- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
An admin was trying to update a VPN ipsec certificate on the MDS for a specific fw domain.
It was interrupted due to network issues..
I can see the lock sign on it and the user who has the session cannot do anything.
MDS R82
Now the following has happened :
1. We cannot take over the session of the user or terminate the session.
2. We cannot edit anything regarding that specific Fw domain.
3. We tried to do mds stop and mds start, then we did a hardware reboot of the MDS, Mds stop/start of that specific fw.
Nothing is helping.
Take over does not work.
Discard changes dont work either.
Any ideas how we can terminate the user and get it back to normal ?
Have you tried locating the Session and Discarding it using mgmt_cli?
There are several SKs on the issue but in most cases they suggest contacting TAC:
https://support.checkpoint.com/results/sk/sk167354
https://support.checkpoint.com/results/sk/sk133872
Thanks asked the engineer to try them now.
The page does not seem to show anything ?
Both of them besides mentioning the SK numbers.
How to know what do in the CLI ?
To view SKs you need to be logged in with your Product Center (User Center) / Support username
For CLI refer to:
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-sessions~v2.0.1%20
There are other relevant topics before and after this one
Without having a look at the SK articles i would do following using mgmt_cli
Having a look at the user's sessions and some info.
(echo "UID STATE MODE LOCKS CHANGES"; mgmt_cli -r true show sessions details-level full -f json | jq -r '.objects[] | select(.["user-name"] == "usename") | "\(.uid) \(.state) \(.["connection-mode"]) \((.locks|length)) \((.changes|length))"') | column -t
to delete all sessions of a user
mgmt_cli -r true show sessions details-level full -f json | jq -r '.objects[] | select(.["user-name"] == "username") | .uid' | xargs -I {} mgmt_cli -r true disconnect uid "{}"
But since the GUI does nothing other than make such API calls, I doubt that it will work for you.
You need valid support account to view those SKs.
See if this helps.
Hi, it did not work. It kicked out all of the connected users but not the one we wanted to disconnect.
Did you try cpstop and cpstart ?
cpstop ; cpstart
If yes, this is the point where i would recommend logging a sr at uc.
Since you said even reboot failed to solve this, definitely open TAC case.
Is it possible to install vpn certificate on the fw domain through CLI or is it locked to the same user in CLI as well ?
My logical assumption would be its most likely locked as well.
No, because the underlying session is still locked.
The session must be published or discarded.
If you cannot do this through the standard mechanisms, then you will need TAC to assist you in removing it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY