- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters Series 2026
WATCH NOWHi all,
On Maestro, Insights has some basic checks like:
- NTP server reachable
- Management server reachable
- Log server reachable
- Gateway reachable
These checks are done by PING (echo-request).
There are also checks for the Check Point services. Does anyone knows how these checks are performed?
The reason I ask this is, is the following: We have a customer with a Private Threat Cloud appliance for CPUSE and blades updates. This works fine and gateways can download software and updates for IPS, AV and AB.
But Insights on Maestro reports the Check Point services as 'Down'. The Maestro set can resolve the hostnames like updates.checkpoint.com, etc. When installing a PTC appliance, the hostfile is altered to point to the IP of the PTC appliance.
Also the ca-bundle.crt in $CPDIR/conf and $FWDIR/bin is configured with the certificate of the PTC appliance.
We can check this by:
curl_cli -v https://updates.checkpoint.com --cacert $CPDIR/conf/ca-bundle.crt
So I would like to know if the check in Insights uses something else? What checks are performed to check the Check Point services websites?
All is working fine and there are no issues with updates etc. But with ten Check Point hosts that are checked and four SGM, we have 40 issues showing in Insights.
Has anyone the answer?
Regards,
Martijn
My suggestion would be to label Insights with a "work in progress" badge.
It is a very promising tool - connview is a masterpiece, but it still needs a lot of work.
For example, troubleshooting tools are available (such as a pretty advanced packet capture and analysis tool), but there is no mention of them in the online manuals.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY