Here is what AI gave...
**********************
That’s a good, detailed observation — and this is a known behavioral issue that can occur with Check Point gateways using dynamic public IPs managed via Smart-1 Cloud / SmartConsole, especially when:
-
The gateway’s external IP is obtained via DHCP or PPPoE,
-
The IP has not actually changed, but
-
The dynamic IP tracking mechanism in the management plane times out or loses synchronization.
Let’s break it down clearly:
🔍 Symptoms
-
Dynamic IP gateway shows no "Status" or “Not Available” in SmartConsole or Smart-1 Cloud.
-
Policy installs, SIC, logs, and monitoring continue to work normally.
-
The IP hasn’t changed (confirmed at OS level).
-
No visible connectivity issues between the gateway and the management server.
⚙️ Root Cause
Check Point management (including Smart-1 Cloud) periodically polls dynamic IP gateways to update their current external IP.
This update relies on:
-
The CPD and CPMI channels staying synchronized.
-
Dynamic object resolution (LocalGatewayExternal).
-
Proper reporting of the IP by the DAIP mechanism within the gateway (fwd and cpd processes).
Over time, if:
-
The gateway has been up for a long time without IP refresh,
-
The DAIP update timer expires without a new DHCP/PPP event, or
-
A temporary desync occurs between the management and the gateway’s object cache in Smart-1 Cloud,
then the status field may stop showing an IP even though SIC and policy communication continue to work.
This is cosmetic but can persist until a trigger refreshes the value.
✅ What You Can Check
On the gateway CLI:
# Check actual external IP and DAIP info
clish -c "show interfaces all"
clish -c "show asset"
On the management (Smart-1 Cloud) — from SmartConsole or CPView:
-
Verify SIC trust and policy install timestamp → still current ✅
-
Run cpstat mg or cpstat fw on the gateway if you have SSH access → no communication issues ✅
🧩 Known Workarounds / Fixes
-
Force the management to refresh the IP record:
-
From SmartConsole → right-click the gateway → Edit → Network Management tab
-
Temporarily change the interface type (Static → Dynamic → back to Dynamic).
-
Save & install policy → this triggers a new DAIP update event.
-
Restart the CPD service on the gateway (non-disruptive to traffic):
cpstop; cpstart
or less intrusive:
cprestart
This reinitializes DAIP reporting.
-
Rebooting the gateway (if maintenance window allows) always resets the dynamic IP advertisement process.
-
Ensure time sync (NTP) — if NTP drifts significantly, the Smart-1 Cloud may discard stale IP updates.
🧱 Additional Notes
-
The issue doesn’t affect routing, policy, or VPN.
-
Smart-1 Cloud will still identify the gateway via SIC name, not IP.
-
In some R81.10 / R81.20 builds, a fix was included to make DAIP reporting more persistent. Check Point recommended upgrading to R81.20 JHF T139 or later if you see recurring DAIP visibility problems.
🧩 Summary
| Component |
Status |
Notes |
| SIC |
✅ Working |
Still trusted |
| Policy Install |
✅ Works |
Communication intact |
| Logs |
✅ Normal |
No loss of log flow |
| Dynamic IP display |
⚠️ Missing |
Cosmetic sync issue |
| Fix |
🔄 Refresh DAIP info via SmartConsole or restart CPD |
|
Best,
Andy