> Source: [sk157492](https://support.checkpoint.com/results/sk/sk157492)

# sk157492 - CME (Cloud Management Extension) for Cloud Firewall Release Updates

| Property | Value |
|----------|-------|
| Solution ID | sk157492 |
| Date Created | 2019-07-10 |
| Last Modified | 2026-09-29 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server, Cloud Firewall |
| Versions | R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Solution

**Introduction \| Installation \| Availability \| Documentation \| List of Resolved Issues \| Installation Troubleshooting**

Introduction {#Introduction}
----------------------------

The **Cloud Management Extension (CME)** is a utility that runs on Check Point Security Management Servers and Multi-Domain Security Management Servers deployed in the cloud or on-premises.

This utility allows integration between Check Point Cloud Firewall solutions (formerly known as CloudGuard Network) and cloud platforms such as AWS (Amazon Web Services), Azure, and GCP (Google Cloud Platform).

**Important Notes:**   

* It is important to keep CME up to date with Automatic Updates. To get CME with Automatic Updates, remove any CME installation you did with CPUSE (refer to [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449) for detailed uninstall instructions).
* Before installing the package, check the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm) \> **Limitations.**

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170636/CME architcture1202305281203214.jpg)

<br />

Scale sets are a way to automatically adjust the number of virtual machines (VMs) based on how much the application needs. When the demand for the application increases, scale sets add more VM instances (scale-out). On the other hand, when the demand decreases, scale sets reduce the number of VM instances (scale-in).  

CME continuously monitors the cloud environment to detect scaling events performed by the cloud platform. When a scale-out or scale-in event occurs, CME automatically creates or removes the corresponding Gateway objects in SmartConsole. This ensures that SmartConsole remains synchronized with the current set of deployed Gateways.

Installation {#Installation}
----------------------------

The CME package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B). Follow the steps of the *Installation Procedure for Online Package* below to complete the setup.

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the CME package manually using the *Installation Procedure for Offline Package* below.  

**Installation Procedure for Online Package**

Show / Hide this section  
>
> 1. Connect to the Security Management Server terminal and enter Expert mode.
> 2. Run the `autoupdatercli enable CME` command   
>    Command Result Example  
>    > `[Expert@mgmt-aws:0]# autoupdatercli enable CME`  
>    > `updates state changed to on for component CME`
>
> You can verify if CME is installed using one of these commands:   
>
> * Run the `autoprov-cfg -v` command. If the command is recognized and returns CME's installed version, then CME is installed.   
>   Command Result Example  
>   > `[Expert@mgmt-aws:0]# autoprov_cfg -v`  
>   > `CME Version: Build: 991592434 Take: 286`
>
> <!-- -->
>
> * Run the `autoupdatercli show | grep -A 30 CloudGuard` command. CME should be listed in the list of products with enabled autoupdating.   
>   Command Result Example  
>   > `[Expert@mgmt-aws:0]# autoupdatercli show | grep -A 30 CloudGuard`  
>   > ` product-name: CloudGuard_IaaS`  
>   > ` `  
>   > ` component-name: CME`  
>   > ` component-branch: cme_AutoUpdate`  
>   > ` GA-Version: 0`  
>   > ` download-scheduler-active: true`  
>   > ` install-scheduler-active: true`  
>   > ` download-action: idle`  
>   > ` install-revert-action: idle`  
>   > ` `  
>   > ` installation-date: 2024-11-18_14:39:15`  
>   > ` package-branch-name: cme_AutoUpdate`  
>   > ` package-version: 286`  
>   > ` package-name: Check_Point_CME_AUTOUPDATE_Bundle_T286_FULL.tgz`  
>   > ` package-installed: true`  
>   > ` package-installable: true`  
>   > ` package-previously-installed: false`

**Installation Procedure for Offline Package**

Show / Hide this section  
> 1. Transfer the offline package to your Management Server (to some directory).
>
> 2. Connect to the command line on the Management Server.
>
> 3. Log in to the Expert mode.
>
> 4. Run:
>
>    `autoupdatercli install /<Full Path>/<Name of Package>`
>    Example:   
>    `[Expert@Host]# autoupdatercli install /var/log/Check_Point_CME_AUTOUPDATE_Bundle_T144_AutoUpdate.tar`   
>    On the Scalable Platform Security Group: `g_all autoupdatercli install <full path to TAR file>`
>
>    <br />
>
>    To make sure the installation was successful, examine this log file:
>
>    `/opt/CPInstLog/AutoUpdateLogs/CME `

**Important Notes for Management High Availability**
:

* In a Management High Availability environment, install the CME package on all servers one after another. All servers must run the same version.
* After completing the installation, verify that all servers run the same version. Run the command "*autoprov-cfg -v*" on each server with CME installed.

Availability {#Availability}
----------------------------

|--------------|------------------|------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Take #**   | **Release Type** | **Release Date** | **Download Package Link**                                                                                                                             |
| **Take 326** | **Recommended**  | 30 Aug 2026      | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk157492/download-m1907081212.png)](https://support.checkpoint.com/results/download/145000) (TAR) |
| **Take 331** | **Latest**       | 22 Sep 2026      | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk157492/download-m1907081212.png)](https://support.checkpoint.com/results/download/145669) (TAR) |

Documentation {#Documentation}
------------------------------

* [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm)

List of Resolved Issues and New Features per CME Update {#List of Resolved Issues}
----------------------------------------------------------------------------------

Enter the string to filter this table:

|--------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                                                                                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 331 Gradual deployment from 22 Sep 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| CGNSPC-3467                                                                                            | Automatic policy reinstall after scale-in keeps PDP Gateways synchronized with Security Management.                                                                                                                                                                                                                                                                                                                                      |
| CGNSPC-1188                                                                                            | Added support for Azure VMSS Flexible Orchestration mode.                                                                                                                                                                                                                                                                                                                                                                                |
| CGNSPC-3444                                                                                            | Various improvements.                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Take 326 Gradual deployment from 30 Aug 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| CGNSPC-4040, CGNSPC-3987, CGNSPC-3398, CGNSPC-4009, CGNSPC-2190, CGNSPC-3906, CGNSPC-4069              | Various improvements.                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Take 325 Gradual deployment from 19 Jul 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| CGNSPC-1491, CGNSPC-1495, CGNSPC-2111, CGNSPC-1961, CGNSPC-2027, CGNSPC-2064, CGNSPC-2317, CGNSPC-3140 | Enhancement: Added CME support for Alibaba Cloud auto scale.                                                                                                                                                                                                                                                                                                                                                                             |
| CGNSPC-1942, CGNSPC-3113                                                                               | Enhancement: Added support for Alibaba Cloud in CME API version 1.4.                                                                                                                                                                                                                                                                                                                                                                     |
| CGNSPC-2199, CGNSPC-2205, CGNSPC-2156, CGNSPC-195                                                      | Additional improvements.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Take 324 Gradual deployment from 17 May 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| CGNSPC-1485                                                                                            | Enhancement: Improved CME health check orchestration to ensure configuration is applied in a proper sequence with the Repository Gateway script.                                                                                                                                                                                                                                                                                         |
| CGNSPC-2028                                                                                            | Enhancement: CME API v1.3.2 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.3.2).                                                                                                                                                                                                                                                                                                         |
| VSECPC-11996, CGNSPC-203                                                                               | Added support for dual-arm (2-arm) GWLB gateway deployments.                                                                                                                                                                                                                                                                                                                                                                             |
| CGNSPC-1483, CGNSPC-2036, CGNSPC-1925                                                                  | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 323 Gradual deployment from 26 April 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ||
| HAAN-2410                                                                                              | Enhancement: Added support for multi-compartment deployment for OCI.                                                                                                                                                                                                                                                                                                                                                                     |
| CGNSPC-1314 CGNSPC-925, CGNSPC-224, CGNSPC-241, CGNSPC-653                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 321 Gradual deployment from 05 April 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ||
| CGNSPC-1366                                                                                            | Enhancement: Improved GCP Automatic Health Probe provisioning compatibility for R81.20 Security Gateways managed by R82.10 or higher Security Management Servers.                                                                                                                                                                                                                                                                        |
| VSECPC-11996                                                                                           | Enhancement: Improved the resilience to AWS sub?account scan failures.                                                                                                                                                                                                                                                                                                                                                                   |
| CGNSPC-1473                                                                                            | Enhancement: Improved the Security Gateway provisioning stability on platforms that do not support Health Check configuration (such as NSX-T).                                                                                                                                                                                                                                                                                           |
| CGNSPC-1368                                                                                            | Enhancement: Improved liveness check reliability during scale-in events.                                                                                                                                                                                                                                                                                                                                                                 |
| CGNSPC-941, CGNSPC-331, CGNSPC-548                                                                     | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 320 Offline release - 16 February 2026 Gradual deployment from 08 March 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                            ||
| CGNSPC-833, CGNSPC-323, VSECPC-11578, CGNSPC-969                                                       | Enhancement: Added Dual-Stack support for Azure, GCP, OCI and AWS Autoscale.                                                                                                                                                                                                                                                                                                                                                             |
| CGNSPC-374                                                                                             | Enhancement: GCP management name comparison is now case-insensitive.                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-12530                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 319 (02 February 2026)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-12679 VSECPC-12204 VSECPC-11857 VSECPC-11163 VSECPC-11164                                       | Enhancement: Added CME events integration with AIOps for improved monitoring.                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-12232                                                                                           | Enhancement: Added support for RFC 7231 4.3.6 behavior when using proxy.                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-11222, VSECPC-11221, VSECPC-12217                                                               | Enhancement: Enhanced AWS Sub-Account Scanning CME now automatically skips failed AWS sub-accounts and continues scanning the remaining sub-accounts and the main account, ensuring uninterrupted coverage and improved reliability.                                                                                                                                                                                                     |
| VSECPC-10949, VSECPC-11996, VSECPC-12862                                                               | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 318 (02 December 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-10977                                                                                           | Enhancement: R82.10 version is now supported.                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11691, VSECPC-11324, VSECPC-11178                                                               | Enhancement: Added CME reporting integration with AIOps for improved visibility and monitoring.                                                                                                                                                                                                                                                                                                                                          |
| VSECC-2994, VSECPC-12191, VSECPC-11694                                                                 | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 317 (19 November 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                 |
| VSECNSX-1979                                                                                           | Enhancement: Nutanix controller now supports paginated discovery of more than 20 agent VM entities, removing the previous entity limit.                                                                                                                                                                                                                                                                                                  |
| VSECPC-11679                                                                                           | Some rules may have duplicates when the source is "Any" and when using "aws-automatic-policy".                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11845, PMTR-120941, VSECPC-12000                                                                | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 311 (06 November 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-11695, VSECPC-11373                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 310 (07 August 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                               |
| VSECPC-11184                                                                                           | Enhancement: Added a deprecation notice to CLI utilities -- *autoprov_cfg* , *cme_menu* , *tgw_menu* . Users are advised to transit to the CME GUI or CME API for configuration as detailed in the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm).                                                                                                    |
| VSECPC-11189                                                                                           | Setting the "*health-check-ip-range*" parameter for an AWS template and using a CME API command fails with an exception during the configuration validation process.                                                                                                                                                                                                                                                                     |
| VSECPC-11139, VSECPC-11125                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 308 (21 July 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-10993                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (Taipei).                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-10891, VSECPC-11065, VSECPC-10935, VSECPC-10569                                                 | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 307 (22 June 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-10493                                                                                           | Enhancement: Extended STS role field validation to include support for role IDs in AWS China and AWS GovCloud regions.                                                                                                                                                                                                                                                                                                                   |
| VSECPC-10879, VSECPC-10932                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10171                                                                                           | Migrating AWS controller to the new "aws-automatic-policy" causes duplicated Access Rules to appear in the resulting policy.                                                                                                                                                                                                                                                                                                             |
| **Take 304 (29 May 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-10480                                                                                           | Enhancement: CME API v1.3.1 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.3.1).                                                                                                                                                                                                                                                                                                         |
| VSECPC-10374                                                                                           | Enhancement: Added the "*scan_subnets_6*" parameter for IPv6 support in AWS Gateway Load Balancer (GWLB).                                                                                                                                                                                                                                                                                                                                |
| **Take 303 (11 May 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-10236, VSECPC-10003, VSECPC-9307, VSECPC-10374, VSECPC-10715, VSECPC-10602                      | Enhancement: CloudGuard Network for AWS Gateway Load Balancer Auto Scaling Group now supports IPv6 traffic enforcement, including subnets scan. Refer to [Cloud Firewall Network for AWS Gateway Load Balancer Auto Scaling Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm) \> Traffic Enforcement in Servers Subnets with CME. |
| **Take 301 (17 April 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-7167                                                                                            | Enhancement: To prevent the accidental installation of restrictive policies on all gateways, the installation targets are now changed to "specific gateway" by default.                                                                                                                                                                                                                                                                  |
| VSECPC-10309                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 300 (18 March 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-5770                                                                                            | Enhancement: Disabled the ability to change CME configuration from Standby members in a High Availability environment.                                                                                                                                                                                                                                                                                                                   |
| VSECPC-10332                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10290                                                                                           | An issue related to GCP. Updated the *user.def* file path to ensure compatibility with R82 Security Management.                                                                                                                                                                                                                                                                                                                          |
| VSECPC-10377                                                                                           | An incorrect Gateway kernel parameter is addressed in the Health Check process during auto provisioning.                                                                                                                                                                                                                                                                                                                                 |
| **Take 299 (23 February 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-10315                                                                                           | Enhancement: * Added CME support for OCI (Oracle Cloud Infrastructure) auto scale. * Updated CME schema version to v1.1.8. * Added support for Azure IAM in CME API version 1.3.                                                                                                                                                                                                                                                         |
| VSECPC-10249                                                                                           | Enhancement: In Azure vWAN Ingress, increased the Load Balancer rule provisioning timeout.                                                                                                                                                                                                                                                                                                                                               |
| **Take 297 (30 January 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-10157, VSECPC-9974                                                                              | Enhancement: Updated CME schema version to v1.1.7                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-9990, VSECPC-9989, VSECPC-9841, VSECPC-9842, VSECPC-9843                                        | Enhancement: Added support for Azure IAM in CME API version 1.2.3.                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-10206                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (Thailand).                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-10285                                                                                           | Enhancement: Added support for the new AWS region: Mexico (Central).                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-10074                                                                                           | When using Azure vWAN Automatic Provisioning through CME API, the Autonomous Threat Prevention and Identity Awareness Blades are configured even when the flags are set to "false".                                                                                                                                                                                                                                                      |
| **Take 294 (20 January 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-9739                                                                                            | Enhancement: Improved CME API performance.                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-8960                                                                                            | Enhancement: CME is no longer supported on R80.40 Security Management Server.                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-9853                                                                                            | Minor fix.                                                                                                                                                                                                                                                                                                                                                                                                                               |

{#Unique_IDTable}

Installation Troubleshooting {#Installation Troubleshooting}
------------------------------------------------------------

The issues described below may occur when you run the CME installation script. Error messages may be similar to those listed below.

* **Issue 1: "Failed to download latest CME package. If you have no internet access please follow the instructions for offline installation in sk157492."**   
  > Solution: CME package failed to download. Make sure there is a connection to the Internet, or follow these steps for offline installation:
  > 1. Connect to the command line on the Management Server.
  >
  > 2. Log in to the Expert mode.
  >
  > 3. Get the AutoUpdater Build Number:
  >
  >    *cpvinfo /opt/AutoUpdater/latest/bin/AutoUpdater \| grep "Build Number"*
  >
  >    If the value of the "*Build Number* " in the output is lower than 990180162, do the procedure for **Issue # 3** and only then continue with the next steps below.
  > 4. Get the latest CME version from the "Availability" section.
  >
  > 5. Transfer the CME package to the Management Server (to some directory).
  > 6. Run:
  >
  >    *autoupdatercli install /\<Full Path\>/\<Name of Package\>*

  <br />

* **Issue 2: "A version of CME is already installed via AutoUpdater..."**   
  > **Solution** : CME has already been installed for the first time and is configured to receive updates automatically. If you have no internet access, follow the instructions for offline installation as described in the solution to **Issue # 1** above.

  <br />

* **Issue 3: "AutoUpdater is not installed on the machine - please install the minimal JHF version as described in sk157492 and try again."**   
  > **Solution**: Install the correct Jumbo Hotfix Accumulator as described in the beginning of the Known Limitations section. If the correct Jumbo Hotfix Accumulator is installed, but the issue persists, the follow these steps and then try again:
  > 1. [Get this AutoUpdater RPM](https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=106362).
  >
  > 2. Transfer the package to your Management Server (to some directory).
  >
  > 3. Connect to the command line on the Management Server.
  >
  > 4. Log in to the Expert mode.
  >
  > 5. Updated the current RPM package:
  >
  >    *rpm -Uhv --force \<Full Path to AutoUpdater RPM\>*
  > 6. Stop the AutoUpdater service:
  >
  >    *autoupdatercli stop*

  <br />

* **Issue 4: "Failed to verify if CME installation completed successfully..."**   
  > The installation could not verify if CME has been successfully downloaded and installed.
  >
  > **Solution** : Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach these log files:
  > * */opt/CPInstLog/AutoUpdateLogs/CME*
  > * */var/log/CPcme/cme_installation.log*

  <br />

* **Issue 5: When you run the script you get an output that instructs you to contact Check Point Support.**   
  > **Solution** : Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach these log files:
  > * */opt/CPInstLog/AutoUpdateLogs/CME*
  > * */var/log/CPcme/cme_installation.log*

  <br />

* **Issue 6: I want to return to previous version of CME**   
  > **Solution**: It is highly recommended that you use the latest take of CME.
  >
  > If you still want to revert to the previous take, run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli revert CME*
  >
  > The revert takes up to 1 minute.
  >
  > To make sure CME was reverted to the previous take, run this command in the Expert mode on the Management Server:
  >
  > *cpinfo -y CPUpdates 2\>\&1 \| grep BUNDLE_CME_AUTOUPDATE*
  >
  > The take number in the output must be the one to which you reverted.
  >
  > **Notes**:
  > * CME is upgraded automatically each time a new take is released.
  > * You can revert only to the previous version. A revert to older versions reverts CME completely and removes it from the Management Server.

  <br />

* **Issue 7: I want to totally remove CME**   
  > **Solution**: Run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli revert-completely CME*
  >
  > The revert takes up to 1 minute.
  >
  > To make sure the CME was reverted completely, run this command in the Expert mode on the Management Server:
  >
  > *cpinfo -y CPUpdates 2\>\&1 \| grep -c BUNDLE_CME_AUTOUPDATE*
  >
  > The output must show "0".
  >
  > If you also wish to stop receiving future updates of CME after the removal, run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli disable CME*

  <br />

* **Issue 8: CME cannot start or cannot revert to an old CME take**   
  > **Symptoms** :   
  > 1) " *Starting cme: failed to run* " error appears during CME revert.   
  > 2) CME installation fails after CME revert-completely.   
  > 3) CME fail to start, and */var/log/CPcme/cme.log* contains " *bad decrypt* " or " *Failed to load CME configuration due to incompatible schema* " error.   
  > 4) CME from take 212 or higher is installed only on the active server, and CME on the standby member fails to start.   
  >
  > **Cause** :   
  > 1) Starting CME take 212 CME configuration has a schema version   
  > 2) The schema version attribute ensures that only compatible CME runs with the given CME configuration.   
  > 3) CME does not run when the CME configuration schema version is incompatible.   
  > 4) Example scenarios that can cause incompatibility:   
  >
  > a. Revert to older CME take.   
  > b. Upgrade -- export configuration and import it on a server with an older CME take.   
  > c. High Availability Management/Multi-Domain servers where the CME on the two members is not from the same take.   
  >
  > **Note** - CME configuration file is not reverted.   
  >
  > **High Availability Scenario** :   
  >
  > 1) CME configuration file is synchronized between the members.   
  > 2) CME loads the configuration during CME boot.   
  > 3) If the CME on the standby member is from an older take, it will fail to start because CME is not compatible with the schema version.   
  >
  > **Notes** :   
  > * Because CME configurations are stored in *$MDSDIR/conf*, the active server is the member with the active global domain.
  > * CME must not run on the standby member of a Security Management Server.
  >
  > <br />
  >
  > **Downgrade scenario** :   
  > When reverting to old CME take (revert or revert-completely + install) and the old CME is not compatible with the schema version, CME does not start.   
  >
  > **Solution** :   
  >
  > **High Availability scenario** :   
  > Install the same CME take in all the High Availability servers.   
  >
  > **Downgrade scenario** :   
  > Run " *autoprov_cfg show all* " and examine the schema version value, install a CME that supports the existing schema version value.   
  >
  <br />

  <br />

* **Issue 9: CME upgrade fails with error "*Step Install Hotfix Action verification failed*"**   
  > **Symptoms** :  
  > 1)The "*Step Install Hotfix Action verification failed* " error when running CME upgrade with installation script on Management HA environment, and the upgrade fails.  
  > 2) A CME upgrade with the Offline package procedure based on [sk157492](https://support.checkpoint.com/results/sk/sk157492)fails.  
  > 3) Review of the log in */opt/CPInstLog/AutoUpdateLogs/CME* shows installation fails with this message:  
  > *"Error: Action Install Bundle Action aborted: step Install Hotfix Action verification failed".*   
  > 4) Happens for CME package online or for offline installation.  
  >
  > **Cause** :  
  > 1) A RPM installation fails, causing the CME installation to fail.  
  > TheIssue only relevant for machines running with last Deployment installer Take 26.   
  >
  > **Solution** :  
  >
  > **To verify the component version** on the machine, run this command in Expert mode:  
  >
  > `# cpvinfo /opt/CPDepInst/latest/bin/da_installer`  
  >
  > The issue will be resolved in Deployment installer higher than Take 26. Refer to [sk181911](https://support.checkpoint.com/results/sk/sk181911).  
  >
  > **To upgrade the CME** , use this workaround:  
  >
  > 1. Revert the CME installation and install the new CME package manually.   
  > 2. To revert the current CME package run:   
  > `# autoupdatercli revert-completely CME`  
  > 3. Install the new package manually or run "`autoupdatercli stop`" to restart the autoupdate process and run the installation again. For details, refer to [sk157492](https://support.checkpoint.com/results/sk/sk157492).   
  >
  > **Note** : You can safely revert the CME. It does not delete the current configuration.  
  >
  <br />

  <br />

* **Issue 10: CME GUI shows "*CME is not available*"**   
  > **Symptoms** :  
  > 1)When openning the CME GUI, there is a warning banner that says that CME is not available.  
  >
  > **Cause** :  
  > 1) CME is not installed.  
  > 2) CME does not meet the minimum requirement (Take 288).  
  > 3) CME API is not running.  
  >
  > **Solution** :  
  >
  > 1) Connect to the Security Management Server in Expert mode.  
  > 2) Verify that you installed CME Take 288 or later. For installation instructions, follow this sk.  
  > 3) After the CME installation, run `wsc restart`.  
  > 4) Make sure CME API is running with `service cme_api status`. If the service is not running, start it with `service cme_api start`.  
  >
  <br />

  <br />

* **Issue 11: R81.10 Management Server does not get the latest CME online package**   
  > **Symptoms** :  
  > 1)This error shows in the */opt/CPInstLog/Autoupdater.log* file:  
  > `Problem with local certificate Error code: 10`  
  > `...Abandoned file removed from the system`  
  > `...Failed to download metadata package for component auto_updater`  
  >
  > **Solution** : Refer to [sk184474](https://support.checkpoint.com/results/sk/sk184474).  
  >
<br />

* **Issue 12: "Failed to connect to bus" error is displayed and services do not start on a Management Server with CME**   
  > **Symptoms** :  
  > 1) Every systemctl command fails with `"Failed to connect to bus: No such file or directory".`  
  > 2) The reboot, shutdown, running `cpstart/cpstop` commands, Multi-Domain Server start-up, and CPUSE operations hang or fail.  
  > 3) The` /var/log/messages` contains `"cme.service: Supervising process which is not our child" followed by "Freezing execution".`  
  >
  > **Casue:** On a server upgraded to R82.10 or higher, an earlier CME registration with the Gaia process manager can remain active alongside the native systemd units, so both mechanisms try to start cme/cme_api.  
  >
  > **Solution** : Refer to [sk1000185](https://support.checkpoint.com/results/sk/sk1000185).  
  >
If your issue cannot be resolved by any of the above solutions, contact Check Point Support and attach the log files located in the */opt/CPInstLog/AutoUpdateLogs/CME* directory.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
