Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AfterMath
Collaborator

Update failed. Contract entitlement check failed. Gateway can not access internet

Hi there

One of our Cluster comes with the error '

Update failed. Contract entitlement check failed. Gateway can not access internet ("https://updates.checkpoint.com/WebService/services/DownloadMetaDataService"). Check connectivity and proxy settings.

': Note that we are running R81.20 with the latest recomended hotfix, and we check dns and comunication, we can ping but we can note reach access..

 

dd.PNG

 

 

0 Kudos
18 Replies
Lesley
Authority Authority
Authority

Is this a VSX setup? Is this a cluster and if so is this the stand-by member?

Do port 80 websites work? Traffic shows allowed in logging?

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
AfterMath
Collaborator

Hi @Lesley 

Not, its not! Yes its a cluster, both members, stand and active

dont work

0 Kudos
the_rock
Legend
Legend

When did this happen, any idea? Does below work?

curl_cli -k google.com

Andy

0 Kudos
AfterMath
Collaborator

Hi @the_rock 

we though like was dns problem, because was not pinging updates.checkpoint.com we have set the valid dns server and know are pinging but still having problem to update.

cc.PNG

0 Kudos
the_rock
Legend
Legend

run ip r g 8.8.8.8 and please send the output

Also, check below files on the fw:

$FWDIR/appi/update/appi_statuc.C

$FWDIR/ips/update/ips_status.C

0 Kudos
AfterMath
Collaborator

Hi @the_rock 

novo1.PNG


novo2.PNG

0 Kudos
the_rock
Legend
Legend

So you probably dont have app control enabled then, if 2nd command fails. Either way, looks like ips update is failing, for sure. 

Question, did you try update it manually from smart console?

Andy

0 Kudos
AfterMath
Collaborator

Hi @the_rock 

App control!  we dont use cp fw for urç filtering and app control..   

We run 4 fw, in two cluster managed by one mgmt, everything is the same. we only have issue in first cluster, 

cp1.PNG

cp2.PNG

 We have tthinking that the issue may be related to the certificare, perahps!
 first cluster with issue

cp3.PNG


second cluster

cp4.PNG

update manually!! i didn´t yet

cp6.PNG

 






0 Kudos
the_rock
Legend
Legend

Well, it might be the case, but are you able to access that portal by the IP address? If yes, then I dont believe that would be causing this problem...

Andy

0 Kudos
AfterMath
Collaborator

yes

 

cp11.PNG

0 Kudos
the_rock
Legend
Legend

I would call TAC for this and do remote.

Andy

0 Kudos
Henrik_J
Contributor

Have you checked the logs to see if it is getting dropped?
If you haven't already, go into global properties and check the box that states to log implied rules.

Sometimes people deactivate these implied rules, which then can cause issues for the gateway to start its own sessions.

I have also noticed issues for gateway communications if you try to do any STATIC NAT on FWs public IP.
So double check NAT rules.

I would also check fw monitor in one seperate window when conducting tests...
See: https://tcpdump101.com/
You can use the new or old version, but old version requires to disable fwaccel / SecureXL, so if you can work with the new it's better.

There you will clearly see what  and where it's sent out, and if it receives anything back at all.

the_rock
Legend
Legend

Glad to see my colleague's site getting "promoted" : - ). I told him about it and he said that makes him very happy, so he will definitely try spend some time to make it even better.

Anyd

0 Kudos
Henrik_J
Contributor

I think the site does its job perfectly.
It might look old and outdated, but to my eyes, it's simply effecient without any needless things.
Really like it.
I think it's the perfect site for people to go to to start with fw monitor, tell him thanks from me 🙂

0 Kudos
the_rock
Legend
Legend

Will do! You can also contact him on twitter or whatever they call it these days...I was never big social media guy )quite frankly, never cared for it lol), but I will definitely tell him Monday when I see him.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

For what its worth, maybe verify below things, as per AI response.

Andy

****************************************

 

 

🔍 Error Summary:

Message:

 

pgsql
Update failed. Contract entitlement check failed. Gateway can not access internet ("https://updates.checkpoint.com/WebService/services/DownloadMetaDataService"). Check connectivity and proxy settings.

 

Troubleshooting Steps:

  1. Test Internet Access from Gateway:

    • Log into the CLI (via SSH or console).

    • Run:

      bash
    • Or, if curl isn't available:

      bash
      telnet updates.checkpoint.com 443
    • If this fails, the gateway has no internet access or DNS resolution problems.

  2. Check DNS Settings:

    • Ensure /etc/resolv.conf has valid DNS entries.

    • Test name resolution:

      bash
      nslookup updates.checkpoint.com
  3. Check Proxy Configuration (if required):

    • If you're behind a corporate proxy, you must configure it:

      • In SmartConsole: Go to Device > System Settings > Proxy.

      • Or CLI:

        bash
        dbset proxy:<proxy_address> dbset proxy_user:<username> # if required dbset proxy_password:<password> # if required
  4. Verify Contract Entitlement:

    • Ensure your gateway has a valid support contract.

    • Log into your Check Point User Center account and verify your product entitlements.

  5. Firewall Rules:

    • Ensure the gateway or any upstream firewall allows outbound HTTPS (TCP 443) to:

      • updates.checkpoint.com

      • dl3.checkpoint.com

      • secureupdates.checkpoint.com

  6. Check for Hotfixes:

    • Some Check Point versions (especially older ones) may need a hotfix to support updated TLS protocols used by Check Point’s servers.

    • Reference relevant SK articles (like SK83520 or SK113747) on Check Point’s support portal.

0 Kudos
the_rock
Legend
Legend

By the way, since I offer this to everyone, if you are willing and allowed to do remote, happy to try and assist that way. let me know. Im in EST time zone (GMT -4)

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

On my SMS this works: I get a 301 moved

 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events