- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi.
We have a customer running about 60 SMB appliances, all of them using R77.20.x (1430) or R81.10.x (1530).
(Yes, the customer knows that the 1430s have to be replaced in the next months. 😉)
My problem is with the 1530s. At the moment I have 4 of them where I cannot install policy. If I do a "fw fetch" on them I get this:
[Expert@cp-xxx01]# fw fetch
ndb_open : failed for /opt/fw1/database/fwauth.NDB: Read-only file system
fwa_db_init: fwdab_init failed
fwd_reload_database: Error loading from fwauth.NDB
Fetching Security Policy from 'aaa.bbb.ccc.ddd'
Local Security Policy is Up-To-Date.
Error: Failed to run policy installation wrapper.
sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/local/FW1"'. rc=1, exit code =-1
Unable to install the Security Policy on the appliance
[Expert@cp-xxx01]#
All of these appliances are running R81.10.00 - Build 575. I know that R81.10.08 - Build 683 is recommended release. Update is planned but it will take a serious amount of time, because update has to be coordinated with every single location.
So, at the moment I have to deal with R81.10.00. I found out that other 1530s with this version have no problems. And I know that there exists a problem with partition /pfrm2.0 filled above 85 % on R77.20.x (sk126372). I cannot find a SK with this limitation for R81.10.x.
But I found that all 1530s with problems have /pfrm2.0 filled above 85 %, the ones working are below this watermark. Since I have problems to get reboot clearance for the systems I would like to know…
Any help will be appreciated.
Thanks in advance,
Oliver
Hey Oliver,
Personally, I would call TAC and ask them to confirm, because that sk126372 states that if running R77.20.80 or higher, it would apply. Let me build quick SMB lab and see if the option is even there, will let you know.
Best,
Andy
Maybe it is the correct way to ask TAC. In the past, I got faster answers here from Check Point employees several times.
You are right that sk126372 states that you do not need a customer hotfix for R77.20.80 and higher. But the SK ist limited to R77.20. Such, I guess they are talking about the version up to R77.20.87.
Just spun up R81.10.10 smb lab and I dont see the option from sk126372 there at all.
Andy
I have no R81.10.10 avaible, but where still able to find this option in R81.10.08. I did some more research an found this in the R81.10.x Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances CLI Reference Guide:
In the R81.10.X releases, this command is available starting from the R81.10.00 version.
Description
Configure additional management settings.
Syntax
set additional-management-settings advanced-settings install-temporary-policy-to-storage { true | false }
I think, I will give this a try.
Seems to be the same as in Web GUI and is also available in R77.20.87…
(But I do not see any hint that a reboot is necessary.)
Yes, does not hurt to attempt it.
Got a possibility to reboot one of the failing appliances. That fixes the problem. Now /pfrm2.0 is at 81 % and writable again. So I am looking for a permanent fix…
Check out this post where TAC advised of a fix for it in R81.10.10
Andy
I logged a call and support kindly pointed me at : https://support.checkpoint.com/results/sk/sk181134
Where it states from Build 996002845 of R81.10.10:
SMBGWY-7083 | General | The Quantum Spark appliance automatically removes files from the "/tmp" partition if the file becomes full. |
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
3 | |
3 | |
2 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY