> Source: [sk131392](https://support.checkpoint.com/results/sk/sk131392)

# sk131392 - Manual Application Control & URL Filtering update fails on the Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk131392 |
| Date Created | 2018-07-12 |
| Last Modified | 2025-11-15 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R82 |
| OS | Gaia |
| Platform | Smart-1 |

## Symptoms

- * Manual and scheduled Application Control \& URL Filtering updates fail on the Security Management Server.
* There is connectivity from the Security Management Server to Check Point Servers (the user has followed the instructions in [sk83520](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk83520)).
* The output from FWM debug (see [sk86186](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86186)) shows an error referencing **FDT** (File Download Tool) similar to the following:  
  `[ERROR] FDT_get_data_imp: Failed to get data (curl error: -1) from https://updates.checkpoint.com/WebService/services/DownloadMetaDataService?wsdl`.
* TCP dumps show a re-transmission packet. Then the update fails in SmartConsole:  

  `[Expert@Management:0]# tcpdump -nnei (external interface) host (Check_Point_server)`  
  `
  tcpdump: verbose output suppressed, use -v or -vv for full protocol decode`  
  `
  listening on eth4, link-type EN10MB (Ethernet), capture size 96 bytes`  
  `
  15:45:41.039284 00:15:5d:28:e7:40 > 28:6f:7f:04:88:e4, ethertype IPv4 (0x0800), length 74: (Management_IP)607 > (Check_Point_server).443: S 96483855:96483855(0) win 5840 `  
  15:45:41.119798 00:1c:7f:85:6a:64 > 00:15:5d:28:e7:40, ethertype IPv4 (0x0800), length 74: (Check_Point_server).443 > (Management_IP).47607: S 1391224950:1391224950(0) ack 96483856 win 4000   
  15:45:41.119826 00:15:5d:28:e7:40 > 28:6f:7f:04:88:e4, ethertype IPv4 (0x0800), length 54: (Management_IP).47607 > (Check_Point_server).443: R 96483856:96483856(0) win 0  

  [Expert@Gateway:0]# tcpdump -nnei (external interface) host (Check_Point_server)  
  tcpdump: verbose output suppressed, use -v or -vv for full protocol decode  
  listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes  
  15:04:34.773379 00:1c:7f:85:6a:62 > 00:17:54:02:c0:35, ethertype IPv4 (0x0800), length 74: (Management_IP).47349 > (Check_Point_server).443: S 311121485:311121485(0) win5840

## Cause

The File Download Tool (FDT) is not working properly. The FWD needs to be restarted (see instructions below).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
