- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
Good day to you all!
We have a customer that have this issue where the Anti-Bot and Anti-Virus blades are showing this error:
"Update failed. Contract entitlement check failed. Server error occurred."
Normally as partners, we would just follow SKs that are available and request support with Check Point TAC if needed. However, this issue already lasted for more than a year and not a single TAC Engineer can resolve the issue.
When we try to curl, http (Port 80) was able to connect, while https (Port 443) was not.
See Below:
We are seeking help in the community because we`re just running circles with Checkpoint TAC. They are requesting outputs again and again, even we already have established that there were no proxies, there are policies, there are routes, and have provided numerous cpinfo.
Some TAC even mentioned that it is because that the gateways are not in a same UC since the secondary gateway is a lease.
Background:
At first, the customer is only running a single security gateway as their Internal Firewall. Then they sought our assistance to make their Internal Firewall into a Security Gateway Cluster. The customer then asked one of the Check Point distributors here in the Philippines to lease a gateway similar to theirs. As partners, we configured the gateways to form a cluster. The Cluster configuration was successful and was running smoothly. UNTIL the error occurred in the secondary (stand-by) gateway. This is the time where the customer will seek our help since it is their first time to encounter such a thing.
We did everything we could to resolve the issue by looking for available SKs that are similar with the case/issue. We sought the help of Checkpoint Support/TAC to help us, but for the last a year or more, none so far have resolved the issue.
Hoping for you honest and steadfast reply.
Regards,
Apologies if I ask same question you were probably asked before, but can you confirm if curl_cli works on say google.com?
Also, can you indeed verify routing is fine? I ask cause I see errors there is no route to host.
Best,
Andy
Hi Andy,
Yes, I can confirm that I am able to curl to google.com at port443. The routing is fine, we have policies in place as well.
If you allow remote session, I am more than happy to have a look, its not an issue. I am fairly sure I could help you out with this.
Best,
Andy
Ironically enough, I noticed exact same issue in my lab today on one of clustered fws, rebooted and went away. Strange...lets see if it comes up again or not. Im on R81.20 jumbo 43 (latest(
Andy
Hi Andy,
Good day!
Yes, normally reboot is the solution for this case. We have encountered this as well with other customers.
We may have a remote session. You can join with the scheduled remote session with TAC Engineer tomorrow (January 25, 2024, 11:00am GMT+8, Philippine Standard Time).
Here`s the SR case: 6-0003715416.
Thanks!
Regards,
Let us know how it goes. Thats way outside my working hours, sorry.
Best,
Andy
Actually, not that I think about it, I can probably do it, it will be 10 pm here in Canada EST. Can you message me offline and send the link for remote? I will also send you my direct email, I really would like to be on that remote. I am always used for time difference in Philippines to be 12 hours from Ottawa, canada, as thats how it was when I was there, but of course it changes haha, now its 13.
Best,
Andy
Can you see firewall logs to the IP addresses shown in the output there when trying the curl to the HTTPS site?
Hi emmap,
Good day!
Yes, we can see the logs.
Regards,
Hi,
Do you have an SR number so I can have a look at was done already on this case?
BR,
Alon
Hi Alonfe,
Good day!
Yes you can look on the case on this SR Number: 6-0003715416.
Please mind that this is not the SR since the beginning, we have opened multiple SR cases for the same issue.
Thanks!
Regards,
Hi Angelo,
Im so sorry I did not jump on remote, saw your email with the link you sent me, but had to do something else for work, and then it was almost 11 pm my time, so went to bed, since I was pretty tired.
How did it go with TAC? Any good news?
Best,
Andy
Hi Angelo,
You mention both cluster members are in different UC's. You probably already did this, but I wonder what the output of 'cplic print' is.
Regards,
Martijn
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY