- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello,
After upgrading one of our firewalls from R80.40 to R81.10 we are unable to install a policy on the firewall.
We have performed the upgrade both from Gaia and SmartConsole, but get the same error after the upgrade.
When installing the policy from SmartConsole the task progress stops at step 'Preparing the policy for the upgraded target (5/11)'.
History:
We have searched for relevant support articles and some of them related to errors or changing in different .def files. As a noted we have not changed any .def files or other linux files directly on either SMS or GW.
IPv6 is disabled on the gateway.
Any suggestions as to what the cause of this error might be?
Thanks!
Just to clarify, this is failing while doing an upgrade to R81.10 from SmartConsole on a gateway running R80.40, correct?
Note this exact error is mentioned here: https://support.checkpoint.com/results/sk/sk139174
If you're absolutely certain you haven't modified any .def files, then this Expect command should restore them to defaults: update_inspect_files -f
If the issue still persists after doing that, I recommend a TAC case: https://help.checkpoint.com
Thank you both for your replies. I first tried TheRocks's suggestion, but could still not install the policy (same error as before).
Then I tried to run the update_inspect_files command, but got this error message:
[Expert@mgt:0]# update_inspect_files -f
Wrong usage: missing '-index' flag
Help text:
update_inspect_files --help
Please run with the following parameters: [-index <HFA_INDEX>] [-list <input file> (list of .def files)] [-path <path to the .def/_HFA.def files> (if different than $FWDIR/lib)] [-f (to force override)] [-mode <upgrade or export>]
To restore changed files run with -restore [-index <HFA index>].
Do I need to refer to a specific hotfix in order do restore the .def files?
Not sure.
Best to engage the TAC here.
I dont think that would be related to specific jumbo, honestly. As the guys said, TAC is your best bet at this point to solve this faster. Clearly, there is syntax missing somewhere, which is whats preventing policy push.
Thank you all for your suggestions. We will open a TAC case.
In the spirit of the community, please do share how it gets fixed, as that always helps other folks.
Cheers mate.
Yes, I will do that. I have a remote session with TAC scheduled this week.
What was the solution to the problem?
There was a syntax error in the file: /opt/CPsuite-R81.20/fw1/lib/user_early.def
After adding #endif at the end of the file, we could successfully push the policy again.
Here is what you need to do to fix this problem. IF mgmt is on R81.10 and gateway on R80.40, do below on your management server and Im fairly confident it will work.
Please open a TAC case: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 37 | |
| 14 | |
| 11 | |
| 10 | |
| 10 | |
| 10 | |
| 7 | |
| 7 | |
| 7 | |
| 6 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY