- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
While adding a gateway to a management station the gateway is added , but without interfaces and topology and an error message when establishing trust between management station (SMS) and gateway (GW).
The trust relationship between SMS and GW is showing an error:
"Failed to connect to GW (IP Address: '...').
Please make sure Check Point Services are running on GW, and trust has been established".
But the trust is nevertheless established as this is showing on the General Properties tab of the GW in the SMS / Smart Console (Green tick mark).
And "Test SIC status" button press results in : "SIC Status for GW: Communicating"
And as stated above , in the SMS, the GW is missing interfaces.
Get interfaces (with or without topology) in the SmartConsole, results in the error:
"get interfaces operation failed for .... (IP of gateway)".
Version R80.10.
Connection to GW is working for both ssh and https.
Try to perform "fw unloadlocal" on the gateway and repeat the "Get Interfaces".
Although the topology extraction should work with SIC in a good state.
Have you perchance changed any of the Global Properties?
Additionally, if this is a remote gateway, such as at one of the branches of the bank or a retail location, please make sure that your SMS is statically NATed and is not simply hiding behind local gateway's external IP.
Did the "fw unloadlocal" and after that another "Get interfaces", but with same result.
"Failed to connect to GW (IP Address: '...').
Please make sure Check Point Services are running on GW, and trust has been established".
The management server is in use for some years and has similar gateways (indeed remote/branch) added in the past, with NAT setting "hiding behind local gateway's external IP" ticked on the gateway.
The global properties have not been changed recently but are not default.
The management station's gateway has static NAT configured with external IP address on the NAT tab ,
On the same tab/page, in the "install on gateway"-box a dummy gateway is selected.
(The dummy gateway is configured elsewhere in the SMS).
On the same NAT tab/page, the "Apply for Security gateway control connections" box is ticked.
Would manualy added interfaces (for this GW, in SMS) lead to any drawback?
The main reason to "fetch" the interfaces is to reduce the risk of a potential configuration error, especially with respect to Anti-Spoofing.
Otherwise, it's ok to define them manually.
Maybe some general troubleshooting of SIC?
Although the commentators above suggested otherwise, SIC and fetching topology are unrelated.
SIC is performed by cpd on TCP, several 18XXX ports, and interfaces are fetched by fwd on a TCP port 256. Make sure fwd is running on the GW and port 256 is not blocked between MGMT and GW.
Had the same problem.
Allowing port 256 from SMS to the gateways solved the problem for me.
Hi JayJay,
Did you solved the issue?
I facing same error when try re-establish SIC connection using cp_conf command without restart service.
Thanks
Hello doing the same and experience the same problem, how did you manage to resolve?
hello all,
In my case cpstop;cpstart did the trick.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY