Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wolfgang
Authority
Authority

Warning! Firewall / SecureXL / HyperFlow boot configuration was not completed correctly

Fresh installed R82 gateway (Jumbo take 36, ElasticXL, VSNext)

Following message after login to console:

Warning! Firewall / SecureXL / HyperFlow boot configuration was not completed correctly.
for troubleshooting instructions, see sk181917 and examine this log file: /opt/CPsuite-R82/fw1/log/conf_param.elg

 

sk181917 isn't available in the knowledgebase. What does that mean ?

conf_param.elg shows:

conf_params;21-Aug-25 10:07:15;[INFO];<module>: ------------------ Start loading conf parameters ------------------
21/08/25 10:07:15: MainThread: confpLogger: INFO: ********************** Init Logger - New Run **********************
21/08/25 10:07:15: MainThread: lib_db: INFO: ********************** Init new redis-client **********************
conf_params;21-Aug-25 10:07:15;[INFO];main: --- Start running kiss ingestion for firewall securexl ppe ---
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/modules/ingest_fwkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPppak-R82/conf/simkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/modules/ingest_fwkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/conf/dmd.conf.
conf_params;21-Aug-25 10:07:15;[INFO];main: Finish running /opt/CPsuite-R82/fw1/scripts/kiss_ingestion.py for all successfully
conf_params;21-Aug-25 10:07:15;[INFO];get_vs_dir_list: Adding VS-500 to the list.
conf_params;21-Aug-25 10:07:15;[INFO];get_vs_dir_list: Adding VS-3 to the list.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-0: firewall, securexl, ppe.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'securexl' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'ppe' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-500: firewall.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-500.
conf_params;21-Aug-25 10:07:15;[ERROR];set_exit_with_error: Error opening or writing to /opt/CPsuite-R82/fw1/CTX/CTX00500/conf/fw_params_v4.conf.tmp; [Errno 2] No such file or directory: '/opt/CPs
uite-R82/fw1/CTX/CTX00500/conf/fw_params_v4.conf.tmp'.
conf_params;21-Aug-25 10:07:15;[ERROR];set_exit_with_error: Error opening or writing to /opt/CPsuite-R82/fw1/CTX/CTX00500/conf/fw_params_v6.conf.tmp; [Errno 2] No such file or directory: '/opt/CPs
uite-R82/fw1/CTX/CTX00500/conf/fw_params_v6.conf.tmp'.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-3: firewall.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-3.
conf_params;21-Aug-25 10:07:15;[INFO];<module>: ------------------ Done loading conf parameters ------------------

 

0 Kudos
15 Replies
Lesley
Authority Authority
Authority

Have you seen https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG... ?

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wolfgang
Authority
Authority

@Lesley Yes, I saw it, sk181917 is mentioned in this but as I wrote not available. We changed nothing in fwkern.conf or other global parameters everything is default.

0 Kudos
Lesley
Authority Authority
Authority

Do you use factory image or one you have downloaded and put the box with isomorphic?

Try not to use factory image

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wolfgang
Authority
Authority

We used isomorphic.

0 Kudos
Lesley
Authority Authority
Authority

Sorry only option I see for now is tac case especially if the sk is internal. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Steffen_Appel
Advisor

@Wolfgang is gaia_api status showing started for all processes?

0 Kudos
the_rock
Legend
Legend

I would definitely verify with TAC. I also searched for that sk, your link is the only thing that comes up.

Andy

0 Kudos
emmap
Employee
Employee

Hi, this is an internal SK, please raise a TAC case for investigation.

0 Kudos
Steffen_Appel
Advisor

We have the same issue on one cluster since take 25, TAC case is open for weeks without much progress.

0 Kudos
the_rock
Legend
Legend

Emma mentioned the sk is internal, maybe ask TAC about it?

0 Kudos
Steffen_Appel
Advisor

I just asked them about it - my assumption is that it is about using the registry instead of fwkern.conf

0 Kudos
Steffen_Appel
Advisor

They say the SK is about the kernel parameter syntax.

0 Kudos
_Val_
Admin
Admin

That SK is internal. I raised an issue with the relevant team. Meanwhile, please open a TAC request for your case

0 Kudos
Sergei_Shir
Employee
Employee

Our apologies for the inconvenience.

This SK article accidentally remained internal after the release of the R82 version.

This SK article is now available here (will appear in the search later):

https://support.checkpoint.com/results/sk/sk181917

0 Kudos
genisis__
Mentor Mentor
Mentor

Might want to add this to the thread I created for Issues with ElasticXL and VSNext.  Issues are getting resolved by Checkpoint, but for me ElasticXL with VSNext is still a little early for production use, and the documentation really should be updated so its separated out from Maestro documentation.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events