- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Experts
I've a query to get the Management server IP from Checkpoint gateway CLI. I'm currently working in an setup which is very big and every time we used to trace the network path for the firewall from user IP address or by using Splunk.
As i don't have permission to access the database which consists of the relevant firewall to it's management server IP address , I've to rely on my seniors to check the database for the relevant Management server IP address.
Is there any command from the gateway/firewall CLI to check the relevant Management server IP address that's been associated to. fw stat shows the policy name, not the CMA IP.
Thanks in advance.
Regards
Srinivasan
There's a few possibilities:
1. cplic print, which will show what licenses are installed on the gateway. In many cases, the IP listed is the management IP.
2. Look at $CPDIR/log/cpd.elg.* and see if there are any messages.
3. Check netstat -an | grep 18192 and see what IP is connected to the gateway.
Try cat $FWDIR/conf/master file if you have access to expert mode of a firewall. It will give you info of management center and log server.
Hi, i'm not getting management server IP. Please advise.
[Expert@Hostname]# cat $FWDIR/conf/masters
[Policy]
usaaucx01-EMEA
usamesx01-EMEA
[Log]
usamesx01-EMEA
[Alert]
usamesx01-EMEA
[Backup]
usamesx01-EMEA
There's a few possibilities:
1. cplic print, which will show what licenses are installed on the gateway. In many cases, the IP listed is the management IP.
2. Look at $CPDIR/log/cpd.elg.* and see if there are any messages.
3. Check netstat -an | grep 18192 and see what IP is connected to the gateway.
cplic print will most likely point to the Multi Domain Server and not the individual CMA.
Hi Mate
Thanks. I got CMA IP by implementing netstat command.
[Expert@Hostname]# netstat -an | grep 18192
tcp 0 0 0.0.0.0:18192 0.0.0.0:* LISTEN
tcp 0 0 172.16.10.1:18192 172.31.24.16:60243 ESTABLISHED
On a more generic level I find it ... disturbing that there seems to be no design available for the Check Point Management Infrastructure.
If a customer would ask me this I would recommend they fix the organisational problem. As the technical answer is merely a workaround for a organisational problem.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY