sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower
How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower
Solution
Note - For Management Server versions R81.20 and higher, see sk175504.
Table of Contents:
Consent flags
How consent flags are enabled
Flags Decision Table
- For Security Management Servers / Domain Management Servers / Log Server (all versions)
- For R77.X / R76SP.X Security Gateways managed by R77.X Security Management Servers
- For R77.X / R80.X Security Gateways managed by R80.X Security Management Servers
How consent flags are modified
Related solutions
Revision History
(1) Consent flags
Note - For Quantum Spark appliances, refer to the CLI command "set privacy-settings" in the R81.10.X CLI Reference Guide.
Important Note: On a Security Gateway, the value of flags is changed automatically during policy installation - after setting the relevant flags on the Security Management Server / Domain Management Server (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool).
| Flag Type | Description |
| " Allow Upload" | Allows the upload of data from the Gaia OS to Check Point. Note: This consent flag is available only starting from R77.20 |
| " Allow Download" | Allows the download of data from Check Point to the Gaia OS. Note: This consent flag is available only starting from R77.20 |
| " Upload Core Dumps" | Allows the upload of core dump files from the Gaia OS to Check Point. Note: This consent flag is available only starting from R80.40 |
Notes:
- The consent flags are stored on the Gaia OS in the following places:
| Consent Flags | Where the consent flags are stored | When the consent flags are created | Comments |
| "Allow Upload" "Allow Download" |
$FWDIR/conf/objects_5_0.C |
R77.20 and higher: - On a Security Gateway / Cluster Member: During the first policy installation. - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server: During the first "Install Database" operation. |
- This article refers to this file as the "Objects Database". - You must not edit this file in any text editor - any settings in this file should be modified only using SmartConsole / SmartDashboard / Database Tool (GuiDBedit Tool) / dbedit tool. - The consent flags are stored in the " firewall_properties" section.The consent flags are: - :allow_download_content (...)- :allow_upload_content (...)- To check the current flag value, run in the Expert mode: grep -n "load_content" $FWDIR/conf/objects_5_0.CPossible values of these flags are: - (false) = upload/download of data is forbidden- (true) = upload/download of data is allowed- How values of consent flags are checked: 1. Check if the flag value exists in the "Internal Database" (in the $CPDIR/tmp/umis_objects.C file) and return it2. If the flag value does not exist in the "Internal Database", then check if the flag value exists in the "Registry" (in the $CPDIR/registry/HKLM_registry.data file) and return it3. If the flag value does not exist in the "Registry", then assume " true" for that consent flag(i.e., allow the upload / download) and return it |
| "Allow Upload" "Allow Download" |
$CPDIR/registry/HKLM_registry.data |
R80.10 and higher: - On a Security Gateway / Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server: During the First Time Configuration Wizard. R80 / R77.30 / R77.20: - On a Security Gateway / Cluster Member: During the first policy installation. - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server: During the first "Install Database" operation. |
- This article refers to this file as the "Registry". - You must not edit this file in any text editor - any settings in this file should be modified only using the " ckp_regedit" command or the "cpprod_util" command.- The consent flags are stored at: /SOFTWARE/CheckPoint/CPshared/6.0/reservedthe consent flags are: - :AllowReceivingDataFromCheckPoint (...)- :AllowSendingDataToCheckPoint (...)- To check the current values, run in the Expert mode one of these two commands: - `grep Allow $CPDIR/registry/HKLM_registry.data |
| "Allow Upload" "Allow Download" |
$CPDIR/tmp/umis_objects.C |
R77.20 and higher / R76SP.X (from Take_84 of R76SP.30 Jumbo Hotfix, and from Take_16 of R76SP.50 Jumbo Hotfix): - On a Security Gateway / Cluster Member: During the first policy installation. - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Domain Log Server / Log Server / SmartEvent Server: During the first "Install Database" operation. |
- This article refers to this file as the "Internal Database". This file is an internal database created by the FWD daemon based on the information from the Registry. - You must not edit this file in any text editor. This file is updated automatically during each start of the FWD daemon / policy installation / database installation operation. - The consent flags are stored in this file in the DownloadAccess section.The consent flags are: - :allow_download_content (...)- :allow_upload_content (...)- To check the current values, run in the Expert mode: grep -A 2 DownloadAccess $CPDIR/tmp/umis_objects.CPossible values of these flags are: - (false) = upload/download of data is forbidden- (true) = upload/download of data is allowed- How values of consent flags are checked: 1. Check if the flag value exists in the "Internal Database" (in the $CPDIR/tmp/umis_objects.C file) and return it2. If the flag value does not exist in the "Internal Database", then check if the flag value exists in the "Registry" (in the $CPDIR/registry/HKLM_registry.data file) and return it3. If the flag value does not exist in the "Registry", then assume " true" for that consent flag(i.e., allow the upload / download) and return it |
| _"Upload Core Dumps" | /config/db/initial/config/db/initial_db |
Important - This consent flag works independently of the "Allow Upload" and "Allow Download" consent flags. - This article refers to these files as the "Gaia OS Database". - You must not edit this file in any text editor - any settings in this file should be modified only using Gaia Portal or Gaia Clish. - To check the current flag value, run this command: - In the Expert mode R80.40 - R81.10: dbget cdm:allow_sendingPossible values of this flag are: - 0 = upload of data is forbidden- 1 = upload of data is allowed- In Gaia Clish R80.40 - R81.10: show core-dump crash_data_status |
- The "
Allow Upload" consent flag has priority over the "Sync with User Center" consent flag (refer to sk94064).
Meaning that if administrator enabled the "Sync with User Center" consent flag, but did not enable the "Allow Upload" consent flag, then synchronization with User Center will not be performed.
- In R77.X and lower, the consent flags on a Security Gateway are independent of the consent flags on a Security Management Server.
Meaning that, for example, if administrator enabled the "Allow Upload" consent flag on an R77.X Security Gateway, but disabled the "Allow Upload" consent flag on an R77.X Security Management Server, then the Security Gateway would still be able to upload the data to Check Point.
Starting in R80, the consent flags on an R80.X Security Management Server have priority over the consent flags on an R77.X / R80.X Security Gateway.
For details, refer to "Flags Decision Table" section below.
Important Notes:
- To completely block the upload of data from a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server to Check Point cloud, the administrator must:
- Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
- Perform "Install Database" operation
- Disable the consent flag in the Gaia OS Database
- To completely block the upload of data from a Security Gateway to Check Point cloud, the administrator must:
- Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
- Perform "Install Policy" operation
- Disable the consent flag in the Gaia OS Database
(2) How consent flags are enabled
Consent flags are enabled during the initial installation and database installation / policy installation.
- The Gaia First Time Configuration Wizard creates the consent flags in the following way:
| Consent Flag | Description |
| "Allow Download" | The Gaia First Time Configuration Wizard creates the " Allow Download" consent flags in the Registry (in the $CPDIR/registry/HKLM_registry.data file).This consent flag is enabled by default. - In R80.40 and higher versions: The checkbox is called " Automatically download Blade Contracts, new software, and other important data (highly recommended)": - In R80.30, R80.20, R80.10, and R80 versions: The checkbox is called " Automatically download Blade Contracts and other important data": - In R77.30 and R77.20 versions: The checkbox is called " Automatically download Blade Contracts and other important data": |
| "Allow Upload" | - In R80.40 and higher versions: The checkbox is called " Send data to Check Point": - In R80.30, R80.20, R80.10, and R80 versions: The checkbox is called " Improve product experience by sending data to Check Point": - In R77.30 and R77.20 versions: The checkbox is called " Improve product experience by sending data to Check Point": |
| "Upload Core Dumps" | - In R80.40 and higher versions: The Gaia First Time Configuration Wizard creates the " Upload Core Dumps" consent flags in the Gaia OS Database (in the /config/initial* files).The checkbox is called " Send crash data which might contain personal data to Check Point": |
The "Install Policy" operation:
- Creates the "
Allow Upload" and "Allow Download" consent flags in the Objects Database (in the$FWDIR/conf/objects_5_0.Cfile) on all configurations (Security Gateway, Management Server, and so on).
- Creates the "
Creates the "
Allow Upload" and "Allow Download" consent flags in the Registry (in the$CPDIR/registry/HKLM_registry.datafile) on a Security Gateway.Creates the "
Allow Upload" and "Allow Download" consent flags in the Internal Database (in the$CPDIR/tmp/umis_objects.Cfile) on a Security Gateway.The "Install Database" operation on a Management Server / Domain Log Server / Log Server / SmartEvent Server object:
- Creates the "
Allow Upload" and "Allow Download" consent flags in the Internal Database (in the$CPDIR/tmp/umis_objects.Cfile) on a Security Management Server / Multi-Domain Security Management Server / Domain Security Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server.
- Creates the "
Gaia Portal or Gaia Clish
In the R80.40 and higher versions, you can control the " Upload Core Dumps" consent flag:
- In Gaia Portal:
- In the navigation tree, click System Management > Core Dumps.
Select or clear the option " Send crash data which might contain personal data to Check Point"
Click Apply.
- In Gaia Clish:
- Run:
set core-dump send_crash_data {on | off}
- Run:
save config
During upgrade:
No change is made to these flags.
After the upgrade is completed, flags can be modified as described in the "How consent flags are modified" section below.
(3) Flags Decision Table
The following tables show possible combinations of flags values and whether the Gaia OS can download data from / upload data to Check Point.
Note: The ability to download / upload is controlled separately by the corresponding flags. Refer to "How consent flags are modified" section below.
| # | Value of flags in Database on R77.X / R80.X Management Server |
Value of flags in Registry on R77.X / R80.X Management Server |
Ability to download / upload on R77.X / R80.X Management Server |
How is this configuration possible? |
| 1 | false |
0 |
Server is not able to download / upload |
Both flags were manually disabled in the Registry (either during the First Time Configuration Wizard, or later), and in the Objects Database. Then Install Database operation was performed. |
| 2 | false |
1 |
Server is not able to download / upload |
Both flags were enabled during First Time Configuration Wizard (default), but were manually disabled in the Objects Database. Then Install Database operation was performed. |
| 3 | true |
0 |
Server is able to download / upload |
Both flags were manually disabled in the Registry, but were enabled in the Objects Database. Then Install Database operation was performed. |
| 4 | true |
1 |
Server is able to download / upload |
Both flags were enabled in the Registry (during the First Time Configuration Wizard, or later), and in the Objects Database. Then Install Database operation was performed. |
(4) How consent flags are modified
Important Notes:
On a Security Gateway, the value of flags is changed automatically during policy installation - after setting the relevant flags on a Security Management Server / Domain Management Server (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool).
On a Multi-Domain Security Management Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Management Servers).
On a Multi-Domain Log Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Log Servers).
Instructions:
Use the following CLI commands:
- In R80.X versions - the "
cpprod_util" command:
| Flag | Operation | Syntax |
| " Allow Download" |
Get the current value |
[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1Returned values: - " 1" - flag is enabled- " 0" - flag is disabled |
| Enable | [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 1 1Note: This command returns " 0" on success |
|
| Disable | [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 0 0Note: This command returns " 0" on success |
|
| " Allow Upload" |
Get the current value |
[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1Returned values: - " 1" - flag is enabled- " 0" - flag is disabled |
| Enable | [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 1 1Note: This command returns " 0" on success |
|
| Disable | [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 0 0Note: This command returns " 0" on success |
- In R77.X versions - the "
ckp_regedit" command:
| Flag | Operation | Syntax |
| " Allow Download" |
Get the current value |
[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPointReturned values: - " [s]1" - flag is enabled- " [s]0" - flag is disabled |
| Enable | [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 1 |
|
| Disable | [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 0 |
|
| " Allow Upload" |
Get the current value |
[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPointReturned values: - " [s]1" - flag is enabled- " [s]0" - flag is disabled |
| Enable | [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 1 |
|
| Disable | [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 0 |
(5) Related solutions
- sk94508 - Recommended Internet Access Settings for Automatic Downloads
- sk94509 - Recommended Internet Access Settings for Uploading Data
- sk106251 - How to configure Security Gateway to accept its traffic only to Check Point online services
- sk92739 - The CPinfo utility
(6) Revision History
| Date | Description |
| 04 Sep 2025 | Improved formatting. On a Multi-Domain Security Management Server / Multi-Domain Log Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Management Servers / Domain Log Servers). |
| 15 Jan 2022 | Improved formatting. |
| 06 Dec 2022 | Added the information about the "Upload Core Dumps" consent flag (available in R80.40 and higher versions). |
| 27 Aug 2017 | "Allow Upload" / "Allow Download" consent flags are stored in the $CPDIR/tmp/umis_objects.C file from Take_16 of R76SP.50 Jumbo Hotfix. |
| 18 July 2017 | "Allow Upload" / "Allow Download" consent flags are stored in the $CPDIR/tmp/umis_objects.C file from Take_84 of R76SP.30 Jumbo Hotfix. |
| 13 July 2017 | Added R76SP.X in relevant places. |
| 31 Aug 2016 | Major updates in the technical explanations. |
| 16 May 2016 | First release of this article. |