Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rabin
Contributor

Checkpoint Policy Installation Failed in Checkpoint Mangement Server

Dear Checkmates,

Greetings,

We are not able to install the policy after installing the eval license. The managment server shows that the access policy installation failed while threat prevention policy gets installed.  We could fetch policy through gateway and through management_cli api but cannot push through the smartconsole.

If yo had encounterd the issue or have any ideas please share. I have attached the screenshot of the erros.

Thank You.

Regards,

Rabindra Khadka

0 Kudos
41 Replies
the_rock
Legend
Legend

Sure, any time, glad to help. As @AkosBakos suggested, cpm_doctor is also good to run here, if you have not already. 

[Expert@CP-MANAGEMENT:0]# cd $FWDIR/scripts
[Expert@CP-MANAGEMENT:0]# ./run_cpmdoc.sh

0 Kudos
Rabin
Contributor

Sure, Will try that one too and post if we find something out of it.

0 Kudos
the_rock
Legend
Legend

Takes about a minute or so to run it and it would give you something like below.

Andy

 

[Expert@CP-MANAGEMENT:0]# ./run_cpmdoc.sh
*******************************************************
* CPM Doctor *
*******************************************************
Jan 07, 2025 10:01:36 AM Starting CPM Doctor
Jan 07, 2025 10:02:51 AM Generated report in: [/opt/CPsuite-R81.20/fw1/scripts/cpm_doctor_report07_01_2025-10_01_39.html]
Jan 07, 2025 10:02:51 AM CPM Doctor found 1 errors. Check the report for more info.
Jan 07, 2025 10:02:51 AM Thank you for using the Check Point CPM Doctor tool
[Expert@CP-MANAGEMENT:0]#

0 Kudos
PhoneBoy
Admin
Admin

FYI, TAC support on EOS versions is "best effort" meaning they'll try to help if they can.
Anything requiring a code fix will require upgrading to a supported release. 

G_W_Albrecht
Legend Legend
Legend

You wrote: Im not any type of guru or specialist, not even close haha

I just wonder why you offer RAS to resolve an issue on a production system if that is so. Also, many companies find it hard to let CP TAC do a RAS even after NDA was signed, so to do RAS with an unknown person from outside would in most cases be a massive security breach that can cost you your job (without a need to cause a network down by that...). At least with my company...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Im not worried...I do it on my own free time and had done it with people many times actually and we solved the issue. Some people are not allowed to do and thats fine too, I dont get offended by that LOL. Personally, I dont see anything wrong with it. Im not in business of recording peoples' screens to use it for malicious reasons, not my motto in life lol

Best,

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

You do it in your own free time for nothing but the customers risk - and he does not know you at all. You could be a hacker from north korea afaik 😉 This business is called something including security, remember ? I have even defended you when in December, at a CheckMates event in Vienna, one guy from the biggest Austrian CP partner asked me about you and told me he found you just post unnecessary nonsense on CheckMates that makes him angry while reading it. My answer: he is just trying to help, anyway, was a bit faked - because i also think you better only post if you really have something important to say...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Thank you for that, but no need to defend me, I can certainly defend myself haha. Anyway, if that person does not like my posts, they can block or ignore me. I am not here for any personal grievances, there are way better and more productive things in life 🙂

Happy New Year!

Andy

0 Kudos
Rabin
Contributor

Thank you for your response! I also completely agree and understand your concerns about security and the risks associated with RAS access.

Thanks for pointing this out! It’s a good reminder for everyone in the field to stay cautious and prioritize security, even when troubleshooting under pressure

the_rock
Legend
Legend

Totally...better be safe than sorry! I just offer genuinly wanting to help, but people can always say no...its a free world 🙂

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

People pay for CP support and are entitled to have RAS with CP TAC - but honestly, a RAS with an unknown stranger is an absolute no-go ! I believe you that you are harmless and honestly only trying to help others, but rather do that by offering suggestions for solution attempts but not by offering RAS to customers systems. This is a suspicious activity as written in the books. I assume you are not working in IT security but have CP as a hobby, according to your statements 😉

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
G_W_Albrecht
Legend Legend
Legend

As this happens all the same with R81.10 GWs, the R80.30 GWs are not the cause of the issue, rather the R81.10 SMS has an issue...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events