Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
johnnyringo
Advisor
Jump to solution

Check Point Security Management Server is not running

I'm deploying a fresh R81.10 CheckPoint Management Server in GCP via terraform.  The deployment looks good from what I can tell, but I'm unable to connect via SmartConsole.  A tcpdump does indicate the traffic is reaching the management server on port 19009 but there is no acknowledgement.  

I checked CPM  status and it isn't even running, even after completing initial configuration and rebooting:

[Expert@whatever:0]# $FWDIR/scripts/cpm_status.sh
Check Point Security Management Server is not running

The server does not have an $FWDIR/log/cpm.elg as one would expect.  It really looks like it's been deployed as a gateway, but I did explicitly set this:

installationType               = "Management only"
 
as an argument to startup-script.sh
0 Kudos
1 Solution

Accepted Solutions
johnnyringo
Advisor

I found the problem.  The gateways and management server use different images; I had missed that during the code merge.

  • R81.10 image for Cluster PAYG = "checkpoint-public/check-point-r8110-gw-payg-cluster-335-985-v20220126"
  • R81.10 image for Management Server = "checkpoint-public/check-point-r8110-payg-335-883-v20210706"

The cluster image supports only the firewall blade initially, so even if the startup-script.sh has been given an arguement to configure a management server, it won't work.  

View solution in original post

0 Kudos
4 Replies
the_rock
Legend
Legend

Do you see fwm running at all? If you do fw stat command, should say its management only.

0 Kudos
genisis__
Leader Leader
Leader

what does cpwd_admin -list tell you?

 

0 Kudos
johnnyringo
Advisor

I found the problem.  The gateways and management server use different images; I had missed that during the code merge.

  • R81.10 image for Cluster PAYG = "checkpoint-public/check-point-r8110-gw-payg-cluster-335-985-v20220126"
  • R81.10 image for Management Server = "checkpoint-public/check-point-r8110-payg-335-883-v20210706"

The cluster image supports only the firewall blade initially, so even if the startup-script.sh has been given an arguement to configure a management server, it won't work.  

0 Kudos
_Val_
Admin
Admin

thanks for sharing the solution

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events