- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Threat Emulation blade not communicating
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Threat Emulation blade not communicating
Hi,
In one of the firewall, We are getting error "Error : Communication error - Could not connect to cloud" on Smart vie monitor for Threat Emulation blade.
Did cpstop/cpstart and reboot the gateway but still the same issue. When checked details, it is showing as below.
What could be the issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good place to start would be to check DNS and gateway settings on that unit and follow the "Error: Could not connect to the Check Point Cloud. Check your connection settings (Proxy, DNS and g...
Plus, in the screenshot you are showing, there is an "Invalid subscription" string which may warrant looking into.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
All other blades like Antivirus, Antibot, URL Filtering are working fine so I don't think its issue with DNS or Proxy or connectivity.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I wonder if there is a Check Point portal where the state of cloud services could be looked-up...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you looked into the service contracts attached to that GW to see if the "Invalid subscription" has any merit?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'd start here: How to verify that Security Gateway and/or Security Management Server can access Check Point servers...
If it's a lack of subscription issue (which your screenshot suggests), that's a different issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
On the gateways command line this also shows you your TE subscription quota status:
# tecli show cloud quota
and
# cpstat threat-emulation -f contract
Regards Thomas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have this exact issue as well, only one of my Cluster XL members is showing this status, the URLs are reachable and the primary member is happily connected, only one of my FWs is showing this error and I have not yet been able to diagnose why...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gaurav,
Is your gateway with the problem a standby member of the cluster or is a standalone unit?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Standby member of a ClusterXL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mason
We had the same or maybe similar issue, which was resolved by following all the steps in sk43807.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Issue is resolved automatically, Without doing any changes on configuration side.
May be some issue at Checkpoint Side or may some local issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Vladimir,
Gateway which is having problem is standby unit of cluster.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In this case, I'd suggest opening a ticket with TAC and referencing this thread in it, as yours and Mason's issues seem to be the same, which leads me to believe that this may be a bug.
Should you do that, please keep this thread updated to let us know how and when the issue is resolved.
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Install a policy with the following
source : firewall-a,b,cluster (internal ips only)
dest: any
service : 80/443/53 domain udp
then retest the connection with the blade
your don’t have to do natting if the firewall already has external IP address
let me know
cheers
