- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
Environment:
We faced today with error when we tried to install policy on CP cluster. We simply can not install security policy on cluster with an error:
Status: Failed - Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 1-2000245)
I can not find any official Check Point's SK regarding this particular error.
There is one SK with many R8X.XX errors, but not this particular one:
"Policy installation failed on gateway. If the problem persists contact Check Point support (Error c... In this SK there is following explanation under 34:
I opened SR along with policy report file from MGMT server (from picture above) but still no valid help from Check Point techical stuff.
We reverted back to one DB revision back (when all worked) - but an error is still in place, can not install policy.
We installed latest jumbo for r80.40 - take 120, but and an error is still there.
How to check if some object is locked in db for some strange reason? We tried with rebooting mgmt server no success.
We tried with rebooting both GW's and with failover, but again we made no success, an error is still in place.
Our GW's are with old jumbo, maybe it should be installed with take 120 too? I assume this is only MGMT side error.
All suggestions are welcome. Kindly feel free to comment this subject.
Regards,
Milos
This is MGMT server's policy install log file during policy install error:
23/08/21 14:13:06,815 INFO com.checkpoint.management.dleserver.coresvc.internal.LegacyPolicyLoader$PolicyLoadTask.doWork:151 [unboundedTaskExecutor-19]: Starting to loading policy 'Standard' for product 'Access' on 1 gateways. Calling thread: unboundedTaskExecutor-3 (id: 226) Standard.W: Security Policy Script generated into Standard.pf&CURRENTVERCMP 23/08/21 14:13:54,121 INFO com.checkpoint.management.dleserver.coresvc.internal.LegacyPolicyLoader$PolicyLoadTask.doWork:40 [unboundedTaskExecutor-19]: Completed to load legacy policy for product 'Access' |
Above latter subject update there are many statements in log file like following one (before this error):
23/08/21 14:13:00,266 INFO com.checkpoint.management.appi.internal.ConverterCpmiAppfwApplication.convert:11 [unboundedTaskExecutor-6]: Converting object: 'World Of Tanks' (uid: 02b38e7c-bd35-23b3-e053-08241dc279c2)
23/08/21 14:13:00,266 INFO com.checkpoint.management.appi.internal.ConverterCpmiAppfw.getArrayListWithWebBrowsingGroup:8 [unboundedTaskExecutor-6]: the services collection contains web browsing group.
23/08/21 14:13:00,266 INFO com.checkpoint.management.appi.internal.ConverterCpmiAppfw.getArrayListWithWebBrowsingGroup:5 [unboundedTaskExecutor-6]: the web browsing group changed.
This is tricky one...I had seen few posts with very similar errors, but its never one specific solution. I have few questions, hopefully we can help you fix this...
1) When exactly did this happen? Any changes done to the policy (im specifically referring to possibly adding/modifying dynamic objects?)
2) Have you tried doing fwm load command on mgmt? So something like this...actually, nm, that does not work on R80+...so try mgmt_cli --help and it should give you options to try install policy from there
3) Does this mgmt only manages these gateways? If not, does policy work on any other firewalls?
4) what does cpwd_admin list show on your management server?
Andy
Hi Andy,
This MGMT only manages this cluster (2 GW's).
This happened when our customer created one object (host type) and put it in access policy layer in source colomn:
When we deleted this error did not dissapear, and policy revert did not solve the error.
Did not try with mgmt_cli and policy install option.
cpwd_admin list output:
APP PID STAT #START START_TIME MON COMMAND
CPVIEWD 8477 E 1 [16:13:38] 23/8/2021 N cpviewd
CPVIEWS 8482 E 1 [16:13:38] 23/8/2021 N cpview_services
CPD 8504 E 1 [16:13:38] 23/8/2021 Y cpd
TP_CONF_SERVICE 8531 E 1 [16:13:38] 23/8/2021 N tp_conf_service --conf=tp_conf.json --log=error
FWD 8575 E 1 [16:13:39] 23/8/2021 N fwd -n
FWM 8684 E 1 [16:13:41] 23/8/2021 N fwm
STPR 8690 E 1 [16:13:43] 23/8/2021 N status_proxy
SOLR 8883 E 1 [16:13:46] 23/8/2021 N java_solr /opt/CPrt-R80.40/conf/jetty.xml
RFL 8979 E 1 [16:13:47] 23/8/2021 N LogCore
SMARTVIEW 9065 E 1 [16:13:49] 23/8/2021 N SmartView
INDEXER 9279 E 1 [16:13:53] 23/8/2021 N /opt/CPrt-R80.40/log_indexer/log_indexer
SMARTLOG_SERVER 10017 E 1 [16:14:18] 23/8/2021 N /opt/CPSmartLog-R80.40/smartlog_server
EXPORTER.QRadar 10340 E 1 [16:14:33] 23/8/2021 N /opt/CPrt-R80.40/log_exporter/targets/QRadar/log_exporter -export /opt/CPrt-R80.40/log_exporter/targets/QRadar/targetConfiguration.xml
REPMAN 10391 E 1 [16:14:37] 23/8/2021 N java_repository_manager
DASERVICE 10438 E 1 [16:14:39] 23/8/2021 N DAService_script
AUTOUPDATER 10737 E 1 [16:14:43] 23/8/2021 N AutoUpdaterService.sh
CPM 17248 E 1 [16:15:16] 23/8/2021 N /opt/CPsuite-R80.40/fw1/scripts/cpm.sh -s
CPSM 12630 E 1 [16:18:03] 23/8/2021 N cpstat_monitor
LPD 24768 E 1 [16:19:35] 23/8/2021 N lpd
Ok, interesting...so mgmt side shows all processes are running. Just wondering, do you get any errors if you do policy verification from dashboard?
The problem was software on GW side, there was some bug which solved installing latest Jumbo on both GW's.
Luckily it went that way, nothing was suspitious with GW's for us.
Yeah, I hear ya, definitely you got lucky on that one. Im glad you got it working!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
16 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY