- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I've just added Appliance 1900 R81.10.15 to a virtual Management Server R81.20 via Internet.
The Status of the Connection is ✅Connected
The Status in Management Console "➖" and I can't install any policies: Installation Policy Error 0-2000259.
Unfortunately I didn't find any Information about this Error.
Very appreciate any help!
Thats expected, since its mgmt cli command.
Andy
and what should I do? I have other firewalls that were configured before me and there is no such problem there.
When I try to fetch the policy in the CLI, it really tries to fetch it from the local IP address. So, somehow I need to tell FW to fetch from Public IP. I didn't find any keys for "fw fetch" to specify a remote server...
fw fetch
Fetching Security Policy from '10.10.XXX.XXX'
Reason: TCP connectivity failure ( port = 18191 )( IP = 10.10.XXX.XXX )[ error no. 10 ].
Security Policy Fetch Failed.
Unable to fetch the Security Policy from the Management Server
Warning: Attemped to fetch policy from an IP address that is different than the one used to fetch the certificate. Please check the management object's IP address in the SmartDashboard.
This points to a connectivity issue.
Confirm you can open a TCP connection on port 18191 (netcat "nc" can be used for this) from the gateway to the management.
Also, what is the relation between the IP listed in the error message versus the one listed in the Main tab of the Management object?
Yes, port is open. Do you see the destination IP?
Personally, ever since I been around CP back from R55 days, I had NEVER seen that error not be related to SIC issue. Now, here is the thing. Say you do SIC reset and it works and then you try push policy and it fails, its usually route missing somewhere along the lines, if you will.
Hope that helps.
Andy
Sure it is routing problem, because the security server in Internet tries to connect to another server in Internet via private IP... why?
Maybe verify NATing, as well as current routes. For example, do ip r g command to "affected" ip address. Something like ip r g 8.8.8.8, just change the IP address, to confirm if its correct.
Andy
check this one out:
How to configure Management behind NAT in Security Gateway - special for SPARK
https://support.checkpoint.com/results/sk/sk66381
thank you! it did help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY