Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kamilazat
Collaborator
Jump to solution

Error code: 0-1-2000096 while installing policy

Hi everyone!

 

Setup: Newly installed ClusterXL+SMS (R81.20 JHF Take 84)

The standby member was not updating its IPS database, and in order make it work, I followed sk43807 and added the ports and protocols to the table.def file on the SMS. It worked perfectly fine and the standby member was able to update its IPS database to the same version as the active node.

Although the standby member can update its IPS version, the output of fw tab -t no_hide_services_ports -u does not show the ports and protocols that I added through the table.def file.

After that, I deleted the added ports and protocols from the table.def file and clicked on 'Install Policy'. It failed with the following error message:

"Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-1-2000096)."

I have already looked up the error code on support.checkpoint.com, and read the only two CheckMates links that it gave me (this and this). I also read all the seemingly similar SKs about policy installation errors. However there is no information about this specific error code.

Additionally, I tried replacing the table.def file from another newly installed setup, removed and reinstalled JHF package, used policy_debug.sh, manually debugged cpm, fwm, fwd and cpd processes while installing policy. I found nothing that seems useful.

Threat Prevention policy installs with no issues.

It is just a lab, but I wonder what I would do if one of our customers had a similar issue (before opening a TAC ticket). I don't think opening a TAC ticket for my case is currently necessary.

 

Where else can I look? Did anyone else encounter such an issue? 

 

Cheers!

0 Kudos
1 Solution

Accepted Solutions
kamilazat
Collaborator

@Gaurav_Pandya doing # fw fetch <IP-of-SMS> told me this:

Management rejected fetch for this module - sic name does not match.

Policy Fetch Failed

And then I went on and reestablished SIC on both nodes, and everything worked perfectly fine.

Thank you very much!

 

As a side note, it's kind of a shame that I didn't see anything related to non-matching SIC names in all the debugs I did.

View solution in original post

5 Replies
Gaurav_Pandya
Advisor

Hi,

Try to fetch policy from below command, it will give more description why policy installation is failing.

#fetch policy <mgmt_IP>

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Never heard of this commend - i always use

fw -d fetch <Master 1>

<Master 1> [<Master 2> ...]

Specifies the Check Point computer(s), from which to fetch the policy.

You can fetch the policy from the Management Server, or a peer Cluster Member.

G_W_Albrecht_0-1728389244783.png

 

Notes:

  • If you fetch the policy from the Management Server, you can enter one of these:

    • The main IP address of the Management Server object.

    • The object name of the Management Server.

    • The hostname that the Security Gateway resolves to the main IP address of the Management Server.

 

CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Gaurav_Pandya
Advisor

Right. "fetch policy" is for SMB appliances. You need to run "fw fetch" command.

(1)
kamilazat
Collaborator

@Gaurav_Pandya doing # fw fetch <IP-of-SMS> told me this:

Management rejected fetch for this module - sic name does not match.

Policy Fetch Failed

And then I went on and reestablished SIC on both nodes, and everything worked perfectly fine.

Thank you very much!

 

As a side note, it's kind of a shame that I didn't see anything related to non-matching SIC names in all the debugs I did.

G_W_Albrecht
Legend Legend
Legend

If policy install fails for other reasons than time out, checking communication/SIC in Dashboard is always the first step before doing debugs...

CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events