sk181650 - The $FWDIR/../oc_feeder.conf file is empty on all VSs and VSX Gateways
The $FWDIR/../oc_feeder.conf file is empty on all VSs and VSX Gateways
Product: IPS, Multi-Domain Security Management, VSX (Traditional)
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Platform: Smart-1
Last Modified: 2025-01-16
Symptoms
- The $FWDIR/../oc_feeder.conf file is empty on all VSs and VSX Gateways.
- Policy installation of Threat Prevention fails with error: "failing to handle indicators <>".
Cause
At least one IOC feed is configured in SmartConsole, and no external IOC feeds are configured in CLI. Policy installation was attempted after the last feed was deleted from SmartConsole. If all feeds are deleted, the JSON field "feeds" is erased and an empty object is added instead, which is represented as { }.
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 90
- Jumbo Hotfix Accumulator for R81.10 starting from Take 171
- Jumbo Hotfix Accumulator for R81 starting from Take 106
If you choose not to upgrade, this workaround is available.
As a workaround, add an external IOC feed through the CLI with state=false. The feed only has the effect of not "reaching" an empty tree of feeds:
ioc_feeds add --feed_name dummyfeed --transport local_file --state false --resource "/home/admin/some_name.csv" --format [value:1,type:ip]
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-11-13
Last Modified: 2025-01-16