- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi,
Is there someone that can help me with this problem? One of our gateways (R77.20) is having an issue with cpd.
When I checked the cpwd_admin list, it is showing that CPD is in T status. I already stopped/start and rebooted the gateway but still no luck.
cpstat showed that we can't established session with AMON and TCP ports 18192 and 18191 aren't listening.
[Expert@NGA-COM01-FWL01:0]# cpwd_admin list
APP PID STAT #START START_TIME MON COMMAND
CPD 0 T 6 [15:04:27] 3/10/2019 N cpd
[Expert@NGA-COM01-FWL01:0]# cpstat os
Failed to establish session with AMON server at 127.0.0.1:18192
[Expert@NGA-COM01-FWL01:0]# netstat -an | grep 18192
[Expert@NGA-COM01-FWL01:0]# netstat -an | grep 18191
Regards,
J
cpwd should attempt to restart cpd every 60 seconds, what type of error messages are being written into $CPDIR/log/cpd.elg?
If the cpd process is dead, SIC to that gateway won't work (policy pushes and logs) and status will show as Disconnected. Traffic should still pass through the gateway, assuming there are not larger problems on the gateway (such as resource shortages) that are causing cpd to die.
Site to site VPNs should still work, unless you are doing a so-called "Intranet" VPN between gateways that are using their SIC certificates to authenticate each other in IKE Phase 1. cpd being dead could break that scenario, while VPNs using a pre-shared secret for authentication in IKE Phase 1 (like Extranet VPNs to externally managed gateways and interoperable device peers) should be fine.
Edit: If you have rebooted it is unlikely you have a memory shortage, run command df -h to see disk utilization.
If that is all you are seeing in your cpd logs, it would appear that SIC needs to be reset on the gateway and reestablished with the SMS.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY