> Source: [sk163112](https://support.checkpoint.com/results/sk/sk163112)

# sk163112 - IPS Update fails while working with PTC (Private Threat Cloud)

| Property | Value |
|----------|-------|
| Solution ID | sk163112 |
| Date Created | 2019-10-28 |
| Last Modified | 2019-10-29 |
| Technical Level | General |

## Symptoms

- * When running a Management update in IPS, the update fails.
* Security Management server shows the status "Disconnected" in the PTC report.

## Cause

*/etc/hosts* has the right configuration for the PTC and there is connectivity from the Security Management server to the PTC. However, the PTC was not added on the Security Management servers (or added incorrectly), which causes the certificate of the PTC to be either different or not exist at all on the Security Management's ca-bundle.crt.

You can verify that the last certificate on the PTC (there are 2) matches the certificate on the Security Management server under 'User_CA':   
On PTC - *# cat /web/conf/server.crt*   
On Security Management - *# cat $FWDIR/bin/ca-bundle.crt*

## Solution

Run the following procedure to add PTC to the Security Management server:

1. Run: *\[Expert@:0\]# ptc_cli mgmt*
2. Select "\[2\] Configure Security Gateways or other Check Point devices".
3. Select "add an externally managed Private ThreatCloud" (or choose an existing one).
4. Follow the the wizard's instructions (add IP, confirm, etc.).

Once the procedure ends, you should see the status on the PTC changes to 'Connected'.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
