- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- install policy FAILED help!
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
install policy FAILED help!
I have the most unhelpful error message of all time - can anyone help me ?
I'm trying to push access policy . everything was working last time i checked which was a few days ago. now this.
If the problem persists contact Check Point support (Error code: 0-2000173-0)
MDS is running 80.40
gateway is running 80.20
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Almost certainly a policy commit failure on the gateway, which provides practically zero information about the failure back to the SMS/SmartConsole. Usually this is due to a memory shortage on an overloaded gateway and sometimes a reboot will fix it. In other cases it is an error in the compiled policy that the SMS did not catch, see here for further reading:
sk101875: Policy installation fails with "Load on module failed - no memory" error
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is the error i get when i try and fetch the policy from the gateway side of things.
[Expert@FW01]# fw fetch
Fetching Security Policy from '#.#.#.#'
Fetching Security Policy Succeeded.
Installing Security Policy...
Error loading policy.
Error: Failed to run policy installation wrapper.
sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/__tmp/FW1"'. rc=1, exit code =-1
Unable to install the Security Policy on the appliance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I suggest opened a ticket with TAC but in the meantime:
Is the Security Gateway a Small Office Appliance?
Can you run the following command and send me the output:
fw -d fetchlocal -d /opt/CPsuite-R81/fw1/state/__tmp/FW1/
Thanks
Tal
tfridman@checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sent, thanks ,
on a better note i was able to push access control policy if i un-selected the "application control" & "url filtering" blades
as soon as i check them back off and try to push policy it fails again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello all.
Faced the same problem.> From the SMS SmartConsole "Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-2000173-0)". From the SMB 1570 "Last policy installation failed: Error reading IPS signatures." on "Fetch policy" button.
There are 0 cases on this problem in the community and knowledge base. My solution to the problem:
1. On SMB Gateway put command /ips off ;
2. On SMB Gateway put command /reboot ;
3. On SMB Gateway put command /cpstop;cpstart ;
4. On SMS Smartconsole disable IPS on object SMB Gateway ;
5. On SMS put command form ssh /reboot
6. On SMS Smartconsole enable IPS on object SMB Gateway ;
7. Push policy from SMS SmartConsole to SMB Gateway. Installed successfully👨🔧
This helped me.
My config:
SMS R 81.
SMB R 80.20.35
