Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Martijn
MVP Platinum
MVP Platinum

Check Point services check in Insights

Hi all,

On Maestro, Insights has some basic checks like:

- NTP server reachable
- Management server reachable
- Log server reachable
- Gateway reachable

These checks are done by PING (echo-request).

There are also checks for the Check Point services. Does anyone knows how these checks are performed?

The reason I ask this is, is the following: We have a customer with a Private Threat Cloud appliance for CPUSE and blades updates. This works fine and gateways can download software and updates for IPS, AV and AB.

But Insights on Maestro reports the Check Point services as 'Down'. The Maestro set can resolve the hostnames like updates.checkpoint.com, etc. When installing a PTC appliance, the hostfile is altered to point to the IP of the PTC appliance.
Also the ca-bundle.crt in $CPDIR/conf and $FWDIR/bin is configured with the certificate of the PTC appliance.
We can check this by:

curl_cli -v https://updates.checkpoint.com --cacert $CPDIR/conf/ca-bundle.crt

So I would like to know if the check in Insights uses something else? What checks are performed to check the Check Point services websites?

All is working fine and there are no issues with updates etc. But with ten Check Point hosts that are checked and four SGM, we have 40 issues showing in Insights. 

Has anyone the answer?

Regards,
Martijn 

1 Reply
JaAnd
Contributor

My suggestion would be to label Insights with a "work in progress" badge.

​It is a very promising tool - connview is a masterpiece, but it still needs a lot of work.

​For example, troubleshooting tools are available (such as a pretty advanced packet capture and analysis tool), but there is no mention of them in the online manuals.

0 Kudos