- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi All,
Recently, i have done an standalone firewall upgrade from R77.10 to R81.10 with this path (R77.10 , R80.30 , R81.10)
All upgrade process done successfully.
But unfortunately, i get the error when I try to install the Threat Prevention policy to the firewall after installed firewall policy successfully.
I did check on the license and the firewall blade itself, all is on as expected.
Meanwhile, i also did try to search on SK but no SK related to this error.
Hence, I appreciate if anyone can guide me on solving this issue. Thank you.
Please note that R81 and above do not officially support that type of appliance anymore so that might be your issue here.
You may try R80.40 which is the last version supported on that hardware.
@Alex- is correct, that appliance cant run R81. Can you just try R80.40 and update us?
Andy
What threat prevention blades are you using? If you are doing automated feature, maybe disable it and try just with IPS blade.
Hi the_rock,
The current ThreatPrevention blade using is only IPS and currently using custom policy shown as below:
Meanwhile when i do cpstart after cpstop, i get these errors:
As i check some link, they mentioned something like Dynamic ID but i don't think my firewall using that.
Below is the link i mentioned (need to translate into english if needed):
How To Troubleshoot Policy Installation Issues - Checkpoint - Network & Security (coskunsanli.net)
Yea, that may need some debugging, for sure. Just as an easy test, uncheck ips, push policy, recheck and try again, see what happens.
Just tested the simple steps:
1. uncheck IPS from the firewall
2. publish and install policy to the firewall
3. re-check back the IPS blade from the firewall
4. publish and install policy to the firewall
5. install Threat Prevention policy to the firewall, but failed with same error
I would get in touch with TAC and see what they say. I never encountered that exact issue before, so not 100% sure whay it would happen, sorry. I dont want to give you steps that could cause major problems, specially given the fact its standalone config.
Okay thanks a lot. @the_rock . I will wait for your update and I will try to check out other way if possible.
Hi @the_rock ,
Currently i have no findings on my site:
So the detail story about my upgrade is like this:
1. I do inplace upgrade from77.30 to R80.30 to R81.10 on same vm machine. once done upgrade, I use migrate server export and import the database into another fresh R81.10 physical 4800 appliance.
2. when i try install threat prevention policy on the 4800 appliance got that error, but it works fine when i do same things on the VM.
3. For now, i try export the VM database again with migrate export. import into the physical appliance to do same thing again.
4. If not work again, will try to do offline inplace upgrade from R77.30 to R81.10 on the appliance.
I did try to factory default and do migrate import again on the Check Point 4800 appliance, but same issue still persist.
Hence, i will do in-place upgrade on the checkpoint appliance start from R77.30.
Will update at here if have any.
Please note that R81 and above do not officially support that type of appliance anymore so that might be your issue here.
You may try R80.40 which is the last version supported on that hardware.
okay. Sure. I will update to you guys once i tested.
Thanks guys.
After i tested the upgrade from R77.30 to R80.40 and import the database to the 4800 appliance, all was working fine (able to install firewall policy and IPS policy). Meanwhile (FYI), I did test to do offline upgrade from R80.40 to R81.10 on the 4800 appliance and failed as R81.10 doesn't support 4800 Check Point appliance.
Happy to hear that.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY