Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wolfgang
Authority
Authority

Warning! Firewall / SecureXL / HyperFlow boot configuration was not completed correctly

Fresh installed R82 gateway (Jumbo take 36, ElasticXL, VSNext)

Following message after login to console:

Warning! Firewall / SecureXL / HyperFlow boot configuration was not completed correctly.
for troubleshooting instructions, see sk181917 and examine this log file: /opt/CPsuite-R82/fw1/log/conf_param.elg

 

sk181917 isn't available in the knowledgebase. What does that mean ?

conf_param.elg shows:

conf_params;21-Aug-25 10:07:15;[INFO];<module>: ------------------ Start loading conf parameters ------------------
21/08/25 10:07:15: MainThread: confpLogger: INFO: ********************** Init Logger - New Run **********************
21/08/25 10:07:15: MainThread: lib_db: INFO: ********************** Init new redis-client **********************
conf_params;21-Aug-25 10:07:15;[INFO];main: --- Start running kiss ingestion for firewall securexl ppe ---
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/modules/ingest_fwkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPppak-R82/conf/simkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/modules/ingest_fwkern.conf.
conf_params;21-Aug-25 10:07:15;[INFO];load_parameters_from_conf_file: There are no parameters to update from /opt/CPsuite-R82/fw1/conf/dmd.conf.
conf_params;21-Aug-25 10:07:15;[INFO];main: Finish running /opt/CPsuite-R82/fw1/scripts/kiss_ingestion.py for all successfully
conf_params;21-Aug-25 10:07:15;[INFO];get_vs_dir_list: Adding VS-500 to the list.
conf_params;21-Aug-25 10:07:15;[INFO];get_vs_dir_list: Adding VS-3 to the list.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-0: firewall, securexl, ppe.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'securexl' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'ppe' in VS-0.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-500: firewall.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-500.
conf_params;21-Aug-25 10:07:15;[ERROR];set_exit_with_error: Error opening or writing to /opt/CPsuite-R82/fw1/CTX/CTX00500/conf/fw_params_v4.conf.tmp; [Errno 2] No such file or directory: '/opt/CPs
uite-R82/fw1/CTX/CTX00500/conf/fw_params_v4.conf.tmp'.
conf_params;21-Aug-25 10:07:15;[ERROR];set_exit_with_error: Error opening or writing to /opt/CPsuite-R82/fw1/CTX/CTX00500/conf/fw_params_v6.conf.tmp; [Errno 2] No such file or directory: '/opt/CPs
uite-R82/fw1/CTX/CTX00500/conf/fw_params_v6.conf.tmp'.
conf_params;21-Aug-25 10:07:15;[INFO];main: Modules to update for VS-3: firewall.
conf_params;21-Aug-25 10:07:15;[INFO];get_params_not_default_by_schema: No parameters to update for 'firewall' in VS-3.
conf_params;21-Aug-25 10:07:15;[INFO];<module>: ------------------ Done loading conf parameters ------------------

 

0 Kudos
14 Replies
Lesley
Authority Authority
Authority

Have you seen https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG... ?

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wolfgang
Authority
Authority

@Lesley Yes, I saw it, sk181917 is mentioned in this but as I wrote not available. We changed nothing in fwkern.conf or other global parameters everything is default.

0 Kudos
Lesley
Authority Authority
Authority

Do you use factory image or one you have downloaded and put the box with isomorphic?

Try not to use factory image

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wolfgang
Authority
Authority

We used isomorphic.

0 Kudos
Lesley
Authority Authority
Authority

Sorry only option I see for now is tac case especially if the sk is internal. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Steffen_Appel
Advisor

@Wolfgang is gaia_api status showing started for all processes?

0 Kudos
the_rock
Legend
Legend

I would definitely verify with TAC. I also searched for that sk, your link is the only thing that comes up.

Andy

0 Kudos
emmap
Employee
Employee

Hi, this is an internal SK, please raise a TAC case for investigation.

0 Kudos
Steffen_Appel
Advisor

We have the same issue on one cluster since take 25, TAC case is open for weeks without much progress.

0 Kudos
the_rock
Legend
Legend

Emma mentioned the sk is internal, maybe ask TAC about it?

0 Kudos
Steffen_Appel
Advisor

I just asked them about it - my assumption is that it is about using the registry instead of fwkern.conf

0 Kudos
Steffen_Appel
Advisor

They say the SK is about the kernel parameter syntax.

0 Kudos
_Val_
Admin
Admin

That SK is internal. I raised an issue with the relevant team. Meanwhile, please open a TAC request for your case

0 Kudos
genisis__
Mentor Mentor
Mentor

Might want to add this to the thread I created for Issues with ElasticXL and VSNext.  Issues are getting resolved by Checkpoint, but for me ElasticXL with VSNext is still a little early for production use, and the documentation really should be updated so its separated out from Maestro documentation.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events