# How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower

## Solution

### **Note** - For Management Server versions R81.20 and higher, see [sk175504](https://support.checkpoint.com/results/sk/sk175504).

**Table of Contents:**

1. Consent flags

2. How consent flags are enabled

3. Flags Decision Table
   - For Security Management Servers / Domain Management Servers / Log Server (all versions)
   - For R77.X / R76SP.X Security Gateways managed by R77.X Security Management Servers
   - For R77.X / R80.X Security Gateways managed by R80.X Security Management Servers
4. How consent flags are modified
5. Related solutions
6. Revision History

### (1) Consent flags

**Note** - For Quantum Spark appliances, refer to the CLI command "`set privacy-settings`" in the [R81.10.X CLI Reference Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Default.htm).

**Important Note:** On a Security Gateway, the value of flags is changed automatically during policy installation - after setting the relevant flags on the Security Management Server / Domain Management Server (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool).

|     |     |
| --- | --- |
| Flag Type | Description |
| " _Allow Upload_" | Allows the upload of data from the Gaia OS to Check Point.<br>Note: This consent flag is available only starting from R77.20 |
| " _Allow Download_" | Allows the download of data from Check Point to the Gaia OS.<br>Note: This consent flag is available only starting from R77.20 |
| " _Upload Core Dumps_" | Allows the upload of core dump files from the Gaia OS to Check Point.<br>Note: This consent flag is available only starting from R80.40 |

**Notes:**

- The consent flags are stored on the Gaia OS in the following places:

|     |     |     |     |
| --- | --- | --- | --- |
| Consent Flags | Where the consent flags are stored | When the consent flags are created | Comments |
| _"Allow Upload"_<br>_"Allow Download"_ | `$FWDIR/conf/objects_5_0.C` | R77.20 and higher:<br>  - On a Security Gateway / Cluster Member:<br>    <br>    _During the first policy installation_.<br>    <br>  - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:<br>    <br>    _During the first "Install Database" operation_. | - This article refers to this file as the "Objects Database".<br>    <br>  - You must not edit this file in any text editor - any settings in this file should be modified only using SmartConsole / SmartDashboard / [Database Tool (GuiDBedit Tool)](https://support.checkpoint.com/results/sk/sk13009) / [dbedit tool](https://support.checkpoint.com/results/sk/skI3301).<br>    <br>  - The consent flags are stored in the "`firewall_properties`" section.<br>    <br>    The consent flags are:<br>    - `:allow_download_content (...)`<br>    - `:allow_upload_content (...)`<br>  - To check the current flag value, run in the Expert mode:<br>    <br>    `grep -n "load_content" $FWDIR/conf/objects_5_0.C`<br>    <br>    Possible values of these flags are:<br>    - `(false)` = upload/download of data is forbidden<br>    - `(true)` = upload/download of data is allowed<br>  - How values of consent flags are checked:<br>    1. Check if the flag value exists in the "Internal Database"<br>       <br>       (in the `$CPDIR/tmp/umis_objects.C` file) and return it<br>       <br>    2. If the flag value does not exist in the "Internal Database",<br>       <br>       then check if the flag value exists in the "Registry"<br>       <br>       (in the `$CPDIR/registry/HKLM_registry.data` file) and return it<br>       <br>    3. If the flag value does not exist in the "Registry",<br>       <br>       then assume "`true`" for that consent flag<br>       <br>       (i.e., allow the upload / download) and return it |
| _"Allow Upload"_<br>_"Allow Download"_ | `$CPDIR/registry/HKLM_registry.data` | R80.10 and higher:<br>  - On a Security Gateway / Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:<br>    <br>    _During the First Time Configuration Wizard_.<br>    <br>R80 / R77.30 / R77.20:<br>  - On a Security Gateway / Cluster Member:<br>    <br>    _During the first policy installation_.<br>    <br>  - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server:<br>    <br>    _During the first "Install Database" operation._ | - This article refers to this file as the "Registry".<br>    <br>  - You must not edit this file in any text editor - any settings in this file should be modified only using the "`ckp_regedit`" command or the "`cpprod_util`" command.<br>    <br>  - The consent flags are stored at:<br>    `/SOFTWARE/CheckPoint/CPshared/6.0/reserved`<br>    the consent flags are:<br>    - `:AllowReceivingDataFromCheckPoint (...)`<br>    - `:AllowSendingDataToCheckPoint (...)`<br>  - To check the current values, run in the Expert mode one of these two commands:<br>    <br>    <br>    - `grep Allow $CPDIR/registry/HKLM_registry.data | grep Data`<br>    - `ckp_regedit -p /SOFTWARE/CheckPoint/CPshared/6.0/reserved | grep CheckPoint`<br>Possible values of these flags are:<br>    - `(0)` = upload/download of data is forbidden<br>    - `(1)` = upload/download of data is allowed<br>  - How values of consent flags are checked:<br>    1. Check if the flag value exists in the "Internal Database"<br>       <br>       (in the `$CPDIR/tmp/umis_objects.C` file) and return it<br>       <br>    2. If the flag value does not exist in the "Internal Database",<br>       <br>       then check if the flag value exists in the "Registry"<br>       <br>       (in the `$CPDIR/registry/HKLM_registry.data` file) and return it<br>       <br>    3. If the flag value does not exist in the "Registry",<br>       <br>       then assume "`true`" for that consent flag<br>       <br>       (i.e., allow the upload / download) and return it |
| _"Allow Upload"_<br>_"Allow Download"_ | `$CPDIR/tmp/umis_objects.C` | R77.20 and higher / R76SP.X (from _Take\_84_ of [R76SP.30 Jumbo Hotfix](https://support.checkpoint.com/results/sk/sk108901), and from _Take\_16_ of [R76SP.50 Jumbo Hotfix](https://support.checkpoint.com/results/sk/sk117633)):<br>  - On a Security Gateway / Cluster Member:<br>    <br>    _During the first policy installation_.<br>    <br>  - On a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Domain Log Server / Log Server / SmartEvent Server:<br>    <br>    _During the first "Install Database" operation_. | - This article refers to this file as the "Internal Database".<br>    <br>    This file is an internal database created by the FWD daemon based on the information from the Registry.<br>    <br>  - You must not edit this file in any text editor.<br>    <br>    This file is updated automatically during _each_ start of the FWD daemon / policy installation / database installation operation.<br>    <br>  - The consent flags are stored in this file in the `DownloadAccess` section.<br>    <br>    The consent flags are:<br>    - `:allow_download_content (...)`<br>    - `:allow_upload_content (...)`<br>  - To check the current values, run in the Expert mode:<br>    <br>    `grep -A 2 DownloadAccess $CPDIR/tmp/umis_objects.C`<br>    <br>    Possible values of these flags are:<br>    - `(false)` = upload/download of data is forbidden<br>    - `(true)` = upload/download of data is allowed<br>  - How values of consent flags are checked:<br>    1. Check if the flag value exists in the "Internal Database"<br>       <br>       (in the `$CPDIR/tmp/umis_objects.C` file) and return it<br>       <br>    2. If the flag value does not exist in the "Internal Database",<br>       <br>       then check if the flag value exists in the "Registry"<br>       <br>       (in the `$CPDIR/registry/HKLM_registry.data` file) and return it<br>       <br>    3. If the flag value does not exist in the "Registry",<br>       <br>       then assume "`true`" for that consent flag<br>       <br>       (i.e., allow the upload / download) and return it |
| _"Upload Core Dumps" | `/config/db/initial`<br>`/config/db/initial_db` |  | **Important** - This consent flag works independently of the "Allow Upload" and "Allow Download" consent flags.<br>  - This article refers to these files as the "Gaia OS Database".<br>    <br>  - You must not edit this file in any text editor - any settings in this file should be modified only using Gaia Portal or Gaia Clish.<br>    <br>  - To check the current flag value, run this command:<br>    - In the Expert mode R80.40 - R81.10:<br>      <br>      `dbget cdm:allow_sending`<br>      <br>      Possible values of this flag are:<br>      - `0` = upload of data is forbidden<br>      - `1` = upload of data is allowed<br>    - In Gaia Clish R80.40 - R81.10:<br>      <br>      `show core-dump crash_data_status` |

- The "`Allow Upload`" consent flag has priority over the "`Sync with User Center`" consent flag (refer to [sk94064](https://support.checkpoint.com/results/sk/sk94064)).

Meaning that if administrator enabled the "`Sync with User Center`" consent flag, but did not enable the "`Allow Upload`" consent flag, then synchronization with User Center will _not_ be performed.

- In R77.X and lower, the consent flags on a Security Gateway are _independent of_ the consent flags on a Security Management Server.

Meaning that, for example, if administrator enabled the "`Allow Upload`" consent flag on an R77.X Security Gateway, but disabled the "`Allow Upload`" consent flag on an R77.X Security Management Server, then the Security Gateway would still be able to upload the data to Check Point.

Starting in R80, the consent flags on an R80.X Security Management Server have priority over the consent flags on an R77.X / R80.X Security Gateway.

For details, refer to "Flags Decision Table" section below.

**Important Notes:**

- To _completely block the upload_ of data from a Security Management Server / Multi-Domain Security Management Server / Domain Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server to Check Point cloud, the administrator must:
1. Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
2. Perform "Install Database" operation
3. Disable the consent flag in the Gaia OS Database
- To _completely block the upload_ of data from a Security Gateway to Check Point cloud, the administrator must:
1. Disable the consent flags in the Objects Database (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool)
2. Perform "Install Policy" operation
3. Disable the consent flag in the Gaia OS Database

### (2) How consent flags are enabled

Consent flags are enabled during the initial installation and database installation / policy installation.

- The Gaia First Time Configuration Wizard creates the consent flags in the following way:

|     |     |
| --- | --- |
| Consent Flag | Description |
| _"Allow Download"_ | The Gaia First Time Configuration Wizard creates the " _Allow Download_" consent flags in the Registry (in the `$CPDIR/registry/HKLM_registry.data` file).<br>This consent flag is enabled by default.<br>  - In R80.40 and higher versions:<br>    <br>    The checkbox is called " _Automatically download Blade Contracts, new software, and other important data (highly recommended)_":<br>    <br>    <br>    <br>  - In R80.30, R80.20, R80.10, and R80 versions:<br>    <br>    The checkbox is called " _Automatically download Blade Contracts and other important data_":<br>    <br>    <br>    <br>  - In R77.30 and R77.20 versions:<br>    <br>    The checkbox is called " _Automatically download Blade Contracts and other important data_":<br>    <br>     |
| _"Allow Upload"_ | - In R80.40 and higher versions:<br>    <br>    The checkbox is called " _Send data to Check Point_":<br>    <br>    <br>    <br>  - In R80.30, R80.20, R80.10, and R80 versions:<br>    <br>    The checkbox is called " _Improve product experience by sending data to Check Point_":<br>    <br>    <br>    <br>  - In R77.30 and R77.20 versions:<br>    <br>    The checkbox is called " _Improve product experience by sending data to Check Point_":<br>    <br>     |
| _"Upload Core Dumps"_ | - In R80.40 and higher versions:<br>    <br>    The Gaia First Time Configuration Wizard creates the " _Upload Core Dumps_" consent flags in the Gaia OS Database (in the `/config/initial*` files).<br>    <br>    The checkbox is called " _Send crash data which might contain personal data to Check Point_":<br>    <br>     |

- The "Install Policy" operation:
  - Creates the "`Allow Upload`" and "`Allow Download`" consent flags in the Objects Database (in the `$FWDIR/conf/objects_5_0.C` file) on all configurations (Security Gateway, Management Server, and so on).

- Creates the "`Allow Upload`" and "`Allow Download`" consent flags in the Registry (in the `$CPDIR/registry/HKLM_registry.data` file) on a Security Gateway.

- Creates the "`Allow Upload`" and "`Allow Download`" consent flags in the Internal Database (in the `$CPDIR/tmp/umis_objects.C` file) on a Security Gateway.
- The "Install Database" operation on a Management Server / Domain Log Server / Log Server / SmartEvent Server object:
  - Creates the "`Allow Upload`" and "`Allow Download`" consent flags in the Internal Database (in the `$CPDIR/tmp/umis_objects.C` file) on a Security Management Server / Multi-Domain Security Management Server / Domain Security Management Server / Multi-Domain Log Server / Domain Log Server / Log Server / SmartEvent Server.
- Gaia Portal or Gaia Clish

In the R80.40 and higher versions, you can control the " _Upload Core Dumps_" consent flag:
  - In Gaia Portal:
    1. In the navigation tree, click **System Management** \> **Core Dumps**.

2. Select or clear the option " **Send crash data which might contain personal data to Check Point**"

3. Click **Apply**.
  - In Gaia Clish:
    1. Run:

`set core-dump send_crash_data {on | off}`

2. Run:

`save config`

During upgrade:

- No change is made to these flags.

- After the upgrade is completed, flags can be modified as described in the "How consent flags are modified" section below.

### (3) Flags Decision Table

The following tables show possible combinations of flags values and whether the Gaia OS can download data from / upload data to Check Point.

**Note:** The ability to download / upload is controlled separately by the corresponding flags. Refer to "How consent flags are modified" section below.

|     |     |     |     |     |
| --- | --- | --- | --- | --- |
| # | Value of<br>flags in<br>Database<br>on R77.X /<br>R80.X<br>Management<br>Server | Value of<br>flags in<br>Registry<br>on R77.X /<br>R80.X<br>Management<br>Server | Ability to<br>download /<br>upload<br>on R77.X /<br>R80.X<br>Management<br>Server | How is this configuration possible? |
| 1 | `false` | `0` | Server is _**not**_ able<br>to download / upload | Both flags were manually disabled in the Registry (either during the First Time Configuration Wizard, or later), and in the Objects Database.<br>Then Install Database operation was performed. |
| 2 | `false` | **`1`** | Server is _**not**_ able<br>to download / upload | Both flags were enabled during First Time Configuration Wizard (default), but were manually disabled in the Objects Database.<br>Then Install Database operation was performed. |
| 3 | **`true`** | `0` | Server is _**able**_<br>to download / upload | Both flags were manually disabled in the Registry, but were enabled in the Objects Database.<br>Then Install Database operation was performed. |
| 4 | **`true`** | **`1`** | Server is _**able**_<br>to download / upload | Both flags were enabled in the Registry (during the First Time Configuration Wizard, or later), and in the Objects Database.<br>Then Install Database operation was performed. |

### (4) How consent flags are modified

**Important Notes:**

- On a Security Gateway, the value of flags is changed automatically during policy installation - after setting the relevant flags on a Security Management Server / Domain Management Server (either using SmartConsole / SmartDashboard, or using Database Tool (GuiDBedit Tool) / dbedit tool).

- On a Multi-Domain Security Management Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Management Servers).

- On a Multi-Domain Log Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Log Servers).

**Instructions:**

Use the following CLI commands:

- In R80.X versions - the "`cpprod_util`" command:

|     |     |     |
| --- | --- | --- |
| Flag | Operation | Syntax |
| " _Allow_<br>_Download_" | Get the<br>current<br>value | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1`<br>Returned values:<br>    - "`1`" \- flag is enabled<br>    - "`0`" \- flag is disabled |
| Enable | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 1 1`<br>Note: This command returns "`0`" on success |
| Disable | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowReceivingDataFromCheckPoint 1 0 0`<br>Note: This command returns "`0`" on success |
| " _Allow_<br>_Upload_" | Get the<br>current<br>value | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_GetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1`<br>Returned values:<br>    - "`1`" \- flag is enabled<br>    - "`0`" \- flag is disabled |
| Enable | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 1 1`<br>Note: This command returns "`0`" on success |
| Disable | `[Expert@HostName:0]# $CPDIR/bin/cpprod_util CPPROD_SetValue CPshared//6.0//reserved AllowSendingDataToCheckPoint 1 0 0`<br>Note: This command returns "`0`" on success |

- In R77.X versions - the "`ckp_regedit`" command:

|     |     |     |
| --- | --- | --- |
| Flag | Operation | Syntax |
| " _Allow_<br>_Download_" | Get the<br>current<br>value | `[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint`<br>Returned values:<br>    - "`[s]1`" \- flag is enabled<br>    - "`[s]0`" \- flag is disabled |
| Enable | `[Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 1` |
| Disable | `[Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowReceivingDataFromCheckPoint 0` |
| " _Allow_<br>_Upload_" | Get the<br>current<br>value | `[Expert@HostName:0]# ckp_regedit SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint`<br>Returned values:<br>    - "`[s]1`" \- flag is enabled<br>    - "`[s]0`" \- flag is disabled |
| Enable | `[Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 1` |
| Disable | `[Expert@HostName:0]# ckp_regedit -a SOFTWARE/CheckPoint/CPshared/6.0/reserved/AllowSendingDataToCheckPoint 0` |

### (5) Related solutions

- [sk94508 - Recommended Internet Access Settings for Automatic Downloads](https://support.checkpoint.com/results/sk/sk94508)
- [sk94509 - Recommended Internet Access Settings for Uploading Data](https://support.checkpoint.com/results/sk/sk94509)
- [sk106251 - How to configure Security Gateway to accept its traffic only to Check Point online services](https://support.checkpoint.com/results/sk/sk106251)
- [sk92739 - The CPinfo utility](https://support.checkpoint.com/results/sk/sk92739)

### (6) Revision History

|     |     |
| --- | --- |
| Date | Description |
| 04 Sep 2025 | Improved formatting.<br>On a Multi-Domain Security Management Server / Multi-Domain Log Server, you must configure the applicable value for the consent flags also in the Global Domain (in addition to the applicable Domain Management Servers / Domain Log Servers). |
| 15 Jan 2022 | Improved formatting. |
| 06 Dec 2022 | Added the information about the "Upload Core Dumps" consent flag (available in R80.40 and higher versions). |
| 27 Aug 2017 | "Allow Upload" / "Allow Download" consent flags are stored in the `$CPDIR/tmp/umis_objects.C` file from _Take\_16_ of [R76SP.50 Jumbo Hotfix](https://support.checkpoint.com/results/sk/sk117633). |
| 18 July 2017 | "Allow Upload" / "Allow Download" consent flags are stored in the `$CPDIR/tmp/umis_objects.C` file from _Take\_84_ of [R76SP.30 Jumbo Hotfix](https://support.checkpoint.com/results/sk/sk108901). |
| 13 July 2017 | Added R76SP.X in relevant places. |
| 31 Aug 2016 | Major updates in the technical explanations. |
| 16 May 2016 | First release of this article.
