- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
I have Smart-1 S600 SMS running R81.10 with take 79. Everything was working perfectly last week. Today I just tried to click on policy on Smart Console, it says "Could not load the selected policy". Also SmartView seems to be not working because I cant monitor the license informations. SMS gaia portal is also not working, not connecting from web browser.
Also, it shows in the logs that bunch of Monitored processes restarting frequently or going down on SMS origin. (Smartview,cpsead etc...)
However, I can SSH into SMS and CPU,RAM,STORAGE usage seems to be perfectly fine. Storage at 50%.
What is the issue?
I had the problem today too. I was in, working with no problems, then suddenly the rules page went blank, and I got an error.
Symptoms:
I found sk180382 No access to Gaia Portal on the Security Management Server (checkpoint.com).
Most of the symptoms matched (HTTPD seemed to be screwed and wouldn't reload). Except I did not get the "sic_cert.pem" error.
TAC directed me to sk179589 "Could not load selected policy" in SmartConsole (checkpoint.com)
I found that my /web/templates/httpd-ssl.conf.templ file was completely empty!
There was a .bac version, so I copied this back over the top of /web/templates/httpd-ssl.conf.templ.
HTTPD was still screwed (no reboot yet)
I rebooted....
Bingo - everything works perfectly again after the reboot.
So, try checking you /web/templates/httpd-ssl.conf.templ file and see if it's empty? That could be the problem. Restore from the backup file (or from another working machine) and reboot. Hopefully that'll fix the issue.
Tried a reboot yet ?
I second what @G_W_Albrecht told you, reboot seems best in this case. But, BEFORE you do that, if you can wait a little bit, can you please send output of below commands?
evconfig
top
ps -auxw
free -m
api status
Andy
# Andy
did not work for me 😉
You lost me there @G_W_Albrecht lol. What did not work?
The last command:
# Andy
-bash: Andy: command not found
😂
HAHAHAHAHA...I dont know man, worked fine for me!! Its layer 8 problem on your end brother...
Hi - this seems to be a problem affecting many important processes.
As G_W_Albrecht suggested, if possible, try rebooting the machine. A few minutes after it comes up, run the following command to see that all the processes are running properly:
cpwd_admin list
If all the processes are up, try repeating the actions you listed and see if everything is working properly.
If not, I suggest opened a ticket with TAC but we could also continue investigating it directly.
Thanks
What troubleshooting has been attempted so far?
cpstop;cpstart etc ...
I tried rebooting, after that I ran cpwd_admin list and everything seems to be in executing state. Problem still exactly the same. Also tried cpstop, cpstart as well.
Restore last update and redo recent changes ?
I do have snapshot and thinking of reverting it, but it's fairly old one so it will be real hassle to do vsx configs again
Is TAC involved already ? I would strongly suggest that with VSX managed...
K, can you confirm the following for us please? What is currently the status if you run api status command from expert mode? Also, can you send output of cpwd_admin list?
I actually had a weird issue couple of years ago with customer on R80.30 I believe and their mgmt server one day just "decided" to stop working and no matter what we did, we could never make smart console come up at all, even after working with TAC for few days. Finally, we decided not to spend more time on it and thank God they had working backup and after restore, we just loaded latest jumbo and all worked fine afterwards. I never recall seeing anything about policy not loading, first time I ever seen that was in my R81.20 lab, but it was standalone, which I could not make work after 5 tries.
Ok, so we can see that cpm and fwm processes are up and running, so thats good, but whats NOT good is that api status shows failed. Can you also run this
cd $FWDIR/scripts
./cpm_status.sh
Send the output of that script please. At this point, I wont waste your time and ask you to try another PC, as I know 100% it wont work, as long as api status shows failed, that has to show successful.
[Expert@mn-dc1-r1c1-sec-fw.sms1:0]# cd $FWDIR/scripts
[Expert@mn-dc1-r1c1-sec-fw.sms1:0]# ./cpm_status.sh
Check Point Security Management Server is running and ready
[Expert@mn-dc1-r1c1-sec-fw.sms1:0]#
this is the output.
Seems like apache in API is not running but I dont know much about api status troubleshooting
As @G_W_Albrecht said, that looks good. If I were you, I would pick up the phone and call TAC and work on this right away. There is something seriously wrong here, what it is, Im not sure myself. For any movement here, you need to see api status as successful, so one thing you could try is maybe api restart, see if it does anything.
Looks fine. TAC needed.
Hi Gombo,
What was the solution? can you please share it here, i am having exact issue.
WR,
Shira
I had the problem today too. I was in, working with no problems, then suddenly the rules page went blank, and I got an error.
Symptoms:
I found sk180382 No access to Gaia Portal on the Security Management Server (checkpoint.com).
Most of the symptoms matched (HTTPD seemed to be screwed and wouldn't reload). Except I did not get the "sic_cert.pem" error.
TAC directed me to sk179589 "Could not load selected policy" in SmartConsole (checkpoint.com)
I found that my /web/templates/httpd-ssl.conf.templ file was completely empty!
There was a .bac version, so I copied this back over the top of /web/templates/httpd-ssl.conf.templ.
HTTPD was still screwed (no reboot yet)
I rebooted....
Bingo - everything works perfectly again after the reboot.
So, try checking you /web/templates/httpd-ssl.conf.templ file and see if it's empty? That could be the problem. Restore from the backup file (or from another working machine) and reboot. Hopefully that'll fix the issue.
Wow, thats quite an issue you had...thanks for sharing, it can definitely help others if they encounter the same situation.
Andy
Hi,
In our case, issue got addressed after performing sk180829.
WR,
Shira
I remember customer doing this before Shira. No idea how it happened in the first place, but thank God it only happened once...
Ah good. That's kinda the same thing I did, but under a different SK. Glad it's all working again now!
I can confirm that this fix works on R81.20 Jumbo 41 for an Open Server SMS.
Had the exact same error message:"Could not load the selected policy"
Copied the /web/templates/httpd-ssl.conf.templ over the .bak file. Rebooted. Policy was visible again. Fixed.
Before applying the fix I noticed the following:
We had a power outage and the SMS was not shut down gracefully. When the SMS was manually started back up, the "Could not load the selected policy" issue appeared in the SmartConsole.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
7 | |
6 | |
4 | |
4 | |
4 | |
4 | |
2 | |
2 | |
2 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY