- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi.
We have a customer running about 60 SMB appliances, all of them using R77.20.x (1430) or R81.10.x (1530).
(Yes, the customer knows that the 1430s have to be replaced in the next months. 😉)
My problem is with the 1530s. At the moment I have 4 of them where I cannot install policy. If I do a "fw fetch" on them I get this:
[Expert@cp-xxx01]# fw fetch
ndb_open : failed for /opt/fw1/database/fwauth.NDB: Read-only file system
fwa_db_init: fwdab_init failed
fwd_reload_database: Error loading from fwauth.NDB
Fetching Security Policy from 'aaa.bbb.ccc.ddd'
Local Security Policy is Up-To-Date.
Error: Failed to run policy installation wrapper.
sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/local/FW1"'. rc=1, exit code =-1
Unable to install the Security Policy on the appliance
[Expert@cp-xxx01]#
All of these appliances are running R81.10.00 - Build 575. I know that R81.10.08 - Build 683 is recommended release. Update is planned but it will take a serious amount of time, because update has to be coordinated with every single location.
So, at the moment I have to deal with R81.10.00. I found out that other 1530s with this version have no problems. And I know that there exists a problem with partition /pfrm2.0 filled above 85 % on R77.20.x (sk126372). I cannot find a SK with this limitation for R81.10.x.
But I found that all 1530s with problems have /pfrm2.0 filled above 85 %, the ones working are below this watermark. Since I have problems to get reboot clearance for the systems I would like to know…
Any help will be appreciated.
Thanks in advance,
Oliver
Hey Oliver,
Personally, I would call TAC and ask them to confirm, because that sk126372 states that if running R77.20.80 or higher, it would apply. Let me build quick SMB lab and see if the option is even there, will let you know.
Best,
Andy
Maybe it is the correct way to ask TAC. In the past, I got faster answers here from Check Point employees several times.
You are right that sk126372 states that you do not need a customer hotfix for R77.20.80 and higher. But the SK ist limited to R77.20. Such, I guess they are talking about the version up to R77.20.87.
Just spun up R81.10.10 smb lab and I dont see the option from sk126372 there at all.
Andy
I have no R81.10.10 avaible, but where still able to find this option in R81.10.08. I did some more research an found this in the R81.10.x Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances CLI Reference Guide:
In the R81.10.X releases, this command is available starting from the R81.10.00 version.
Description
Configure additional management settings.
Syntax
set additional-management-settings advanced-settings install-temporary-policy-to-storage { true | false }
I think, I will give this a try.
Seems to be the same as in Web GUI and is also available in R77.20.87…
(But I do not see any hint that a reboot is necessary.)
Yes, does not hurt to attempt it.
Got a possibility to reboot one of the failing appliances. That fixes the problem. Now /pfrm2.0 is at 81 % and writable again. So I am looking for a permanent fix…
Check out this post where TAC advised of a fix for it in R81.10.10
Andy
I logged a call and support kindly pointed me at : https://support.checkpoint.com/results/sk/sk181134
Where it states from Build 996002845 of R81.10.10:
| SMBGWY-7083 | General | The Quantum Spark appliance automatically removes files from the "/tmp" partition if the file becomes full. |
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY