sk94064 - Synchronization with User Center

Synchronization with User Center

Product: Multi-Domain Security Management, Security Management, User Center
Version: Other, R82.10
Last Modified: 2025-09-17

Solution

Table of Contents:

Introduction

The "Sync with User Center" feature synchronizes information regarding your environment with the Check Point UserCenter.

The UserCenter account provides:

Example of a UserCenter Account

Prerequisites

  1. A device with licenses and an installed policy/database.
  2. Uploading/downloading data to Check Point is allowed.
    For details, refer to sk111080.
  3. Internet connectivity to Check Point Servers.
    • Make sure the Management Server can connect to the required Check Point servers:

| | | | --- | --- | | Server | Command to Run on the Management Server | | dl3.checkpoint.com | curl_cli [-x <ProxyAddress>:<ProxyPort>] -v http://dl3.checkpoint.com | | services.checkpoint.com | curl_cli [-x <ProxyAddress>:<ProxyPort>] -v --cacert $CPDIR/conf/ca-bundle.crt https://services.checkpoint.com | | updates.checkpoint.com | curl_cli [-x <ProxyAddress>:<ProxyPort>] -v --cacert $CPDIR/conf/ca-bundle.crt https://updates.checkpoint.com |

For details, refer to sk83520. - Multi-Domain Security Management Server / Domain Management Server: Configure the proxy settings in the Gaia Portal. - Single-Domain Security Management Server: You can configure the proxy settings in SmartConsole (in the Management Server object > Network Management > Proxy) or in Gaia Portal. Note: If you configure the proxy settings in SmartConsole, you must click Menu > Install database > select the Management Server object > click Install. 4. The Sync to User Center feature uses CPDiag*. It must be the latest version.

How to configure "Sync with UserCenter" in SmartConsole

In SmartConsole R80.10 and higher

In SmartConsole, on the left navigation panel, click " Manage & Settings" and click " Sync with UserCenter".

When synchronization is enabled, an update occurs one time each day.

Note: For Multi-Domain Sever, you must do the above procedure on a minimum of one Domain Management Server to sync with the UserCenter.

In SmartDashboard R75.47 - R77.x

In SmartDashboard, go to the " Help" menu and click " Sync with UserCenter...".

Clicking the " Synchronize now" button runs an applicable script on the Security Management Server. The script collects information from the Security Management database and the managed Security Gateways and writes it into the $FWDIR/conf/SMC_Files/SU/data_file.xml file.

Checking the box " Periodically sync server and gateways data with UserCenter" runs the script one time each week.

When the information is sent to Check Point, the UserCenter presents it in the list of "Software Products & Appliances".

Note: In a Multi-Domain Security Management Server environment, this feature is only available in context of each Domain Management Server. Currently, it does not work in the MDS context.

How to configure "Sync with UserCenter" with API

Support for the Management API commands:

Management API Commands:

show sync-with-user-center

set sync-with-user-center

Information sent to Check Point User Center

This information is sent to Check Point User Center:

Error Messages and Warnings

(1) Sync of Multi-Domain Management server with UserCenter fails

Symptoms

Cause There is a database issue related to the _objects_0.C file in the R80.x Multi-Domain Security Management Server. This file is no longer in use by R80.x versions.

Solution

  1. Connect to the command line on the Multi-Domain Security Management Server.
  2. Log in to Expert mode.
  3. Move the file to a different directory: mv -v $FWDIR/conf/objects_5_0.C /home/admin/objects_5_0.C
  4. Make sure the file was moved: grep -n "load_content" $FWDIR/conf/objects_5_0.C

Example output: grep: /opt/CPmds-R80/conf/objects_5_0.C: No such file or directory 5. Connect with SmartConsole to the Global Domain. 6. Clear the checkboxes in Global Properties > Security Management Access. 7. Publish the changes. 8. Select the checkboxes in Global Properties > Security Management Access. 9. Publish changes. 10. Connect with SmartConsole to the MDS level. 11. Enable the "Sync with the UserCenter" again at the MDS level: 1. In the left panel, click Multi Domain. 2. Click Sync with UserCenter. 3. Select Synchronize information once a day. 4. Wait for the confirmation status " Connected to the Check Point UserCenter".

(2) The option "Sync with UserCenter" is grayed out in SmartConsole connected to a Domain Management Server

Symptoms

Cause OS information is missing in the _objects_0.c file below the Domain Management Server's object definition section. In the _objects_0.c file, below the Domain Management Server's object: : (<Name of Domain Management Server object> ...
:os_info () In a working environment is should look like this:
: (<Name of Domain Management Server object> ...
:os_info ( :AdminInfo ( :chkpf_uid ("{<UID>}") :ClassName (os_info)

Solution

  1. Connect with SmartConsole to the Domain Management Server.

  2. In the left panel, click Gateways & Servers.

  3. Double-click the Domain Management Server object.

  4. In the left panel, click General Properties.

  5. Below the Platform section, click Get to fetch the OS information.

  6. Click OK.

  7. Publish the changes.

Known Limitations

The product list does not show these devices:

For assistance, contact Check Point Support.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.