Show
31 - 40 of 35,568 discussions
Sorted by:

Fresh installed R82 gateway (Jumbo take 36, ElasticXL, VSNext)
Following message after login to console:
Warning! Firewall / SecureXL / HyperFlow boot configuration was not completed correctly. ...
-
The SK is now available: https://support.checkpoint.com/results/sk/sk181917
- Have you seen https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuid...
- @Lesley Yes, I saw it, sk181917 is mentioned in this but as I wrote not available. We cha...
- I would definitely verify with TAC. I also searched for that sk, your link is the only thing that c...
- Hi, this is an internal SK, please raise a TAC case for investigation.
- Do you use factory image or one you have downloaded and put the box with isomorphic? Try not to u...
- We used isomorphic.
- Sorry only option I see for now is tac case especially if the sk is internal.
- Emma mentioned the sk is internal, maybe ask TAC about it?
3 weeks ago
16
Replies
833
Views

I currently hold the CCSA certification and am planning to pursue the CCME certification next, followed by the CCSE. I would like to confirm if it is possible to obtain the CCME certification before ...
-
The official answer is in here: https://support.checkpoint.com/results/sk/sk163417 I recommend ...
-
No, the CCME does not extend the validity of your CCSA. Only core certification progression (e.g.,...
- Im positive the best person to confirm would be @Jason_Tugwell . Andy
- From what I know though, yes, you can take CCME before CCSE and all your existing certs would still...
- Always check the SK article. That is important. https://support.checkpoint.com/results/sk/sk16...
- Thanks @Don_Paterson , Can you please confirm, I will do CCME before CCSE. And before th...
- Thank you so much @Don_Paterson for the brief explanation. One more question, suppose ...
- Thnaks @the_rock And before the expiration of CCME, if I do CCSE. Will it activate al...
2025-07-27
09:33 AM
20
Replies
1173
Views

There are issues with newer SmartConsole versions R81.20/R82 where SmartConsole Extensions no longer execute properly when calling the following function "request-commit". Is this a bug i...
-
Hi @HeikoAnkenbrand , Fix in on the way for R81.20, and is expected on the next SmartCon...
- Yup, I got the same results.
- I have sent this to the relevant Group Manager in R&D and Release Manager. I will update when...
- Any news in this case?
- The error only occurs with the latest Smart Console versions. I don’t have any issues with the ol...
- An issue description would be helpful. My CP Services Check SmartConsole extension doesn't show an...
- I've identified a problem in R81.20 build 670 with extensions that use large HTML files, and I'm wo...
- Hi @Omer_Ran, Thanks for the info. I'll test it in my LAB environment and get back to ...
- Hi @Omer_Ran, Thanks for testing this so quickly. Will it be fixed in the next SmartConsole...
2 weeks ago
10
Replies
724
Views

Overview
ElasticXL is a new cluster technology that enables simplified operation with a single management object with automatic configuration and software synchronisation between all clus...
-
Hi @patones1, The P letter stands for Pivot. This means this member get all the traffic and ...
-
Though support is in the plans, it is not a currently supported configuration to mix hardware types...
-
There will be a presentation in Vienna at the CPX: Wednesday 15:20-16:20 -->&...
- On ElasticXL is it possible to configure different (and compatible) models as Cluster? If yes could...
- yes, but I think its more great and cool if we can edit another interface to be a SYNC interface
- Hi I try this elasticXL with 5800 device, 2 box 5800 already reimage with r82 version and running...
- Hi Peter, Thank you, I think this success: [Global] GW1-s01-01> cphaprob stat Cluster Mode: ...
- Hello @Ricki_Juntak , you find some hints on ElasticXL in this guide here. Essentially:...

Hello,
We have just received a new paar of gateways 9100. First at all: the way of connection via console provided in the video tutorial is terrible - send a link via Whatsap...
-
Download your own ISO and install that one. I think something is up with de factory ISO. See also:&...
- Thats odd...my colleague and I set 4 of them up the other day and it was admin / admin, even said t...
- Indeed should be admin / admin, quick start guide attached.
- I think you need to run the first-time setup wizard from the MGMT GUI first (admin/admin) before CL...
- Technically you dont, it works even before that. Andy
- I can't run the first-time setup wizard because I'm already being asked for the cred...
- Are you able to try factory reset it and test? Andy
- I reset already - it didn't help
- I guess the only thing left then is what @Lesley suggested. Other than that, you can call...
2025-08-01
04:12 AM
18
Replies
1043
Views

Hi, What does this indicate? It's not very clear to me do we need to make any changes? Thanks a lot! Accept Templates : disabled by Firewall Layer Policy Security disables template offloads fro...
-
After disabling the rule and re-installing the policy, check fwaccel stat again to see if there is ...
-
@RemoteUser even if fwaccel stat reports "Accept templates: enabled", the "Accelera...
- Did you read sk32578: SecureXL Mechanism ?
- Remove rule #xxxx if it is not needed, or move it all the way down in rulebase. Most of the ...
- What is the rule# relative to the policy size? Commonly this would be due to a specific objects l...
- Hi Yes, but what is mean disables template offloads from rule #xxxx? It's affects some...
- Hey bro, Make sure this is enabled (what I attached) Andy
- Also, can you send output of below? Andy [Expert@R82:0]# fwaccel templates The templates table...
- I would say if anyone on this planet can explain this perfectly, its @Timothy_Hall ...
2025-07-09
07:35 AM
20
Replies
1561
Views

Hi Team, We are using 9100 with ClusterXL Activity and standby configuration. R81.20 with JHF 99, along with Mobile access vpn with SNX. we are facing issue with user-based policy. raised the TAC t...
-
LDAP fetch timer can be changed: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP...
- https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clien...
- Maybe start with the how to guide and try to follow it. If you get stuck ask for help here. I can...
- thnks, i have flow the admin guide and configure the identity collector but when i r...
- This is a normal message that shows on all my setups with working IDC. Are there any specific issue...
- Some time we are not getting logs for the users, also when i run the same cli command on another st...
- screenshots look good. What version IDC you use? With reduce sync, do you mean if you change someth...
- Thanks for update, IDC version 82.126.0000, if you see the output below , i have highlighted ...
- Hi, I have gone through recent Americas Deep Dive: Identity Awareness Best Practices , Is it...
2025-07-28
01:07 AM
12
Replies
1124
Views

Hi Everyone, I am just curious about a network change in our environment. Currently we are using Cisco Umbrella as our DNS server and security layer for all external/public requests. Do you think ...
-
In terms of actually preventing potential threats via DNS, I'd say both are similar in this regard....
-
Our DNS Security is done inline whereas Umbrella is the DNS server (and does security functions on ...
- Check Point DNS Security is handled through Anti-Bot and Anti-Virus Blades. There is some addition...
- In larger environments, it's typical to have internal DNS servers (can be Active Directory, BIND, o...
- Thank You for your response and Yes, I am exploring Check Point DNS security but I just wanted to d...
- This clears up a lot of thing. Thank You. I understand, If I want to replace Umbrella then I ...
- For what its worth, I know few customers who use below public dns servers and so far, I heard no co...
- Yes, I agree quad9 is better among others.
- Microsoft and Google will probably be the domains for which DC along with Public DNS will be used t...
2025-06-02
09:07 AM
23
Replies
2272
Views

Can anyone help me to resolve the issue IKEv2 Phase2 is not getting up and configuration seems to be fine from both the sides Version :R81.20
-
Hey everyoone, Just to update on this, had zoom remote with @MaheshCheck and below are ...
- We need way more info in order to help properly. First of all, what is the other side? Do e...
- Yes ,its S2S VPN Firewall version is R81.20 Jumbo Hotfix Take 84 When we select single host...
- Domain based ,Star,IKev2 Cisco is peer
- If its combo of hosts/subnets. then please try "per gateway" If that fails, run simple vpn debug....
- There are so manu Ike fiels so which one i have to take attached screenshot for reference
- I would review whatever is today's date. Honestly, I feel your best bet is to call TAC, do remote s...
- Hey Mahesh, Im sure you are sleeping as Im writting this, but in case tunnel still does not work ...
2024-12-17
05:58 AM
38
Replies
11909
Views

Anyone else get this display issue where the results won't actually show? I think I've had this issue since R80.00 EA and across multiple computers / installs. It happens randomly and on both Logs an...
- Tags:
- smartconsole
-
I'm on SmartConsole 82.0.9800.1055 and I haven't seen the issue crop up so I think they got it fixe...
- Still an issue on R82. This even happens when I remote desktop into other computers:
- Hello, Very good news from TAC, they found the bug and they provided a custom build of SmartConsol...
- I can also confirm thats the case, I see the same in my R82 lab. Tried rebooting, tested many rules...
- Hi, Im on smartconsole R82 Build 1056, but still does not dsiplay the log, even if i go to L...
- In Standalone machine Log Indexing is not enabled by default. Edit the Standalone object an...
- @rroihans please open a separate discussion.
- Yes it's indexing. Mgmt R81.20 Jumbo Hotfix Take 53 SmartConsole 81.20.9700.653
2022-11-11
01:44 PM
44
Replies
10073
Views