sk92739 - The CPInfo utility

The CPInfo utility

Solution

Note - To collect a CPInfo file on a Quantum Spark Gateway, follow sk138892.

- Introduction

- Usage Instructions

- Downloads and First Time Installation Instructions

- CLI Syntax

- Data Collected
- System Requirements

- Manual update of CPInfo in SmartConsole

- Troubleshooting

- Known Limitations

- Revision History

Introduction

CPInfo is an auto-updatable utility that collects diagnostics data on a customer's machine at the time of execution and uploads it to Check Point servers (it replaces the standalone cp_uploader utility for uploading files to Check Point servers). The CPInfo output file allows analyzing customer setups from a remote location.

When contacting Check Point Support, collect the CPInfo files from the Security Management server and Security Gateways involved in your case.

Note: CPinfo collects information about the system it is executed on, and is only supported for Gaia OS. CPWinUploader is a utility that uploads files to Check Point, but does not collect anything. CPWinUploader can upload CPinfo files (which were collected on a Gaia machine).

Important Note

CPInfo collects a vast amount of information. It collects files, runs commands and other methods. Some of the commands are resource intensive and running them adds more load to the system.

Because collecting the CPinfo output file may decrease the performance of the target system, verify the CPU utilization by running the "top" command in the Expert mode.

Do not run the CPInfo tool if the current CPU utilization of at least one CPU core is greater than 70%. We recommend to collect the CPInfo output during the maintenance window.

Usage Instructions

CPInfo can be run directly on the command line (in all versions), or can be called from SmartUpdate.

CLI SmartUpdate
- On Gaia OS:

Run "cpinfo [flags]" in Gaia Clish or in Expert mode
- On Linux OS:

Run "cpinfo [flags]" in CLI
- On Windows OS:

Run "cpinfo [flags]" in Windows Command Prompt
- On all operating systems, Run "cpinfo -h" to see additional help
1. Connect with SmartUpdate GUI to Security Management Server / Domain Management Server.
2. Go to the Package Management tab.
3. Right-click on the Security Gateway / Management Server object, from which you want to collect the CPInfo.
4. Select " Upload diagnostics (CPInfo) to Check Point".
5. Enter your User Center credentials, SR number, and click OK.

Generating CPInfo on a Multi-Domain Security Management Server

  1. Connect to the command line on the Multi-Domain Security Management Server.
  2. If your default shell is Gaia Clish, then go to the Expert mode:

expert 3. Log in with the "superuser" credentials. 4. Go to the MDS environment:

mdsenv 5. Verify the correct environment:

echo $FWDIR

Example output: /opt/CPmds-R82.10/ 6. Run the CPInfo tool (see "CLI Syntax").

To collect CPInfo from the context of a specific Domain Management Server:

  1. Connect to the command line on the Multi-Domain Security Management Server.
  2. If your default shell is Gaia Clish, then go to the Expert mode:

expert 3. Log in with the "superuser" credentials. 4. Go to the "MDS" context:

mdsenv 5. Verify the correct environment:

echo $FWDIR

Example output: /opt/CPmds-R82.10/ 6. Run the CPInfo tool (see "CLI Syntax"):

cpinfo -c <Name_of_Domain>

CPInfo will generate these files:

<HostName>_<DateTime>.info

<HostName>_<DateTime>_<Name_of_Domain>.info

Generating CPInfo on a VSX Gateway / VSX Cluster for a specific Virtual System

  1. Connect to the command line on the VSX Gateway / VSX Cluster Member.
  2. If your default shell is Gaia Clish, then go to the Expert mode:

expert 3. Go to the context of the applicable Virtual System:

vsenv <VS_ID> 4. Run the CPInfo tool (see "CLI Syntax").

Downloads and First Time Installation Instructions

Download the latest CPInfo utility from the table below:

Package Product Version Build number Download
CPInfo for Gaia OS
(on a server with the Intel / AMD CPU)
R82.10 914000231 (TGZ)
CPInfo for Gaia OS
(on a server with the ARM CPU)
R82.10 914000231 (TGZ)
CPInfo for Gaia OS R80 - R82 914000274 (TGZ)

Important: We recommend that you install the hotfix in sk184766 to resolve the CRL validation failure issue.

Note: If the download of the CPInfo utility is impossible, then either install the CPInfo RPM from the /sysimg/CPwrapper/linux/CPinfo/ folder on the installed Gaia OS, or extract the CPInfo RPM from the /linux/CPinfo/ folder in the installation ISO image.

Run the following commands from the directory where you put the downloaded file:

  1. Place the file in a temporary directory on the target system.

  2. Go into that directory.

  3. Unpack the CPInfo archive package:

tar -xvzf cpinfo_<package_name>.tgz

  1. Install the CPInfo utility:

rpm -Uvh --force CPinfo-10-00.x86_64.rpm

rpm -Uvh --force CPinfo-10-00.aarch64.rpm

rpm -Uvh --force CPinfo-10-00.i386.rpm

Notes: - The CPInfo utility will be installed in this directory:

/opt/CPinfo-10/ - The installation log file is:

/opt/CPInstLog/install_status.log (in addition, refer to /opt/CPInstLog/install_cpinfo_10.elg) - The CPInfo installation directory will automatically be added to the $PATH environment variable 5. Log out from all shells on the target system.

  1. Log in again.

  2. Verify that the CPInfo utility was installed:

rpm -qa | grep CPinfo Note: If the CPinfo-10-00 package does not appear in the output, try to rebuild the RPM database:

rpm -v --rebuilddb 8. Check the build number of CPInfo utility: - Either run:

cpinfo

The output should be:

This is Check Point CPinfo Build 914000xxx for GAIA

Verifying CK...

cpinfo -v

The output should be: This is Check Point CPinfo Build 914000xxx for GAIA

Download the latest CPInfo utility for the Windows OS from the table below:

Package Product Version Download
CPInfo for Windows OS R77.30
and
lower
(TGZ)
  1. Download the CPInfo package.

  2. Place the file in a temp directory on the target system.

  3. Unpack the CPInfo package using a program like WinZIP, WinRAR, 7zip, etc.

  4. Go into the Package folder.

  5. Right-click the cpinfo_914000xxx_1.exe - select Run as administrator.

  6. Follow the installation instructions in the Installation Shield.

  7. Check the build number of CPInfo utility in Windows Command Prompt: - Either run:

`C:> cpinfo``

The output should be:

This is Check Point CPinfo Build 914000xxx for Windows

Verifying CK...

C:\> cpinfo -v

The output should be:

This is Check Point CPinfo Build 914000xxx for Windows

Notes:

C:\Program Files (x86)\CheckPoint\cpinfo\ - The installation log file is:

C:\Program Files (x86)\CheckPoint\CPInstLog\install_status.log

(in addition, refer to C:\Program Files (x86)\CheckPoint\CPInstLog\install_cpinfo_.elg) - The CPInfo installation folder will automatically be added to the %PATH% environment variable

CLI Syntax

On Gaia OS On Windows OS
```
# cpinfo [-h]
[-v]

Syntax:

Show / Hide the explanation about the flags

Enter the string to filter this table:

Parameter Description Important Notes
No Parameters Collects the CPInfo output file - The output file will be created in the current working directory

with this name:

.info_
-h Shows the built-in help and exits
-v Shows the CPInfo version and exits
`-y {all }` Shows installed hotfixes
(either all, or for a specific product)
-l Includes the export of the $FWDIR/log/fw.log
records in the CPInfo file
- This will cause additional CPU load and memory consumption
-k Includes the contents of FireWall and SecureXL
kernel tables in the CPInfo file
(outputs of " fw tab -t ", " fwaccel conns")
- This will cause additional CPU load and memory consumption
-c <Domain_Name> Generates the CPInfo file for the
specified Domain Management Server
- Applies only to Multi-Domain Management Server
- Allows to collect CPInfo (and MDS export on R80 or higher)

per certain Domain without having to switch to its context
-o <filename> Writes the collected information
to the specified output file
- Creates output file named <filename>.info,

unless this file extension was already specified
- If "-o" is not specified, then a file named

"HostName_DD_MM_YYYY_HH_mm.info"

is created in the current working directory

(example for a file created on machine "R77.30-GW",

on 05 Oct 2016, at 15h 04m -

" R77.30-GW_5_10_2016_15_04.info")
- Can be used in combination with "-z"
- Can be used in combination with "-i"
- Can NOT be used in combination with "-n"
-z Compresses the CPInfo output file - Used in combination with "-o"
- If the "Allow Upload" consent flag is enabled ( sk111080),

then the file is compressed by default (even without "-z")
-i Non-interactive mode - CPInfo does not ask for the "SR Number"
- Can be used in shell scripts for automation
- Should be used in combination with "-n" or "-R"
- Can NOT be used in combination with "-a"
-a Forces the update check of the CPInfo utility
(by default, it is checked once a week)
- Can NOT be used in combination with "-d"
- Can NOT be used in combination with "-i"
-d Specifies not to check for updates of CPInfo utility - Can NOT be used in combination with "-a"
-D Specifies not to upload files to Check Point Cloud - Can NOT be used in combination with "-f" or "-w" or "-e"
-n Specifies not to collect and create the CPInfo file - Should be used in combination with "-f" or "-w"
- Can NOT be used in combination with "-o"
-f <file> Uploads additional files to Check Point Cloud - Should be used in combination with "-n" and "-i"
- Either specify a single file: file

Or specify multiple files: file1 file2 file3 ...

(multiple files must be separated by spaces)
- Also refer to "-w"
- If the file to be uploaded is not compressed,

then CPInfo utility will first compress it, and then upload it
-w <filename> Specifies a file that contains a list of files to be uploaded to Check Point Cloud - Used instead of "-f"
- Lines in this file must be separated by the "\n" character

(press Enter after each line)
-s <SR_Number> Specifies the number of the Service Request
opened with Check Point Support
- For example, -s 28-123456789
-u <username> Connects to Check Point User Center with the specified username - <username> is your e-mail used for User Center login
- User will be asked to enter a password
- If "-u" is not used, then CK of this machine is used for authentication
- Also refer to "-K <CK_Number>"
- cannot be used in combination with –i flag
-K <CK_Number> Connects to Check Point User Center with the specified CK Number - Used instead of "-u"
- Run the "cplic print" command

and take only the hex digits after the "CK-"
- Exists since Build 914000164
-e <e-mail> Specifies the e-mails of people that should be notified about the upload status of the CPinfo file - Either specify a single e-mail:

user@exampledomain.com
- Or specify multiple e-mails:

"user1@exampledomain.com;user2@exampledomain.com;..."


- must be enclosed in double-quotes
- must be separated by semi-colons
-R Removes the local CPinfo output files from the current user's home directories
-T <timeout> Specifies the timeout (in seconds) for the
commands executed by the CPInfo utility
- Applies only to Gaia / SecurePlatform / IPSO / Linux OS
- Default timeout is 5 minutes (300 seconds)
- Value "0" means no timeout
- This does not apply to collection of the CPInfo output file itself
-x Specifies not to export the management database - Applies only to the versions R80 or higher
- On a Security Management Server - will not collect the migrate export
- On a Multi-Domain Management Server - will not collect an MDS export
-j <conf_file> Creates a CPInfo configuration file <conf_file> - Applies only to Windows OS
- Requires installed Check Point Software on this machine
- Can NOT be used in combination with "-n"
- Must wait for the CPInfo output file to be collected:

CPInfo output file is collected, and name of each

collected section / command / file is saved in this

configuration file (which can be edited, so that

irrelevant data is not collected)
-b Runs the CPInfo based on the configuration file that was created with the "-j" option
(you can delete irrelevant lines from that file)
- Applies only to Windows OS
- Requires installed Check Point Software on this machine
-g Specifies not to resolve network addresses - Applies only to Windows OS
- Requires installed Check Point Software on this machine
-F
-r
Includes the Windows Registry in the CPInfo file - Applies only to Windows OS
- "-F" exists in Builds 914000164 and higher
- "-r" exists in Builds 914000158 and lower
-t Specifies to collect only the relevant tables - Applies only to Windows OS
- Applies only to machine with installed SecureRemote client
-N Reverts to the state of uploading CPview of the last day - It will still will be zipped together with .info file
-V <num_days> Specifies the number of days of CPview history to be collected - 0 days will result in no CPView database upload
- Negative / double number of days is not allowed
- Upon receiving num_days > 0, a warning will be printed that collection of CPView database might take a few minutes (" Collection process might take a few minutes. Please wait until the collection is done.")
- Combination of ' -V' and ' -N' flag is not allowed
-Q Runs the CPSDC Tool - Refer to sk164414.
-S Censors hashed passwords in the CPinfo output file. - Hashed passwords are displayed as: **********

Examples:

Show / Hide the examples

Note: Refer to explanations in the "Allowing upload of data to Check Point / download of data from Check Point" section.

Enter the string to filter this table:

# What to do How to do it
1 - Generate the CPInfo file
- Create the file in the current working directory
- Use the default name
- Do not compress the output file
The final file will be:
HostName_DD_MM_YYYY_HH_mm.info
cpinfo
2 - Generate the CPInfo file
- Create the file in the current working directory
- Use the default name
- Compress the output file
The final file will be:
HostName_DD_MM_YYYY_HH_mm.info.gz
cpinfo -z
3 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile with default extension .info
- Compress the output file
The final file will be:
/var/tmp/myfile.info.gz
cpinfo -z -o /var/tmp/myfile
4 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile with default extension .info
- Include export of $FWDIR/log/fw.log records
- Include contents of FireWall and SecureXL tables
- Compress the output file
The final file will be:
/var/tmp/myfile.info.gz
cpinfo -l -k -z -o /var/tmp/myfile
5 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:


- log in with user@exampledomain.com
- upload to Service Request 28-123456789
The final file will be:
/var/tmp/myfile.cpinfo.gz
cpinfo -z -o /var/tmp/myfile.cpinfo -u user@exampledomain.com -s 28-123456789
6 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:


- log in with CK-123456789000
- upload to Service Request 28-123456789
The final file will be:
/var/tmp/myfile.cpinfo.gz
cpinfo -z -o /var/tmp/myfile.cpinfo -K 123456789000 -s 28-123456789
7 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Upload the output file to Check Point:


- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload status
The final file will be:
/var/tmp/myfile.cpinfo.gz
cpinfo -z -o /var/tmp/myfile.cpinfo -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@exampledomain.com"
8 - Generate the CPInfo file
- Create the file in the directory /var/tmp/
- Use the file name myfile.cpinfo
- Compress the output file
- Do not prompt for an SR Number
cpinfo -i -z -o /var/tmp/myfile.cpinfo
9 - Do not generate the CPInfo file
- Upload the file /var/log/myfile.txt


- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload status
cpinfo -n -i -f /var/log/myfile.txt -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@example.com"
10 - Do not generate the CPInfo file
- Upload all files listed in the /var/log/upload_these_files.txt


- log in with user@exampledomain.com
- upload to Service Request 28-123456789
- Notify people about upload status
cpinfo -n -i -w /var/log/upload_these_files.txt -u user@exampledomain.com -s 28-123456789 -e "user1@exampledomain.com;user2@example.com"
11 - Create a CPInfo configuration file
Note: Must wait for the CPInfo output file to be collected
cpinfo -n -i -F -j C:\CPinfo_config.txt
12 - Check the status of the CPView history daemon cpview -s stat
13 - Run the Check Point Support Data Collector (CPSDC) Tool
- Collect the output of the specified commands (in addition to the files and logs)
cpinfo -d -D -Q "-r <Domain_Name>"

Data Collected

CPInfo collects the entire Security Gateway installation directory, including $FWDIR/log/* and other log files. Some other viewable information includes:

  • System message logs
  • Module version information
  • Installed hotfixes information
  • OS and network statistics
  • Interfaces and devices information
  • Various FW1 tables
  • Configuration and database files
  • Core dump files

System Requirements

DNS A DNS server must be configured on the server, on which you run CPInfo.
Uploading CPInfo files to Check Point To upload CPInfo files to Check Point, the following ports should be open:
- For Authentication (HTTPS - port 443):


- services.checkpoint.com
- File uploading (HTTPS - port 443, or SFTP - port 22):


- ftp-proxy.checkpoint.com
- mercury.ts.checkpoint.com
- fairfax.ott.checkpoint.com
  • Connecting through a Proxy

This section is relevant for machines that access the Internet through an HTTP proxy server, while Check Point Security Gateway / Security Management on that machine is not configured with such a proxy (as described in the Administration Guide).

The CPInfo utility updates itself and uploads files over the HTTPS protocol.

The CPInfo utility will read the proxy configuration that was configured on the Security Gateway (either in SmartConsole / SmartDashboard, or on CLI).

Allowing upload of data to Check Point / download of data from Check Point

Software can automatically upload the relevant data to Check Point / download the relevant data from Check Point. This behavior is controlled by the corresponding consent flags ("Allow Upload" / "Allow Download"). By default, both consent flags are enabled (i.e., a server that is connected to the Internet will communicate with Check Point servers).

CPInfo utility (build 914000148 and higher) requires these consent flags to be enabled:

CPInfo Action Server Version Required Consent Flag Reference
Download the CPInfo self-update package R81.20 and higher "Download Non-Security" sk175504
R81.10 and lower "Allow Download" sk111080
Upload CPInfo output files to Check Point
Note: If the server is connected to the Internet,
and the "Allow Upload" consent flag is enabled,
then when running the CPInfo utility:
- It will prompt you for an SR Number

( please provide an SR number or enter "s" to skip)
- It will try to upload the collected CPInfo file

without asking the user
R81.20 and higher "Upload Information" sk175504
R81.10 and lower "Allow Upload" sk111080

Manual update of CPInfo in SmartConsole

SmartConsole uses the CPInfo utility for Check Point upload services. Follow the instructions below to manually update the CPInfo utility in SmartConsole:

  1. Run CPInfo installation on your SmartConsole client machine. If the CPInfo's latest build is already installed, you can skip this step.

  2. After installation, copy the following files to the SmartConsole client:

C:\Program Files (x86)\CheckPoint\cpinfo\bin\cpinfo.exe

C:\Program Files (x86)\CheckPoint\cpinfo\bin\data\ca_bundle.crt

  1. Go to the SmartConsole folder:

C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM

  1. Back up these files and replace them with the files you copied to the "bin" folder:

C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM\cpinfo.exe

C:\Program Files (x86)\CheckPoint\SmartConsole\<version>\PROGRAM\data\ca-bundle.crt

Troubleshooting

For the list of problems and troubleshooting instructions, refer to sk114496 - Troubleshooting the CPInfo utility article.

Known Limitations

The following limitations are known with CPInfo utility:

Description
Files that contain '/' or '\' in their name, which is not according to the OS on which the CPInfo utility is running, cannot be uploaded to Check Point.
Example:
- Uploading \directory\demofile will be blocked
- Uploading /directory/demofile will be processed successfully
The size of the files to upload is limited to 10 GB.
Refer to sk92526 for relevant instructions.

Revision History

Date Description
10 Feb 2026 Added CPInfo packages for R82.10
01 Sep 2025 CPInfo package was replaced (build 914000 259)
28 Aug 2025 Improved formatting
16 Sep 2024 CPInfo package was replaced (build 914000 250)
21 Apr 2024 CPInfo package was replaced (build 914000 248)
06 Aug 2023 CPInfo package was replaced (build 914000 239)
09 Mar 2023 CPInfo package was replaced (build 914000 234)
02 June 2022 CPInfo package was replaced (build 914000 231)
17 Jan 2022 CPInfo package was replaced (build 914000 227)
16 Aug 2021 CPInfo package was replaced (build 914000 219)
06 Oct 2020 CPInfo package was replaced (build 914000 215)
07 June 2020 Added "Important Note" in the "Introduction" section
22 Dec 2019 CPInfo package was replaced (build 914000 202)
16 Dec 2019 CPInfo package was replaced (build 914000 201)
07 Oct 2019 CPInfo package was replaced (build 914000 196)
26 Dec 2018 CPInfo package was replaced (build 914000 191)
05 Nov 2018 CPInfo package was replaced (build 914000 190)
12 Dec 2017 Minor design changes
17 Oct 2017 Added links for CPUSE offline packages
03 Oct 2017 CPInfo package was replaced (build 914000 182)
12 Sep 2017 - CPInfo package was replaced (build 914000 180)
- Important Notes, Syntax and Flags tables were updated
13 Jun 2017 Updated the description of the " -R" flag for R80.x
22 Mar 2017 CPInfo package was replaced (build 914000 176)
05 Dec 2016 Added the section "Troubleshooting"
04 Dec 2016 - Article was redesigned
- Added section about generating CPInfo on Multi-Domain Management Server
20 Nov 2016 - CPInfo package was replaced (build 914000 173) with a new ca-bundle.crt
- Added "Manual update of CPInfo in SmartConsole" section
- Added the explanation for the " -D" flag
02 Oct 2016 CPInfo package was replaced (starting in build 914000 164)