sk178886 - After replacing Host and Network objects with an Updatable object in the Access Control rule base, Security Gateway drops the traffic

After replacing Host and Network objects with an Updatable object in the Access Control rule base, Security Gateway drops the traffic

Product

Application Control
Version R80.40 (EOS), R81 (EOS), R81.10 (EOS)
OS Gaia
Last Modified 2026-01-28

Symptoms

One of the updatable objects was downloaded incorrectly (see sk178886).

Cause

The Management Server sends an invalid Updatable Object to the Security Gateway.

In the $CPDIR/local.updatable_obj file, the value of the ":name ()" parameter in the new Updatable Object is empty.

Example:

Solution

This problem was fixed. The fix is included in:

If you experience this issue after the upgrade, do this procedure on the Management Server:

  1. Take the backup of your Management Server database:
    • For information about Gaia Backup and Gaia Snapshot, see the Gaia Administration Guide for your version.
    • For information about the "migrate export" and "migrate import" commands, see the CLI Reference Guide for your version.
  2. Connect to the command line on the Management Server.
  3. Log in to the Expert mode.
  4. On a Multi-Domain Security Management Server, go to the context of the applicable Domain on the Management Server:

mdsenv <IP Address or Name of Domain Management Server> 5. Remove the current file with Updatable Objects:

mv -v $MDS_FWDIR/conf/SMC_Files/uo{,_BKP} 6. Stop Check Point services:

cpstop ; cpstart

mdsstop ; mdsstart 7. Connect with SmartConsole to the Security Management Server / applicable Domain Management Server. 8. Import the required Updatable Object(s) again. 9. Make sure the Management Server created the $MDS_FWDIR/conf/SMC_Files/uo directory again.

Run in the Expert mode:

ls -l $MDS_FWDIR/conf/SMC_Files/uo

Article Properties

Access Level General
Status Approved
Date Created 2022-04-29
Last Modified 2026-01-28