sk111080 - How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower

How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower

Solution

Note - For Management Server versions R81.20 and higher, see sk175504.

Table of Contents:

  1. Consent flags

  2. How consent flags are enabled

  3. Flags Decision Table

    • For Security Management Servers / Domain Management Servers / Log Server (all versions)
    • For R77.X / R76SP.X Security Gateways managed by R77.X Security Management Servers
    • For R77.X / R80.X Security Gateways managed by R80.X Security Management Servers
  4. How consent flags are modified

  5. Related solutions

  6. Revision History

(1) Consent flags

Note - For Quantum Spark appliances, refer to the CLI command "set privacy-settings" in the R81.10.X CLI Reference Guide.

Important Note: On a Security Gateway, the value of flags is changed automatically during policy installation - after setting the relevant flags on the Security Management Server / Domain Management Server (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool).

Flag Type Description
" Allow Upload" Allows the upload of data from the Gaia OS to Check Point.
Note: This consent flag is available only starting from R77.20
" Allow Download" Allows the download of data from Check Point to the Gaia OS.
Note: This consent flag is available only starting from R77.20
" Upload Core Dumps" Allows the upload of core dump files from the Gaia OS to Check Point.
Note: This consent flag is available only starting from R80.40

Notes:

Consent Flags Where the consent flags are stored When the consent flags are created Comments
"Allow Upload"
"Allow Download"
$FWDIR/conf/objects_5_0.C R77.20 and higher:
- On a Security Gateway / Cluster Member:

During the first policy installation.

- On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:

During the first "Install Database" operation.
- This article refers to this file as the "Objects Database".

- You must not edit this file in any text editor - any settings in this file should be modified only using SmartConsole / SmartDashboard / Database Tool (GuiDBedit Tool) / dbedit tool.

- The consent flags are stored in the "firewall_properties" section.

The consent flags are:
- :allow_download_content (...)
- :allow_upload_content (...)
- To check the current flag value, run in the Expert mode:

grep -n "load_content" $FWDIR/conf/objects_5_0.C

Possible values of these flags are:
- (false) = upload/download of data is forbidden
- (true) = upload/download of data is allowed
- How values of consent flags are checked:
1. Check if the flag value exists in the "Internal Database"

(in the $CPDIR/tmp/umis_objects.C file) and return it

2. If the flag value does not exist in the "Internal Database",

then check if the flag value exists in the "Registry"

(in the $CPDIR/registry/HKLM_registry.data file) and return it

3. If the flag value does not exist in the "Registry",

then assume "true" for that consent flag

(i.e., allow the upload / download) and return it
"Allow Upload"
"Allow Download"
$CPDIR/registry/HKLM_registry.data R80.10 and higher:
- On a Security Gateway / Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:

During the First Time Configuration Wizard.

R80 / R77.30 / R77.20:
- On a Security Gateway / Cluster Member:

During the first policy installation.

- On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:

During the first "Install Database" operation.
- This article refers to this file as the "Registry".

- You must not edit this file in any text editor - any settings in this file should be modified only using the "ckp_regedit" command or the "cpprod_util" command.

- The consent flags are stored at:
/SOFTWARE/CheckPoint/CPshared/6.0/reserved
the consent flags are:
- :AllowReceivingDataFromCheckPoint (...)
- :AllowSendingDataToCheckPoint (...)
- To check the current values, run in the Expert mode one of these two commands:


- `grep Allow $CPDIR/registry/HKLM_registry.data
"Allow Upload"
"Allow Download"
$CPDIR/tmp/umis_objects.C R77.20 and higher / R76SP.X (from Take_84 of R76SP.30 Jumbo Hotfix, and from Take_16 of R76SP.50 Jumbo Hotfix):
- On a Security Gateway / Cluster Member:

During the first policy installation.

- On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Domain Log Server / Log Server / SmartEvent Server:

During the first "Install Database" operation.
- This article refers to this file as the "Internal Database".

This file is an internal database created by the FWD daemon based on the information from the Registry.

- You must not edit this file in any text editor.

This file is updated automatically during each start of the FWD daemon / policy installation / database installation operation.

- The consent flags are stored in this file in the DownloadAccess section.

The consent flags are:
- :allow_download_content (...)
- :allow_upload_content (...)
- To check the current values, run in the Expert mode:

grep -A 2 DownloadAccess $CPDIR/tmp/umis_objects.C

Possible values of these flags are:
- (false) = upload/download of data is forbidden
- (true) = upload/download of data is allowed
- How values of consent flags are checked:
1. Check if the flag value exists in the "Internal Database"

(in the $CPDIR/tmp/umis_objects.C file) and return it

2. If the flag value does not exist in the "Internal Database",

then check if the flag value exists in the "Registry"

(in the $CPDIR/registry/HKLM_registry.data file) and return it

3. If the flag value does not exist in the "Registry",

then assume "true" for that consent flag

(i.e., allow the upload / download) and return it
_"Upload Core Dumps" /config/db/initial
/config/db/initial_db
Important - This consent flag works independently of the "Allow Upload" and "Allow Download" consent flags.
- This article refers to these files as the "Gaia OS Database".

- You must not edit this file in any text editor - any settings in this file should be modified only using Gaia Portal or Gaia Clish.

- To check the current flag value, run this command:
- In the Expert mode R80.40 - R81.10:

dbget cdm:allow_sending

Possible values of this flag are:
- 0 = upload of data is forbidden
- 1 = upload of data is allowed
- In Gaia Clish R80.40 - R81.10:

show core-dump crash_data_status

Meaning that if administrator enabled the "Sync with User Center" consent flag, but did not enable the "Allow Upload" consent flag, then synchronization with User Center will not be performed.

Meaning that, for example, if administrator enabled the "Allow Upload" consent flag on an R77.X Security Gateway, but disabled the "Allow Upload" consent flag on an R77.X Security Management Server, then the Security Gateway would still be able to upload the data to Check Point.

Starting in R80, the consent flags on an R80.X Security Management Server have priority over the consent flags on an R77.X / R80.X Security Gateway.

For details, refer to "Flags Decision Table" section below.

Important Notes:

  1. Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
  2. Perform "Install Database" operation
  3. Disable the consent flag in the Gaia OS Database
  1. Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
  2. Perform "Install Policy" operation
  3. Disable the consent flag in the Gaia OS Database

(2) How consent flags are enabled

Consent flags are enabled during the initial installation and database installation / policy installation.

Consent Flag Description
"Allow Download" The Gaia First Time Configuration Wizard creates the " Allow Download" consent flags in the Registry (in the $CPDIR/registry/HKLM_registry.data file).
This consent flag is enabled by default.
- In R80.40 and higher versions:

The checkbox is called " Automatically download Blade Contracts, new software, and other important data (highly recommended)":



- In R80.30, R80.20, R80.10, and R80 versions:

The checkbox is called " Automatically download Blade Contracts and other important data":



- In R77.30 and R77.20 versions:

The checkbox is called " Automatically download Blade Contracts and other important data":

"Allow Upload" - In R80.40 and higher versions:

The checkbox is called " Send data to Check Point":



- In R80.30, R80.20, R80.10, and R80 versions:

The checkbox is called " Improve product experience by sending data to Check Point":



- In R77.30 and R77.20 versions:

The checkbox is called " Improve product experience by sending data to Check Point":

"Upload Core Dumps" - In R80.40 and higher versions:

The Gaia First Time Configuration Wizard creates the " Upload Core Dumps" consent flags in the Gaia OS Database (in the /config/initial* files).

The checkbox is called " Send crash data which might contain personal data to Check Point":

In the R80.40 and higher versions, you can control the " Upload Core Dumps" consent flag:

  1. Select or clear the option " Send crash data which might contain personal data to Check Point"

  2. Click Apply.

set core-dump send_crash_data {on | off}

  1. Run:

save config

During upgrade:

(3) Flags Decision Table

The following tables show possible combinations of flags values and whether the Gaia OS can download data from / upload data to Check Point.

Note: The ability to download / upload is controlled separately by the corresponding flags. Refer to "How consent flags are modified" section below.

# Value of
flags in
Database
on R77.X /
R80.X
Management
Server
Value of
flags in
Registry
on R77.X /
R80.X
Management
Server
Ability to
download /
upload
on R77.X /
R80.X
Management
Server
How is this configuration possible?
1 false 0 Server is not able
to download / upload
Both flags were manually disabled in the Registry (either during the First Time Configuration Wizard, or later), and in the Objects Database.
Then Install Database operation was performed.
2 false 1 Server is not able
to download / upload
Both flags were enabled during First Time Configuration Wizard (default), but were manually disabled in the Objects Database.
Then Install Database operation was performed.
3 true 0 Server is able
to download / upload
Both flags were manually disabled in the Registry, but were enabled in the Objects Database.
Then Install Database operation was performed.
4 true 1 Server is able
to download / upload
Both flags were enabled in the Registry (during the First Time Configuration Wizard, or later), and in the Objects Database.
Then Install Database operation was performed.

(4) How consent flags are modified

Important Notes:

Instructions:

Use the following CLI commands:

Flag Operation Syntax
" Allow
Download"
Get the
current
value
[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1
Returned values:
- "1" - flag is enabled
- "0" - flag is disabled
Enable [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 1 1
Note: This command returns "0" on success
Disable [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 0 0
Note: This command returns "0" on success
" Allow
Upload"
Get the
current
value
[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1
Returned values:
- "1" - flag is enabled
- "0" - flag is disabled
Enable [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 1 1
Note: This command returns "0" on success
Disable [Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 0 0
Note: This command returns "0" on success
Flag Operation Syntax
" Allow
Download"
Get the
current
value
[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint
Returned values:
- "[s]1" - flag is enabled
- "[s]0" - flag is disabled
Enable [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 1
Disable [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 0
" Allow
Upload"
Get the
current
value
[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint
Returned values:
- "[s]1" - flag is enabled
- "[s]0" - flag is disabled
Enable [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 1
Disable [Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 0

(5) Related solutions

(6) Revision History

Date Description
04 Sep 2025 Improved formatting.
On a Multi-Domain Security Management Server / Multi-Domain Log Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Management Servers / Domain Log Servers).
15 Jan 2022 Improved formatting.
06 Dec 2022 Added the information about the "Upload Core Dumps" consent flag (available in R80.40 and higher versions).
27 Aug 2017 "Allow Upload" / "Allow Download" consent flags are stored in the $CPDIR/tmp/umis_objects.C file from Take_16 of R76SP.50 Jumbo Hotfix.
18 July 2017 "Allow Upload" / "Allow Download" consent flags are stored in the $CPDIR/tmp/umis_objects.C file from Take_84 of R76SP.30 Jumbo Hotfix.
13 July 2017 Added R76SP.X in relevant places.
31 Aug 2016 Major updates in the technical explanations.
16 May 2016 First release of this article.