Modifying Policy Installation timeouts

Modifying Policy Installation timeouts For large Policy base install, it may be necessary to increase the following timeout:

  • Between SmartConsole and SSecurity Management server.
  • Between the Security Management server and the Security gateway.


Increasing timeout between SmartConsole and Security Management server

Perform the following on the Security Management server machine:

  1. Run regedit and locate the following path:HKEY_CURRENT_USER\Software\CheckPoint\Management Clients\<version>\CheckPoint SmartDashboard
  2. Create a value named “ServerTimeout” of type DWORD, and assign its data an appropriate value in milliseconds.
  3. Run cpstop;cpstart
  4. Install the policy

Increasing the timeout between Security Management server and the Security Gateway

  1.  Stop the Security Management server. Run cpstop
  2.  Edit the $FWDIR/conf/objects_5_0.C file or use GuiDBedit.
  3.  Search for the property ‘install_policy_timeout‘ and change its value to 1000 as shown below:
    :install_policy_timeout (1000)Note: The number is in seconds and the default timeout is 600 seconds, increase as necessary.Path in GuiDGEdit:
    Global Properties -> firewall_properties -> install_policy_timeout 

4.  Save the file and start the Security Management server (‘cpstart‘)

5.  Install the policy.

About

fwknowledge.wordpress.com

Tagged with: , , ,
Posted in CheckPoint

Leave a comment