sk92739 - The CPInfo utility
The CPInfo utility
Solution
Note - To collect a CPInfo file on a Quantum Spark Gateway, follow sk138892.
| - Introduction - Usage Instructions - Downloads and First Time Installation Instructions - CLI Syntax - Data Collected |
- System Requirements - Manual update of CPInfo in SmartConsole - Troubleshooting - Known Limitations - Revision History |
Introduction
CPInfo is an auto-updatable utility that collects diagnostics data on a customer's machine at the time of execution and uploads it to Check Point servers (it replaces the standalone cp_uploader utility for uploading files to Check Point servers). The CPInfo output file allows analyzing customer setups from a remote location.
When contacting Check Point Support, collect the CPInfo files from the Security Management server and Security Gateways involved in your case.
- Check Point also offers the Check Point Uploader (CPWinUploader), a GUI-based utility to upload files that were requested by Check Point Support to Check Point User Center. (This utility relies on the CPInfo utility, and is automatically installed by it on Windows OS.)
Note: CPinfo collects information about the system it is executed on, and is only supported for Gaia OS. CPWinUploader is a utility that uploads files to Check Point, but does not collect anything. CPWinUploader can upload CPinfo files (which were collected on a Gaia machine).
- To view and analyze a CPInfo output file, use the DiagnosticsView utility.
Important Note
CPInfo collects a vast amount of information. It collects files, runs commands and other methods. Some of the commands are resource intensive and running them adds more load to the system.
Because collecting the CPinfo output file may decrease the performance of the target system, verify the CPU utilization by running the "top" command in the Expert mode.
Do not run the CPInfo tool if the current CPU utilization of at least one CPU core is greater than 70%. We recommend to collect the CPInfo output during the maintenance window.
Usage Instructions
CPInfo can be run directly on the command line (in all versions), or can be called from SmartUpdate.
| CLI | SmartUpdate |
| - On Gaia OS: Run " cpinfo [flags]" in Gaia Clish or in Expert mode- On Linux OS: Run " cpinfo [flags]" in CLI- On Windows OS: Run " cpinfo [flags]" in Windows Command Prompt- On all operating systems, Run " cpinfo -h" to see additional help |
1. Connect with SmartUpdate GUI to Security Management Server / Domain Management Server. 2. Go to the Package Management tab. 3. Right-click on the Security Gateway / Management Server object, from which you want to collect the CPInfo. 4. Select " Upload diagnostics (CPInfo) to Check Point". 5. Enter your User Center credentials, SR number, and click OK. |
Generating CPInfo on a Multi-Domain Security Management Server
- Connect to the command line on the Multi-Domain Security Management Server.
- If your default shell is Gaia Clish, then go to the Expert mode:
expert
3. Log in with the "superuser" credentials.
4. Go to the MDS environment:
mdsenv
5. Verify the correct environment:
echo $FWDIR
Example output: /opt/CPmds-R82.10/
6. Run the CPInfo tool (see "CLI Syntax").
To collect CPInfo from the context of a specific Domain Management Server:
- Connect to the command line on the Multi-Domain Security Management Server.
- If your default shell is Gaia Clish, then go to the Expert mode:
expert
3. Log in with the "superuser" credentials.
4. Go to the "MDS" context:
mdsenv
5. Verify the correct environment:
echo $FWDIR
Example output: /opt/CPmds-R82.10/
6. Run the CPInfo tool (see "CLI Syntax"):
cpinfo -c <Name_of_Domain>
CPInfo will generate these files:
- The execution summary:
<HostName>_<DateTime>.info
- CPInfo collected from the Domain Management Server:
<HostName>_<DateTime>_<Name_of_Domain>.info
Generating CPInfo on a VSX Gateway / VSX Cluster for a specific Virtual System
- Connect to the command line on the VSX Gateway / VSX Cluster Member.
- If your default shell is Gaia Clish, then go to the Expert mode:
expert
3. Go to the context of the applicable Virtual System:
vsenv <VS_ID>
4. Run the CPInfo tool (see "CLI Syntax").
Downloads and First Time Installation Instructions
For Gaia OS (R80 and higher)
Download the latest CPInfo utility from the table below:
| Package | Product Version | Build number | Download |
| CPInfo for Gaia OS (on a server with the Intel / AMD CPU) |
R82.10 | 914000231 | (TGZ) |
| CPInfo for Gaia OS (on a server with the ARM CPU) |
R82.10 | 914000231 | (TGZ) |
| CPInfo for Gaia OS | R80 - R82 | 914000274 | (TGZ) |
Important: We recommend that you install the hotfix in sk184766 to resolve the CRL validation failure issue.
Note: If the download of the CPInfo utility is impossible, then either install the CPInfo RPM from the /sysimg/CPwrapper/linux/CPinfo/ folder on the installed Gaia OS, or extract the CPInfo RPM from the /linux/CPinfo/ folder in the installation ISO image.
- Show / Hide the installation instructions for Gaia OS
Run the following commands from the directory where you put the downloaded file:
Place the file in a temporary directory on the target system.
Go into that directory.
Unpack the CPInfo archive package:
tar -xvzf cpinfo_<package_name>.tgz
- Install the CPInfo utility:
- In versions R82.10 and higher, on a server with the Intel / AMD CPU:
rpm -Uvh --force CPinfo-10-00.x86_64.rpm
- In versions R82.10 and higher, on a server with the ARM CPU:
rpm -Uvh --force CPinfo-10-00.aarch64.rpm
- In versions R82 and lower:
rpm -Uvh --force CPinfo-10-00.i386.rpm
Notes: - The CPInfo utility will be installed in this directory:
/opt/CPinfo-10/
- The installation log file is:
/opt/CPInstLog/install_status.log
(in addition, refer to /opt/CPInstLog/install_cpinfo_10.elg)
- The CPInfo installation directory will automatically be added to the $PATH environment variable
5. Log out from all shells on the target system.
Log in again.
Verify that the CPInfo utility was installed:
rpm -qa | grep CPinfo
Note: If the CPinfo-10-00 package does not appear in the output, try to rebuild the RPM database:
rpm -v --rebuilddb
8. Check the build number of CPInfo utility:
- Either run:
cpinfo
The output should be:
This is Check Point CPinfo Build 914000xxx for GAIA
Verifying CK...
- Or run:
cpinfo -v
The output should be:
This is Check Point CPinfo Build 914000xxx for GAIA
For Windows OS (R77.30 and lower)
Download the latest CPInfo utility for the Windows OS from the table below:
| Package | Product Version | Download |
| CPInfo for Windows OS | R77.30 and lower |
(TGZ) |
- Show / Hide the installation instructions for Windows
Download the CPInfo package.
Place the file in a temp directory on the target system.
Unpack the CPInfo package using a program like WinZIP, WinRAR, 7zip, etc.
Go into the
Packagefolder.Right-click the
cpinfo_914000xxx_1.exe- selectRun as administrator.Follow the installation instructions in the Installation Shield.
Check the build number of CPInfo utility in Windows Command Prompt: - Either run:
`C:> cpinfo``
The output should be:
This is Check Point CPinfo Build 914000xxx for Windows
Verifying CK...
- Or run:
C:\> cpinfo -v
The output should be:
This is Check Point CPinfo Build 914000xxx for Windows
Notes:
- The CPInfo utility will be installed into this folder:
C:\Program Files (x86)\CheckPoint\cpinfo\
- The installation log file is:
C:\Program Files (x86)\CheckPoint\CPInstLog\install_status.log
(in addition, refer to C:\Program Files (x86)\CheckPoint\CPInstLog\install_cpinfo_.elg)
- The CPInfo installation folder will automatically be added to the %PATH% environment variable
CLI Syntax
| On Gaia OS | On Windows OS |
| ``` # cpinfo [-h] |
[-v] |
Syntax:
Show / Hide the explanation about the flags
Enter the string to filter this table:
Parameter Description Important Notes No Parameters Collects the CPInfo output file - The output file will be created in the current working directory
with this name:
.info_ -hShows the built-in help and exits -vShows the CPInfo version and exits `-y {all }` Shows installed hotfixes
(either all, or for a specific product)-lIncludes the export of the $FWDIR/log/fw.log
records in the CPInfo file- This will cause additional CPU load and memory consumption -kIncludes the contents of FireWall and SecureXL
kernel tables in the CPInfo file
(outputs of " fw tab -t", " fwaccel conns")
- This will cause additional CPU load and memory consumption -c <Domain_Name>Generates the CPInfo file for the
specified Domain Management Server- Applies only to Multi-Domain Management Server
- Allows to collect CPInfo (and MDS export on R80 or higher)
per certain Domain without having to switch to its context-o <filename>Writes the collected information
to the specified output file- Creates output file named <filename>.info,
unless this file extension was already specified
- If "-o" is not specified, then a file named
"HostName_DD_MM_YYYY_HH_mm.info"
is created in the current working directory
(example for a file created on machine "R77.30-GW",
on 05 Oct 2016, at 15h 04m -
" R77.30-GW_5_10_2016_15_04.info")
- Can be used in combination with "-z"
- Can be used in combination with "-i"
- Can NOT be used in combination with "-n"-zCompresses the CPInfo output file - Used in combination with " -o"
- If the "Allow Upload" consent flag is enabled ( sk111080),
then the file is compressed by default (even without "-z")-iNon-interactive mode - CPInfo does not ask for the "SR Number"
- Can be used in shell scripts for automation
- Should be used in combination with "-n" or "-R"
- Can NOT be used in combination with "-a"-aForces the update check of the CPInfo utility
(by default, it is checked once a week)- Can NOT be used in combination with " -d"
- Can NOT be used in combination with "-i"-dSpecifies not to check for updates of CPInfo utility - Can NOT be used in combination with " -a"-DSpecifies not to upload files to Check Point Cloud - Can NOT be used in combination with " -f" or "-w" or "-e"-nSpecifies not to collect and create the CPInfo file - Should be used in combination with " -f" or "-w"
- Can NOT be used in combination with "-o"-f <file>Uploads additional files to Check Point Cloud - Should be used in combination with " -n" and "-i"
- Either specify a single file:file
Or specify multiple files:file1 file2 file3 ...
(multiple files must be separated by spaces)
- Also refer to "-w"
- If the file to be uploaded is not compressed,
then CPInfo utility will first compress it, and then upload it-w <filename>Specifies a file that contains a list of files to be uploaded to Check Point Cloud - Used instead of " -f"
- Lines in this file must be separated by the "\n" character
(press Enter after each line)-s <SR_Number>Specifies the number of the Service Request
opened with Check Point Support- For example, -s 28-123456789 -u <username>Connects to Check Point User Center with the specified username - <username>is your e-mail used for User Center login
- User will be asked to enter a password
- If "-u" is not used, then CK of this machine is used for authentication
- Also refer to "-K <CK_Number>"
- cannot be used in combination with –i flag-K <CK_Number>Connects to Check Point User Center with the specified CK Number - Used instead of " -u"
- Run the "cplic print" command
and take only the hex digits after the "CK-"
- Exists since Build 914000164-e <e-mail>Specifies the e-mails of people that should be notified about the upload status of the CPinfo file - Either specify a single e-mail:
user@exampledomain.com
- Or specify multiple e-mails:
"user1@exampledomain.com;user2@exampledomain.com;..."
- must be enclosed in double-quotes
- must be separated by semi-colons-RRemoves the local CPinfo output files from the current user's home directories -T <timeout>Specifies the timeout (in seconds) for the
commands executed by the CPInfo utility- Applies only to Gaia / SecurePlatform / IPSO / Linux OS
- Default timeout is 5 minutes (300 seconds)
- Value "0" means no timeout
- This does not apply to collection of the CPInfo output file itself-xSpecifies not to export the management database - Applies only to the versions R80 or higher
- On a Security Management Server - will not collect the migrate export
- On a Multi-Domain Management Server - will not collect an MDS export-j <conf_file>Creates a CPInfo configuration file <conf_file>- Applies only to Windows OS
- Requires installed Check Point Software on this machine
- Can NOT be used in combination with "-n"
- Must wait for the CPInfo output file to be collected:
CPInfo output file is collected, and name of each
collected section / command / file is saved in this
configuration file (which can be edited, so that
irrelevant data is not collected)-bRuns the CPInfo based on the configuration file that was created with the " -j" option
(you can delete irrelevant lines from that file)- Applies only to Windows OS
- Requires installed Check Point Software on this machine-gSpecifies not to resolve network addresses - Applies only to Windows OS
- Requires installed Check Point Software on this machine-F-rIncludes the Windows Registry in the CPInfo file - Applies only to Windows OS
- "-F" exists in Builds 914000164 and higher
- "-r" exists in Builds 914000158 and lower-tSpecifies to collect only the relevant tables - Applies only to Windows OS
- Applies only to machine with installed SecureRemote client-NReverts to the state of uploading CPview of the last day - It will still will be zipped together with .info file -V <num_days>Specifies the number of days of CPview history to be collected - 0 days will result in no CPView database upload
- Negative / double number of days is not allowed
- Upon receiving num_days > 0, a warning will be printed that collection of CPView database might take a few minutes (" Collection process might take a few minutes. Please wait until the collection is done.")
- Combination of ' -V' and ' -N' flag is not allowed-QRuns the CPSDC Tool - Refer to sk164414. -SCensors hashed passwords in the CPinfo output file. - Hashed passwords are displayed as: ********** Examples:
Show / Hide the examples
Note: Refer to explanations in the "Allowing upload of data to Check Point / download of data from Check Point" section.
Enter the string to filter this table:
# What to do How to do it 1 - Generate the CPInfo file
- Create the file in the current working directory
- Use the default name
- Do not compress the output file
The final file will be:
HostName_DD_MM_YYYY_HH_mm.infocpinfo2 - Generate the CPInfo file
- Create the file in the current working directory
- Use the default name
- Compress the output file
The final file will be:
HostName_DD_MM_YYYY_HH_mm.info.gzcpinfo -z3 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile with default extension.info
- Compress the output file
The final file will be:
/var/tmp/myfile.info.gzcpinfo -z -o /var/tmp/myfile4 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile with default extension.info
- Include export of $FWDIR/log/fw.log records
- Include contents of FireWall and SecureXL tables
- Compress the output file
The final file will be:
/var/tmp/myfile.info.gzcpinfo -l -k -z -o /var/tmp/myfile5 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:
- log in with user@exampledomain.com
- upload to Service Request 28-123456789
The final file will be:
/var/tmp/myfile.cpinfo.gzcpinfo -z -o /var/tmp/myfile.cpinfo -u user@exampledomain.com -s 28-1234567896 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:
- log in with CK-123456789000
- upload to Service Request 28-123456789
The final file will be:
/var/tmp/myfile.cpinfo.gzcpinfo -z -o /var/tmp/myfile.cpinfo -K 123456789000 -s 28-1234567897 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:
- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload status
The final file will be:
/var/tmp/myfile.cpinfo.gzcpinfo -z -o /var/tmp/myfile.cpinfo -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@exampledomain.com"8 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Do not prompt for an SR Numbercpinfo -i -z -o /var/tmp/myfile.cpinfo9 - Do not generate the CPInfo file
- Upload the file /var/log/myfile.txt
- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload statuscpinfo -n -i -f /var/log/myfile.txt -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@example.com"10 - Do not generate the CPInfo file
- Upload all files listed in the /var/log/upload_these_files.txt
- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload statuscpinfo -n -i -w /var/log/upload_these_files.txt -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@example.com"11 - Create a CPInfo configuration file
Note: Must wait for the CPInfo output file to be collectedcpinfo -n -i -F -j C:\CPinfo_config.txt12 - Check the status of the CPView history daemon cpview -s stat13 - Run the Check Point Support Data Collector (CPSDC) Tool
- Collect the output of the specified commands (in addition to the files and logs)cpinfo -d -D -Q "-r <Domain_Name>"Data Collected
CPInfo collects the entire Security Gateway installation directory, including
$FWDIR/log/*and other log files. Some other viewable information includes:
- System message logs
- Module version information
- Installed hotfixes information
- OS and network statistics
- Interfaces and devices information
- Various FW1 tables
- Configuration and database files
- Core dump files
System Requirements
DNS A DNS server must be configured on the server, on which you run CPInfo. Uploading CPInfo files to Check Point To upload CPInfo files to Check Point, the following ports should be open:
- For Authentication (HTTPS - port 443):
-services.checkpoint.com
- File uploading (HTTPS - port 443, or SFTP - port 22):
-ftp-proxy.checkpoint.com
-mercury.ts.checkpoint.com
-fairfax.ott.checkpoint.com
- Connecting through a Proxy
This section is relevant for machines that access the Internet through an HTTP proxy server, while Check Point Security Gateway / Security Management on that machine is not configured with such a proxy (as described in the Administration Guide).
The CPInfo utility updates itself and uploads files over the HTTPS protocol.
The CPInfo utility will read the proxy configuration that was configured on the Security Gateway (either in SmartConsole / SmartDashboard, or on CLI).
Allowing upload of data to Check Point / download of data from Check Point
Software can automatically upload the relevant data to Check Point / download the relevant data from Check Point. This behavior is controlled by the corresponding consent flags ("Allow Upload" / "Allow Download"). By default, both consent flags are enabled (i.e., a server that is connected to the Internet will communicate with Check Point servers).
CPInfo utility (build 914000148 and higher) requires these consent flags to be enabled:
CPInfo Action Server Version Required Consent Flag Reference Download the CPInfo self-update package R81.20 and higher "Download Non-Security" sk175504 R81.10 and lower "Allow Download" sk111080 Upload CPInfo output files to Check Point
Note: If the server is connected to the Internet,
and the "Allow Upload" consent flag is enabled,
then when running the CPInfo utility:
- It will prompt you for an SR Number
( please provide an SR number or enter "s" to skip)
- It will try to upload the collected CPInfo file
without asking the userR81.20 and higher "Upload Information" sk175504 R81.10 and lower "Allow Upload" sk111080 Manual update of CPInfo in SmartConsole
SmartConsole uses the CPInfo utility for Check Point upload services. Follow the instructions below to manually update the CPInfo utility in SmartConsole:
Run CPInfo installation on your SmartConsole client machine. If the CPInfo's latest build is already installed, you can skip this step.
After installation, copy the following files to the SmartConsole client:
C:\Program Files (x86)\CheckPoint\cpinfo\bin\cpinfo.exe
C:\Program Files (x86)\CheckPoint\cpinfo\bin\data\ca_bundle.crt
- Go to the SmartConsole folder:
C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM
- Back up these files and replace them with the files you copied to the "
bin" folder:
C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM\cpinfo.exe
C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM\data\ca-bundle.crtTroubleshooting
For the list of problems and troubleshooting instructions, refer to sk114496 - Troubleshooting the CPInfo utility article.
Known Limitations
The following limitations are known with CPInfo utility:
Description Files that contain '/' or '\' in their name, which is not according to the OS on which the CPInfo utility is running, cannot be uploaded to Check Point.
Example:
- Uploading\directory\demofilewill be blocked
- Uploading/directory/demofilewill be processed successfullyThe size of the files to upload is limited to 10 GB.
Refer to sk92526 for relevant instructions.Revision History
Date Description 10 Feb 2026 Added CPInfo packages for R82.10 01 Sep 2025 CPInfo package was replaced (build 914000 259) 28 Aug 2025 Improved formatting 16 Sep 2024 CPInfo package was replaced (build 914000 250) 21 Apr 2024 CPInfo package was replaced (build 914000 248) 06 Aug 2023 CPInfo package was replaced (build 914000 239) 09 Mar 2023 CPInfo package was replaced (build 914000 234) 02 June 2022 CPInfo package was replaced (build 914000 231) 17 Jan 2022 CPInfo package was replaced (build 914000 227) 16 Aug 2021 CPInfo package was replaced (build 914000 219) 06 Oct 2020 CPInfo package was replaced (build 914000 215) 07 June 2020 Added "Important Note" in the "Introduction" section 22 Dec 2019 CPInfo package was replaced (build 914000 202) 16 Dec 2019 CPInfo package was replaced (build 914000 201) 07 Oct 2019 CPInfo package was replaced (build 914000 196) 26 Dec 2018 CPInfo package was replaced (build 914000 191) 05 Nov 2018 CPInfo package was replaced (build 914000 190) 12 Dec 2017 Minor design changes 17 Oct 2017 Added links for CPUSE offline packages 03 Oct 2017 CPInfo package was replaced (build 914000 182) 12 Sep 2017 - CPInfo package was replaced (build 914000 180)
- Important Notes, Syntax and Flags tables were updated13 Jun 2017 Updated the description of the " -R" flag for R80.x 22 Mar 2017 CPInfo package was replaced (build 914000 176) 05 Dec 2016 Added the section "Troubleshooting" 04 Dec 2016 - Article was redesigned
- Added section about generating CPInfo on Multi-Domain Management Server20 Nov 2016 - CPInfo package was replaced (build 914000 173) with a new ca-bundle.crt
- Added "Manual update of CPInfo in SmartConsole" section
- Added the explanation for the " -D" flag02 Oct 2016 CPInfo package was replaced (starting in build 914000 164)