- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I've just added Appliance 1900 R81.10.15 to a virtual Management Server R81.20 via Internet.
The Status of the Connection is ✅Connected
The Status in Management Console "➖" and I can't install any policies: Installation Policy Error 0-2000259.
Unfortunately I didn't find any Information about this Error.
Very appreciate any help!
Thats expected, since its mgmt cli command.
Andy
and what should I do? I have other firewalls that were configured before me and there is no such problem there.
When I try to fetch the policy in the CLI, it really tries to fetch it from the local IP address. So, somehow I need to tell FW to fetch from Public IP. I didn't find any keys for "fw fetch" to specify a remote server...
fw fetch
Fetching Security Policy from '10.10.XXX.XXX'
Reason: TCP connectivity failure ( port = 18191 )( IP = 10.10.XXX.XXX )[ error no. 10 ].
Security Policy Fetch Failed.
Unable to fetch the Security Policy from the Management Server
Warning: Attemped to fetch policy from an IP address that is different than the one used to fetch the certificate. Please check the management object's IP address in the SmartDashboard.
This points to a connectivity issue.
Confirm you can open a TCP connection on port 18191 (netcat "nc" can be used for this) from the gateway to the management.
Also, what is the relation between the IP listed in the error message versus the one listed in the Main tab of the Management object?
Yes, port is open. Do you see the destination IP?
Personally, ever since I been around CP back from R55 days, I had NEVER seen that error not be related to SIC issue. Now, here is the thing. Say you do SIC reset and it works and then you try push policy and it fails, its usually route missing somewhere along the lines, if you will.
Hope that helps.
Andy
Sure it is routing problem, because the security server in Internet tries to connect to another server in Internet via private IP... why?
Maybe verify NATing, as well as current routes. For example, do ip r g command to "affected" ip address. Something like ip r g 8.8.8.8, just change the IP address, to confirm if its correct.
Andy
check this one out:
How to configure Management behind NAT in Security Gateway - special for SPARK
https://support.checkpoint.com/results/sk/sk66381
thank you! it did help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY