- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Setup is 2x Management Server 5150 with dedicated SmartEvent server all running R80.20.M2 pushing policy to a single 5800 HA ClusterXL setup all running R80.10. The management and cluster are located at the same site. The access/threat policy takes less than 3 minutes to succeed on the cluster but the 99% finalizing status takes a very long time to complete. I've just pushed a policy and it again finished in 3 minutes but has been stuck at 99% finalizing for the past 45 minutes...
Is anyone else experiencing this after updating your management to R80.20.M2 or R80.20 in general?
Finalizing step is for post-policy installation activities, most notably Install Database at the log server in order to ensure that names of hosts are displayed instead of IP addresses at the log cards. So by the time that you see Finalizing, the enforcement already happens.
That 99% finalizing finished after almost exactly 2 hours. This time of finalizing aligns with what another employee is experiencing when pushing to this same cluster. Yet another employee says he does not have these same issues:
I updated the version above because it's R80.20.M2 for the management. After talking with my team, we are also seeing these issues:
- SmartConsole > Gateways & Servers clicking on a gateway or cluster will open up a, seemingly, random gateway object. This is not resolved until you close and re-open the SmartConsole
- SmartConsole > Logs & Monitor sometimes this tab is unresponsive and it will have to be opened in the top menu
- SmartConsole login sessions using RADIUS get hung where we cannot login. Rebooting the management does not help the situation but it clears randomly after time where we can login. Local logins still work during this time.
We have opened a TAC case and will update this ticket with the resolution.
Hi
Is this something that is happens every time or at least frequently?
If so please contact me directly at tfridman@checkpoint.com so that we can collect the relevant debug information and analyze with R&D.
Best wishes
Tal
After working through some troubleshooting with support we narrowed it down to this happening on a certain gateway. I think it was amplified because this is one of our more active environments. I believe we gave some debugs to support last week. I'll include you on the messages with support. Thanks for following up!
Great. If you still want me to have R&D look at it directly please send me the following files for the install policy that is stuck:
$MDS_FWDIR/log/cpm.elg
$MDS_FWDIR/log/install_policy.elg
Also from the first message this is a Security Management Server?
Best wishes
Tal
Will do. Our admin is going to include you in the ticket we have opened. Thanks!
Hi @Julie_Paul
This issue was also handled by TAC and resolved with a W/A.
The problem was related to the policy that was installed on the gateway (please refer to SR 6-0001670596 for further information).
Tal
We have yet to apply the suggestions from TAC. We will update after this is resolved on our side here and via the ticket.
Thanks for update!
Tal
Still trying to capture the correct debugs for support...
I have observed this behavior when IPS updates were performed during policy installation and the TP profile called for them NOT to be in Staging mode.
The longer the period between IPS updates, the longer the installation of the policy takes.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
6 | |
5 | |
4 | |
4 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY