- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I have installed checkpoint R81.10 SMS for test purpose on Nutanix AHV. Now I can access the installed SMS server through SSH & Browser. But can not able to ping or login through smart console.
1) I think this is a layer 2 problem. Can you see the MAC address?
# arp -an | grep 10.1.75.76
2) If the IP address 10.1.75.76 is a firewall module, a default security policy is installed as long as you have not yet installed a access policy. This means that you cannot ping the fw but you can uninstall the firewall policy and then you can ping the firewall.
# fw unloadlocal
Hi,
If you have SSH you can launch tcpdump on SMS in order to see whether the ICMPs and SmartConsole traffic are arriving to the machine. In this way you can narrow down the problem.
Regards
@Franktum
I have captured any ping traffic using tcpdump on the Newly configured SMS Server. But the ping is not replying
Kindly, check the attached screenshot
1) I think this is a layer 2 problem. Can you see the MAC address?
# arp -an | grep 10.1.75.76
2) If the IP address 10.1.75.76 is a firewall module, a default security policy is installed as long as you have not yet installed a access policy. This means that you cannot ping the fw but you can uninstall the firewall policy and then you can ping the firewall.
# fw unloadlocal
Machines seem to be in the same network and I see arp request and reply in the capture.
Are we sure mgmt has been installed and not gateway? What does cpstat mg output show?
Maybe check with cpconfig -> check GUI clients and option 8
Very good point about running cpstat mg
@HeikoAnkenbrand
Thank you. It worked for me after executing the commands you have sent me.
Run fw stat. If it says anything other than "Local Host is not a Firewall Module", you accidentally configured it as a standalone SMS/firewall, and the firewall default InitialPolicy is blocking your ping and SmartConsole connectivity. If this is the case you will need to reload and answer correctly with only "Management Server" during the first-time wizard.
Definitely valid point.
Andy
@Timothy_Hall
The ping is working for me. But I can't able to login through Smart Console. Check the attached screenshot for fwstat
Our SMS in installed on nutanix AHV with .qcow2 file from checkpoint.
Which image / file from sk158292 did you use and which ftw selections were made?
You have accidentally configured it as a Security Gateway as well as Security Management Server (standalone) as I guessed earlier. You need to reload and make sure that Security Gateway is unchecked during the first-time wizard.
100% no doubt about it, you configured it as standalone (fw + mgmt as one machine)
If it was ONLY mgmt, it would show below.
Andy
[Expert@cpazuremgmt:0]# fw stat
Local host is not a FireWall-1 module
[Expert@cpazuremgmt:0]#
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
12 | |
11 | |
10 | |
9 | |
8 | |
7 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY