sk182684 - "Error: Update of the Network Feed 'OBJECT NAME' failed because the Security Gateway could not reach the destination" log from a Security Gateway
"Error: Update of the Network Feed 'OBJECT NAME' failed because the Security Gateway could not reach the destination" log from a Security Gateway
Product
Security Gateways
Version
R81.20
OS
Gaia
Last Modified
2025-04-24
Symptoms
- "
Error: Update of the Network Feed 'OBJECT NAME' failed because the Security Gateway could not reach the destination" log from a Security Gateway.
Example:
In SmartConsole, in the Network Feed object, the "Test Feed" action ends with the same error.
Connection from the Security Gateway to the feed file is successful (with the "
curl_cli -k <Full URL>" command).The
$FWDIR/log/efo_error.elgfile on the Security Gateway contains this error:
[<DATE TIME>][<NAME of FEED OBJECT>]: EFO_FEED> get_domain_from_url: called with URL <URL OF FEED>/<NAME OF FEED FILE>
[<DATE TIME>][<NAME of FEED OBJECT>]: EFO_FEED> get_domain_ips: called with name <URL OF FEED>
[<DATE TIME>][<NAME of FEED OBJECT>]: EFO_FEED> get_domain_ips: failed to resolve the domain name, res=-1
[<DATE TIME>][<NAME of FEED OBJECT>]: EFO_FEED> validate_feed_url: error: could not resolve the domain
Cause
The Network Feed object update fails because its URL contains a port number.
By default, a port number is not supported in the Network Feed URL.
Example:
https://myserver.example.com:8080/my_feed_file.csv
Solution
This problem was fixed. The fix is included starting from:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 89
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
The immediate workaround is:
- Change the configuration on the feed server to serve the feed file over these TCP ports:
- For HTTP - over the TCP port 80
- For HTTPS - over the TCP port 443
- In SmartConsole, in the Network Feed object:
- In the Feed URL field, remove the port number.
- Click the "Test Feed" button and make sure the test is successful.
- Install the Access Control policy.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-10-09
Last Modified: 2025-04-24