Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Thomas_Eichelbu
Advisor
Advisor

ZPH Status Unknown in SmartConsole ...

Hello dear Check Pointers!

as hunting red dots i my daily business iam stumbling over this nice red dot in the Zero Phishing Blade, ZPH.



ZPH_Reddot.PNG

what can it be?
i know ZPH is working correctly.
we tested it successfully with the phishing demos provided by Check Point.
Phishing site are blocked, and login fields are correctly inspected .. all fine. but a red dot is shown in SmartConsole 😞
We do not use the autonomous Threat Prevention Profile, all manually.

i have a nice FQDN set for the Usercheck page of ZPH.
Certificate valid and installed, all resolvable by the GW.
i checked https://support.checkpoint.com/results/sk/sk177023 all fine so far.

just interesting is the thing with the trailing dot after the FQDN (sk177023)  ... really?
who did made a "." after the FQDN?
i dont see any difference if the trailing dot is added yes or not.
can anybody answer this?

in the logs i get this error:
/opt/CPUserCheckPortal/log/zph/error_log
[Fri Jun 06 09:56:22.813619 2025] [mpm_prefork:notice] [pid 10608:tid 10608] AH00169: caught SIGTERM, shutting down
[Fri Jun 06 09:56:25.938708 2025] [core:error] [pid 15668:tid 15668] (EAI 2)Name or service not known: AH00547: Could not resolve host name *:-1 -- ignoring!
AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using A.B.C.D. Set the 'ServerName' directive globally to suppress this message
[Fri Jun 06 09:56:25.981056 2025] [mpm_prefork:notice] [pid 15668:tid 15668] AH00163: CPWS/2.4.61 (Unix) configured -- resuming normal operations
[Fri Jun 06 09:56:25.981135 2025] [core:notice] [pid 15668:tid 15668] AH00094: Command line: '/opt/CPshrd-R81.20/web/Apache/bin/httpd -D FOREGROUND -f /opt/CPshrd-R81.20/conf/multiportal/httpd-conf/ZeroPhishing/httpd.conf -D PORTAL_NAME_ZeroPhishing'


any idea so far?
who can shine with success and present a green dot here?

best regards


 

0 Kudos
8 Replies
Tal_Paz-Fridman
Employee
Employee

I have forwarded your post to relevant owner in R&D to see if he has an insights.

In the meantime consider opening a ticket with Check Point Support (TAC).

0 Kudos
the_rock
Legend
Legend

I had that issue in the lab while ago, but cant, for the life of me now, remember how I fixed it. Let me check to see if I can find it in my notes.

Andy

0 Kudos
the_rock
Legend
Legend

Okay...found how I fixed it. 

steps that worked for me in the lab:

-uncheck zero phising blade

-save, push policy

-recheck, save, push policy

-install database on mgmt

-reboot gateway (this HAD TO be done in my case)

-afrer reboot, all was green

Andy

0 Kudos
the_rock
Legend
Legend

Hey Thomas,

Any luck with this?

Andy

0 Kudos
Thomas_Eichelbu
Advisor
Advisor

Hello, 

well i was quite lazy over the weekend 🙂
i will try it asap, perhaps i´ll do it today to run this procedure as u described...

hello-it-have-you-tried.gif

i´ll keep you posted!

best regards

the_rock
Legend
Legend

Sounds good 🙂

0 Kudos
Thomas_Eichelbu
Advisor
Advisor

So hello ... 

just tried it ... 
but made no difference, still the error "Unknown Status" ... 
i rebooted both cluster members.

what you have in "cpstat zph" 

[Expert@XXXXXXX:0:ACTIVE]# cpstat zph

Status code: 0
Status short description: OK
Status long description: Zero Phishing is up and running


interesting is also .. .the status "Zero Phishing Status" is marked with a red dot. but in the status above all is shown as green.
so should i be woried about this red dot or not?

best regards

 

0 Kudos
the_rock
Legend
Legend

Hm, really odd...do you see the same if you log into actual sv monitor from c/programfiles(x86)/checkpoint/program/R8x.xx?

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events