# Synchronization with User Center

**Product:** Multi-Domain Security Management, Security Management, User Center  
**Version:** Other, R82.10  
**Last Modified:** 2025-09-17

## Solution

**Table of Contents:**

- Introduction
- Example of a UserCenter Account
- Prerequisites
- How to configure "Sync with UserCenter" in SmartConsole
- How to configure "Sync with UserCenter" with API
- Information sent to Check Point User Center
- Error Messages and Warnings
- Known Limitations

## Introduction

The "Sync with User Center" feature synchronizes information regarding your environment with the Check Point UserCenter.

The UserCenter account provides:

- Better inventory management
- Pro-active support
- More efficient ticket resolution

## Example of a UserCenter Account

## Prerequisites

1. A device with licenses and an installed policy/database.
2. Uploading/downloading data to Check Point is allowed.  
   For details, refer to [sk111080](https://support.checkpoint.com/results/sk/sk111080).
3. Internet connectivity to Check Point Servers.
   - Make sure the Management Server can connect to the required Check Point servers:

|     |     |
     | --- | --- |
     | Server | Command to Run on the Management Server |
     | `dl3.checkpoint.com` | `curl_cli [-x <ProxyAddress>:<ProxyPort>] -v http://dl3.checkpoint.com` |
     | `services.checkpoint.com` | `curl_cli [-x <ProxyAddress>:<ProxyPort>] -v --cacert $CPDIR/conf/ca-bundle.crt https://services.checkpoint.com` |
     | `updates.checkpoint.com` | `curl_cli [-x <ProxyAddress>:<ProxyPort>] -v --cacert $CPDIR/conf/ca-bundle.crt https://updates.checkpoint.com` |

- Proxy configuration (if needed).

For details, refer to [sk83520](https://support.checkpoint.com/results/sk/sk83520).
     - Multi-Domain Security Management Server / Domain Management Server:
       Configure the proxy settings in the Gaia Portal.
     - Single-Domain Security Management Server:
       You can configure the proxy settings in SmartConsole (in the Management Server object > Network Management > Proxy) or in Gaia Portal.
       **Note:** If you configure the proxy settings in SmartConsole, you must click **Menu** \> **Install database** \> select the Management Server object \> click **Install**.
4. The Sync to User Center feature uses CPDiag*. It must be the latest version.

* CPDiag is a software suite of tools designed to collect statistics, data, and metrics from Check Point products (Security Gateway/Management) and upload them to Check Point servers for analysis. The collected data is valuable for correlation and learning (for Check Point and customers with proactive support). The information collected by CPDiag contains parameters about the Security Gateway's health, use, events, errors, and configuration. For more information, see the section "Information sent to Check Point User Center" below. When you allow the uploading/downloading of data to Check Point, CPDiag updates on a monthly basis.

## How to configure "Sync with UserCenter" in SmartConsole

### In SmartConsole R80.10 and higher

In SmartConsole, on the left navigation panel, click " **Manage & Settings**" and click " **Sync with UserCenter**".

When synchronization is enabled, an update occurs one time each day.

**Note:** For Multi-Domain Sever, you must do the above procedure on a minimum of one Domain Management Server to sync with the UserCenter.

### In SmartDashboard R75.47 - R77.x

In SmartDashboard, go to the " **Help**" menu and click " **Sync with UserCenter...**".

Clicking the " **Synchronize now**" button runs an applicable script on the Security Management Server. The script collects information from the Security Management database and the managed Security Gateways and writes it into the `$FWDIR/conf/SMC_Files/SU/data_file.xml` file.

Checking the box " **Periodically sync server and gateways data with UserCenter**" runs the script one time each week.

When the information is sent to Check Point, the UserCenter presents it in the list of "Software Products & Appliances".

**Note:** In a Multi-Domain Security Management Server environment, this feature is only available in context of each Domain Management Server. Currently, it does not work in the MDS context.

## How to configure "Sync with UserCenter" with API

Support for the Management API commands:

- [Management API v2.0.1](https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction~v2.0.1) and higher
- [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm), Take 41 (PRJ-62454) and higher
- [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm), Take 115 (PRJ-62453) and higher

Management API Commands:

- To see the current configuration for "Sync with User Center":

`show sync-with-user-center`

- To configure "Sync with User Center":

`set sync-with-user-center`

## Information sent to Check Point User Center

This information is sent to Check Point User Center:

- Module name
- IP Address
- MAC Address
- Version
- Install Policy time stamp
- Appliance model
- Machine type (Security Gateway, Management, and more)
- OS
- Is this VSX?
- Cluster name
- Hit Count last time stamp
- APPI last update
- IPS last update
- Hardware (memory, CPU, network card, etc.)
- License data
- Active blades
- User/Kernel crash information
- Non Private CPView history statistics

## Error Messages and Warnings

### (1) Sync of Multi-Domain Management server with UserCenter fails  
**Symptoms**

- Although you configured the feature correctly, the "Sync with UserCenter" when upgraded from R77.x Multi-Domain Management fails with this message " _Warning: Uploading date to the Check Point UserCenter is not enabled. Please enable it in Global Domain > Global Properties > Security Management Access_".
- Despite the warning presented, the upload option is selected in Global Domain > Global Properties > Security Management Access.

**Cause**
   There is a database issue related to the _objects_0.C file in the R80.x Multi-Domain Security Management Server. This file is no longer in use by R80.x versions.
   
**Solution**

1. Connect to the command line on the Multi-Domain Security Management Server.
2. Log in to Expert mode.
3. Move the file to a different directory:
   `mv -v $FWDIR/conf/objects_5_0.C /home/admin/objects_5_0.C`
4. Make sure the file was moved:
   `grep -n "load_content" $FWDIR/conf/objects_5_0.C`

Example output:
   `grep: /opt/CPmds-R80/conf/objects_5_0.C: No such file or directory`
5. Connect with SmartConsole to the **Global Domain**.
6. Clear the checkboxes in **Global Properties** > **Security Management Access**.
7. Publish the changes.
8. Select the checkboxes in **Global Properties** > **Security Management Access**.
9. Publish changes.
10. Connect with SmartConsole to the **MDS** level.
11. Enable the "Sync with the UserCenter" again at the MDS level:
    1. In the left panel, click **Multi Domain**.
    2. Click **Sync with UserCenter**.
    3. Select **Synchronize information once a day**.
    4. Wait for the confirmation status " _Connected to the Check Point UserCenter_".

### (2) The option "Sync with UserCenter" is grayed out in SmartConsole connected to a Domain Management Server  
**Symptoms**

- The option " _Sync with UserCenter_" is grayed out in SmartConsole connected to a specific Domain Management Server

**Cause**
  OS information is missing in the _objects_0.c file below the Domain Management Server's object definition section.
  In the _objects_0.c file, below the Domain Management Server's object: 
  `: (<Name of Domain Management Server object>`
  ...  
  `:os_info ()`
  In a working environment is should look like this:  
  `: (<Name of Domain Management Server object>`
  ...  
  `:os_info (`
  `:AdminInfo (`
  `:chkpf_uid ("{<UID>}")`
  `:ClassName (os_info)`
  
**Solution**

1. Connect with SmartConsole to the Domain Management Server.
2. In the left panel, click **Gateways & Servers**.
3. Double-click the Domain Management Server object.
4. In the left panel, click **General Properties**.
5. Below the **Platform** section, click **Get** to fetch the OS information.

6. Click **OK**.
7. Publish the changes.

## Known Limitations

The product list does not show these devices:

- SmartLSM Gateway.
- Multiple devices with the same CK (Bundles SKUs, vSec).

For assistance, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
