- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Dear Sir/Madam,
I tried to install policies and database and got this error message. "TCP connectivity failure ( port = 18191 )( IP = X.X.X.X )[ error no. 10 ] Policy installation canceled."
This is a standalone setup with gaia r77.30 Matthew DoUri BialikKyle ReynoldsAvigdor SharonIgal NahimovskiOfir AgasiKyle ReynoldsBob BentKristen Kenedy
Please assist with what I could do.
Kind regards,
kul@
If you have the ability to connect to the console of your standalone gateway, check if the CPD is running.
If not, lookup one of the posts describing how to troubleshoot it on the platform and the version you are running.
I checked cpd,ita running fine o
If it is a non-production environment, or if you have a maintenance window, try fw unloadlocal and reinstall the policy.
Any chance something changed in your policy that will block your communication with the unit if it is successfully installed?
Okay will do that the device is under production. is it possible to back up policies before I do fw unloadlocal ??
And also one more question, if I do freshinstallatiion is it possible to back up policies, Nat, route and interfaces. So that after fresh installation I can just load the Config files.
You can backup the current state of the unit in WebUI as well as perform a snapshot there.
You can perform migrate export to get the objects and rulebase in a portable format.
You can separately backup Gaia config in CLI.
Good idea to download backups and snapshots of the unit.
The problem is that if the unit is failing to install the current policy, restoring it to the same state may not fix your issues.
Why not try TAC SR? It may be something simple they will be able to spot and fix in a short remote session.
I tried to get support from TAC,they asked me to do fresh installation. I assume there is a possible way to rectify the issue.
They said the issue is change of IP of the device IP,which got the database ti be corrupted.
Sometimes TAC people make mistake as well so I am here getting possible help from you guys.
Thank you very much for getting on with this discussion.
Did you change the IP of the device at all?
Is the IP in the error message what you expect it to be?
fw unloadlocal does not change the policy configuration, it merely unloads it from the firewall kernel.
I haven't Changed the ip.
If you opened a TAC case, please send me the SR# privately.
They said I need to do fresh installation.
Any idea can I copy objects, route, policies from current configuration so it gets easier for me when I do fresh installation.
Please send me the SR number privately so I can review the basis for this recommendation.
As far as migrating the security policy configuration, if there is corruption, it might be best to use cp_merge to export/import the configuration (assuming you want to stay on R77.30): Using cp_merge utility
The OS-specific settings can be exported/imported as described here: Export / Import configuration / partial configuration in Gaia
Sure will do, thanks alot
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
12 | |
11 | |
11 | |
7 | |
6 | |
5 | |
5 | |
5 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY