I ran the curl _cli command which still report the cert validation error:
ERR_lib_error_string: SSL routines
ERR_func_error_string: tls_process_server_certificate
ERR_reason_error_string: certificate verify failed
ERR_error_string: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed
* SSL certificate problem: unable to get local issuer certificate
Does this also mean that the other updates from their cloud (IPS, AV, Dynamic Obj etc) are not getting updates????
I entered TAC case this to get official answer
I have the same problem with SMS when I try to update the firmware from R82 T39 to Take 60. Although it can resolve checkpoint.com and other addresses, the gateways in the same places with the same DNS configurations and internet connection can access and download updates without any problems.
I also had update alarms in many different places. The gateways could not reach the update servers to update the blades' engines, such as threat prevention and antivirus and so on. This issue has been resolved, but CPUSE still persists.
Hello, my problem in my gateway has been resolved, but what I did is upgrade to JHF T60 and CRL fix, I am not sure if the fix resolved the issue though it does not resolve immediately after the fix has been installed. You may try install the fix sk184766 - Certificate and CRL validation fails from March 1, 2026 I think your issue with the blades has something to do with it.
My Corp GWs are 9200's, Management and SmartEvent servers are virtual -- all are R82 JHF 73 with Check_Point_R82_JHF_T73_TIME_FIX_MAIN_MAIN_Bundle_T2_FULL. The DA on them are 2672. None show the error. Our 3920's are at remote sites running R82.10 464 - which were upgraded from GA1 (272). They all have Check_Point_R82_10_ga_time_fix_main_Bundle_aarch64_T9_FULL.tgz applied which passed verification. They all are DA 2672 as well but the 3920's now report the error.
I read in this thread that originally, if the 3900 was an upgrade from GA1 to GA2, you needed to do a fresh install. That just was not a viable option. So waited for this HF to be released that was targeted for GA1 - GA2 upgraded devices. CP TAC should be able to provide an insight. I'll update this thread when they provide the answer
Were you able to recieve an answer ? we have the exact same problem.
The new DA agent was supposed to be ready this weekend. But when I looked, it was still not available. TAC confirmed "... The DA looks as if it is not quite finished as of yet. "
I opened an SR and they provided the new 2742 DA in the SR. I applied it and the CPUSE issue is now fixed. The DA is version-specific (they told me mine would only work for R82) so get it from support.
I'm experiencing the same issue on R82. Despite having Take 60 + CRL hotfix installed, "Check Update' still fails in Gaia." I'm getting the same error as before the fix: "Connection Error, FDT - Unexpected error code"
I have had a TAC case open. All our remote 3920's R82.10 GA2 (bld 464) that were upgrades from GA1 (272) have the same message, TAC reply today below. Apparently will not provide the DA upgrade directly:
The CRL hotfix did not cause the issue. The Hotfix prevented the Gateways and Management server from potential outages because of the CRL issue. The CRL issue also effected the Deployment Agent as well.
We do not like to apply updates without proper testing, as a result, we decided on rolling out the updates to the DA. I apologize for the inconvenience this may have caused.
The issue has been resolved in the new released deployment agent 2742. It is now available for download. I updated the deployment agent to 2742, and the issues does not appear again. I can also now check for update, and it is now connecting to the checkpoint cloud.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY