Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ma_gorkhali
Contributor
Jump to solution

License update

We have recently renewed our license from NGTP to NGFW for some of our maestro, cloud-based firewall as well as for some of our legacy based appliance. Synchronize with Check Point UserCenter is enabled but it is still not updating the gateways and displaying as license about to expire. I believe this should automatically renew if connected to the usercenter ?

0 Kudos
1 Solution

Accepted Solutions
ma_gorkhali
Contributor

Hello @the_rock  I have some update.

First thing is there is a bug with the problematic Maestro sk180364 - Gateway cluster member prematurely expires half-closed TCP connections when SecureXL is e.... This was the main reason why we were not able to download the contracts automatically. The other 2 Maestro clusters were in the latest hotfix due to which it automatically downloaded those contracts as well as license.

I did a offline license/contract installation for the problematic Maestro. We followed this SK inorder to solve the issue sk163323 - Solutions for license issues on Maestro Security Appliances.

I will patch the Maestro next year.

Thank you for your help you are amazing.

View solution in original post

31 Replies
_Val_
Admin
Admin

Can you show the message, and also features you updated? 

0 Kudos
ma_gorkhali
Contributor

Hello @_Val_  the strange thing is 2 of our maestro cluster is updated but  one of the maestro cluster has not updated yet. I can see in the usercenter that the expiry date for the blade has increased. It was renewed 24hrs ago and is it something that takes time ?

0 Kudos
Lesley
Leader Leader
Leader

Maybe try to receive licenses from usercenter in smartupdate? If there all is good push the policy. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
ma_gorkhali
Contributor

Hi @Lesley  Do you mean click on 'get all license' under Licenses and Contracts  on the SmartUpdate and then install the policy ?

0 Kudos
Lesley
Leader Leader
Leader

Something like get all licenses and contracts from userscenter and use there usercenter login where the firewalls are placed in. Have no access to pc now so cannot share screenshot

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
ma_gorkhali
Contributor

This should be the one I suspect ? 

 

license-issue.png

 

 

the_rock
Legend
Legend

Yep, thats it!

0 Kudos
the_rock
Legend
Legend

I would try what @Lesley suggested.

Andy

0 Kudos
_Val_
Admin
Admin

It might be that one of the security groups does not have Internet connectivity and cannot update contracts and licenses automatically. If this is the case, look into https://support.checkpoint.com/results/sk/sk163323

Also, try pushing the licenses and contracts from SmartUpdate, as already suggested. 

If neither works, please open a TAC case

0 Kudos
ma_gorkhali
Contributor

Thank you for your reply.

Smart update is currently not able to communicate with usercenter although do have internet access from the SMS itself.user-center.png

 

 

Adding to this SMO does have internet connection and can connect to checkpoint sites

0 Kudos
the_rock
Legend
Legend

Can you send below output from expert mode of sms?

curl_cli -k www.google.com

Andy

0 Kudos
ma_gorkhali
Contributor

Here you go

From SMO

curl-google-cli.png

 

FROM SMS

 

sms.png

 

0 Kudos
the_rock
Legend
Legend

So it does have Internet access, but, is PC where smart console installed able to get to the Internet?

Andy

0 Kudos
ma_gorkhali
Contributor

Not the PC doesn't have internet? Is that the reason why I am not being able to fetch the contract using smartupdate ? 

0 Kudos
the_rock
Legend
Legend

Im fairly sure that is why.

0 Kudos
ma_gorkhali
Contributor

Let me try connecting to smartconsole from the PC where there is internet

(1)
the_rock
Legend
Legend

I feel confident that will work.

0 Kudos
ma_gorkhali
Contributor

Hello, 

 

I installed smartconsole in my PC where there is internet connectivity and still could not fetch the contract

It does ask for a credential and my user is a superuser for accessing usercenter or do you we need a admin@domain.com account to pull it through or should the superuser be more than enough ? 

0 Kudos
_Val_
Admin
Admin

Please refer to https://support.checkpoint.com/results/sk/sk11054 about offline license update.

0 Kudos
the_rock
Legend
Legend

So when you try from PC that has Internet access and enter yoour UC info, does it give same error? Because when I test in the lab, works 100% of the time.

Andy

0 Kudos
ma_gorkhali
Contributor

Yes, same error exactly the same. I am bit confused what is the issue as the license got updated in most of the firewall in total of 100 plus firewall except for one of the maestro cluster and the SMO for that cluster does have internet connectivity as well. All of those that got updated were automatically updated.

0 Kudos
the_rock
Legend
Legend

Im with you there, that is a bit puzzling, agree.

Andy

0 Kudos
ma_gorkhali
Contributor

Adding to this I have a different maestro cluster managed by different SMS. Maestro in DEV environment got updated automatically as well but when I try to fetch the contract from the user center I am getting the same error in DEV environment as well

0 Kudos
ma_gorkhali
Contributor

@the_rock @_Val_  @Lesley  Does maestro gateway play any role in fetching out the license. As maestro is more of a local license should the gateway directly be talking with the internet ? 

 

Looks like the problematic maestro where license was not updating had some connection issue although I was able to curl in the sites . I could see some drop return packets from my proxy so I have forwarded my traffic to another proxy where no drop is been seen right now.

 

How long does it take for the license to get automatically updated from the usercenter ?

0 Kudos
the_rock
Legend
Legend

I believe what you were trying to do is technically fetched from the smart console itself, thats why I mentioned last night to try from PC with the Internet access, but you said that did not work either.

Andy

0 Kudos
ma_gorkhali
Contributor

Hello @the_rock yeah it did not that's right

0 Kudos
ma_gorkhali
Contributor

I have raised a case hopefully he solves it and then will post

the_rock
Legend
Legend

Keep us posted.

Andy

0 Kudos
the_rock
Legend
Legend

I understand. Let me do some tests in the lab later on this.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events