- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
After upgrading one of our firewalls from R80.40 to R81.10 we are unable to install a policy on the firewall.
We have performed the upgrade both from Gaia and SmartConsole, but get the same error after the upgrade.
When installing the policy from SmartConsole the task progress stops at step 'Preparing the policy for the upgraded target (5/11)'.
History:
We have searched for relevant support articles and some of them related to errors or changing in different .def files. As a noted we have not changed any .def files or other linux files directly on either SMS or GW.
IPv6 is disabled on the gateway.
Any suggestions as to what the cause of this error might be?
Thanks!
Just to clarify, this is failing while doing an upgrade to R81.10 from SmartConsole on a gateway running R80.40, correct?
Note this exact error is mentioned here: https://support.checkpoint.com/results/sk/sk139174
If you're absolutely certain you haven't modified any .def files, then this Expect command should restore them to defaults: update_inspect_files -f
If the issue still persists after doing that, I recommend a TAC case: https://help.checkpoint.com
Thank you both for your replies. I first tried TheRocks's suggestion, but could still not install the policy (same error as before).
Then I tried to run the update_inspect_files command, but got this error message:
[Expert@mgt:0]# update_inspect_files -f
Wrong usage: missing '-index' flag
Help text:
update_inspect_files --help
Please run with the following parameters: [-index <HFA_INDEX>] [-list <input file> (list of .def files)] [-path <path to the .def/_HFA.def files> (if different than $FWDIR/lib)] [-f (to force override)] [-mode <upgrade or export>]
To restore changed files run with -restore [-index <HFA index>].
Do I need to refer to a specific hotfix in order do restore the .def files?
Not sure.
Best to engage the TAC here.
I dont think that would be related to specific jumbo, honestly. As the guys said, TAC is your best bet at this point to solve this faster. Clearly, there is syntax missing somewhere, which is whats preventing policy push.
Thank you all for your suggestions. We will open a TAC case.
In the spirit of the community, please do share how it gets fixed, as that always helps other folks.
Cheers mate.
Yes, I will do that. I have a remote session with TAC scheduled this week.
What was the solution to the problem?
There was a syntax error in the file: /opt/CPsuite-R81.20/fw1/lib/user_early.def
After adding #endif at the end of the file, we could successfully push the policy again.
Here is what you need to do to fix this problem. IF mgmt is on R81.10 and gateway on R80.40, do below on your management server and Im fairly confident it will work.
Please open a TAC case: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 14 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY