Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rabin
Contributor

Checkpoint Policy Installation Failed in Checkpoint Mangement Server

Dear Checkmates,

Greetings,

We are not able to install the policy after installing the eval license. The managment server shows that the access policy installation failed while threat prevention policy gets installed.  We could fetch policy through gateway and through management_cli api but cannot push through the smartconsole.

If yo had encounterd the issue or have any ideas please share. I have attached the screenshot of the erros.

Thank You.

Regards,

Rabindra Khadka

0 Kudos
41 Replies
G_W_Albrecht
Legend Legend
Legend

Did you resolve the errors shown already ? I would bet that the policy does not even get compiled and policy fetch from GW just loads the old policy...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Rabin
Contributor

Hi @G_W_Albrecht ,

No luck, still we cannot push the policy from smartconsole. As observer from the gateway we can fetch the policy but i am not sure whether its new or old one. Is there any thing that we could try here ?.

Thank You.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

What is shown if you just verify the policy ? What is the error if the old errors have been fixed ? And please provide a screenshot with all lines from the Policy install window...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Hey Rabindra,

Please try to verify policy like @G_W_Albrecht suggested, so we can see why its failing. There must be something causing this, since warnings showing in the screenshot are simply that, just warnings, it would not fail because of that.

Andy

 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

This could be more than warnings as we do not see all lines right of Access policy, but top line policy verification failed is a grave error that will make the policy not installable...

So show all lines please!

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

@AkosBakos is right actually, seems like its related to threat prevention policy, but yes, agree, we need to see all the lines.

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Hi @Rabin 

You wanted to install the Threat Prevention policy only as I see.

  • You are able to install the Access Control policy, or do you get the same error?
  • As I remember you was the person who asked about Content Awareness yesterday.
    • did you apply any RegExp in the filename section?

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
G_W_Albrecht
Legend Legend
Legend

Where do you see that he wanted to install the Threat Prevention policy only ? That selection is not shown. As TP policy install has succeeded, it is the enlarged Access policy part that is mostly hidden and has warnings in the shown lines, and you see that Access policy install failed on top...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

See below. Though based on the message, appears its failing for a different gateway.

Andy

 

Screenshot_1.png

0 Kudos
G_W_Albrecht
Legend Legend
Legend

That is wrong.The line for TP policy Succeeded is only one line without warnings, or else it would look like:

Screenshot 2025-01-07 143411.png

but the Access policy line is expanded, see the 

Screenshot 2025-01-07 143013.png

- from Policy Installation failed down the warnings belong to Access Policy...

I do not really understand how you as a long-time CP specialist make such mistakes, this is all obvious from the screenshot...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Its not really clear to me, sorry. Im simply going by what I see and what I see it shows threat prevention policy. Unless I look at the whole thing, I cant tell. 

Btw, Im not any type of guru or specialist, not even close haha

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

If it is succeeding, it has no warnings, as in the screenshot. In my screenshot, it succeeds with warnings, this is shown differently. As it just succeeds, the warning below Policy Install failed belong to the Access Policy.

But blunder or not, we will need to see all lines for any suggestions.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

I agree. You are right its most likely regular policy, since even verification would only work for access policy, not threat prevention one, but lets see if @Rabin can send us the exact failure, will be easier to help.

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Hu @G_W_Albrecht 

I linked this issue to this behind the scenes.

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
G_W_Albrecht
Legend Legend
Legend

So where do the warnings come from if TP is installed successfully (that is, without warnings and errors) ?

You can see all in the screenshot (except the access policy line and further lines right from it, that would be the most important lines to show)

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Rabin
Contributor

Hi @AkosBakos ,

I could not follow up these cases as i am stuck with another issue which EOS and probably EOL. Will definately update you on this.

Rabindra

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Please provide more details of the actual error and version/JHF of the relevant components.

Side note R80.30 is EOL

CCSM R77/R80/ELITE
0 Kudos
Rabin
Contributor

Hi Everyone,

Regarding this issus, just wanted to provide the quick update on this issue. The current checkpoint appliances are in R80.30 version with the latest hotfix take 255 and same goes for another cluster which has R81.10 version with latest hotfix take 172 with same issue. 

We have verified the policy before installing the policies which get successfully verified. We checked the resource utilization seems normal, collected the cpd.elg logs for furhter analysis. As far as the screenshot is concerned there are only warning for application blades for https inspection and some source and destination with any which are not recommended. 

Will post the detailed screenshot shortly.

Thank You.

0 Kudos
the_rock
Legend
Legend

That would 100% help us. Its a bit odd if you only see warnings, since policy would never fail due to those.  Anyway, once you send the full error, Im sure we will fix it quick.

Andy

0 Kudos
Rabin
Contributor

Dear All,

Please find the attached screenshot here:

the_rock
Legend
Legend

Seems this is the solution. I did see this once in the lab in R81.10 and after rebooting the mgmt, it got solved.

Andy

https://support.checkpoint.com/results/sk/sk149093

G_W_Albrecht
Legend Legend
Legend

In viber_image_2025-01-07_19-47-47-349.jpg you could have clicked more... before taking a screenshot.

But as viber_image_2025-01-07_19-47-23-546.jpg shows an internal error i would suggest to cantact CP TAC asap to get this resolved !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Rabin
Contributor

There are more and more warning which are just for policies, which were working before, I have verified all those so it's the same, anyway thank you. We have TAC support aligned and as POA : reboot, hotfix  but not resolved and further debugs has been collected. This is critical issue since we are not able to make any changes, I had to seek some support from the community as well.

Thank You all for the insight, I will keep posting if this issue gets resolved.

 

Regards,

Rabindra.

(1)
G_W_Albrecht
Legend Legend
Legend

Seeking support from community is always good ! It is just that we can not suggest much here (would need debugs) - and most posts are only misinterpreting your screenshot 😉

Could well be a database corruption as policies were working before, did TAC run cpm_doctor yet ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Can you please try below from support site? I have a good feeling it would solve the problem.

Andy

https://support.checkpoint.com/results/sk/sk149093

0 Kudos
Rabin
Contributor

Hi @the_rock ,

We have latest hotfix take 255 for R80.30 version which should have fix the issue and rebooted several times with no luck. Sure will try pretending not having hotfixes go for workaround solution mentioned in the sk, let's see.😜

Thank you for the support😊

0 Kudos
the_rock
Legend
Legend

Fair enough. Ultimately, as @Chris_Atkinson said, R80.30 is eol, so you should upgrade, for sure. Now, if you cant do so any time soon, we will do our best to help you fix it. Im happy to do remote if you are allowed.

Andy

0 Kudos
Rabin
Contributor

Actually we could upgrade but at the peak hours, memory and CPU utilization exceed over 100% but for another cluster we have managed to upgrade to R81.10. Even though R80.30 has no support we, somehow managed to get support from TAC.  Thank You so much for the support 🙌. Sure I will let you know if TAC team can not resolve it.

Once again thank you so much, appreciate it. 😊

AkosBakos
Leader Leader
Leader

Hi for the last chance:

What does 

say?

----------------
\m/_(>_<)_\m/
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events