sk182622 - "CloudGuard Controller is not responding" error in SmartConsole after installing Jumbo Hotfix Accumulator
"CloudGuard Controller is not responding" error in SmartConsole after installing Jumbo Hotfix Accumulator
Product
CloudGuard Controller, Multi-Domain Security Management, Security Management
Version
R81.10 (EOS), R81.20
Last Modified
2024-09-08
Symptoms
- SmartConsole displays a warning stating that the CloudGuard Controller is not responding after you install R81.20 Jumbo Hotfix Accumulator Take 79 or R81.10 Jumbo Hotfix Accumulator Take 158 on the Security Management Server/Multi-Domain Security Management Server:
"Error: 'CloudGuard Controller' is not responding. Verify that 'CloudGuard Controller' is installed on the gateway.
If 'CloudGuard Controller' should not be installed verify that it is not selected in the Products List of the gateway (SmartConsole > Gateway > General Properties > Check Point Products List). This error may occur if the Security Cluster is in Multi-Version Cluster mode. After upgrading all the cluster members to the same version, this error should disappear".
Cause
The cause of the issue is an incorrect reference set in the amon_fw.conf file.
The issue does not affect the functionality of the CloudGuard Controller, but it displays an incorrect status, which can be confusing.
To make sure that CloudGuard Controller is enabled and running, run the vsec stat command, for example:
[Expert@management:0]# vsec stat
CloudGuard Controller is enabled and running
Usage:
on Enable CloudGuard Controller
off Disable CloudGuard Controller
Solution
This problem was fixed. The fix is included starting from:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 84
- Jumbo Hotfix Accumulator for R81.10 starting from Take 165
Check Point recommends to always upgrade to the Recommended version (Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
As a workaround, you can run these steps: Important note: Apply these steps only on R81.20 Jumbo Hotfix Accumulator Take 79 or R81.10 Jumbo Hotfix Accumulator Take 158.
For Security Management:
- Connect to the server with SSH and log in to expert mode.
- Run:
amon_config cpstatdll add vSEC-Controller $FWDIR/lib vsec_monitoring_agent - Run:
cpwd_admin stop -name CPD -path "$CPDIR/bin/cpd_admin" -command "cpd_admin stop" - Run:
cpwd_admin start -name CPD -path "$CPDIR/bin/cpd" -command "cpd"
For Multi-Domain Security Management Server:
- Connect to the server with SSH and log in to expert mode.
- To enter the applicable domain context run:
mdsenv <DOMAIN_IP> - Run:
amon_config cpstatdll add vSEC-Controller $MDS_FWDIR/lib vsec_monitoring_agent - Repeat steps 2 and 3 for each applicable domain.
- Run:
mdsstop; mdsstart
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-08-26
Last Modified: 2024-09-08
Was this page helpful? Yes No