> Source: [sk21534](https://support.checkpoint.com/results/sk/sk21534)

# sk21534 - How to configure and troubleshoot IPS protection "Malicious IPs" (DShield Storm Center)

| Property | Value |
|----------|-------|
| Solution ID | sk21534 |
| Date Created | 2003-07-31 |
| Last Modified | 2021-06-11 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

**Note: In order to block designated IP list, Check Point strongly recommend to use Custom Intelligence Feeds feature introduced in R80.30 - refer to** **[sk132193](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk132193)** .  

**Table of Contents:**

1. Introduction
2. Configuration and Important Notes
3. Troubleshooting
4. Debug
5. Related documentation
6. Related solutions
7. Revision history

Click Here to Show the Entire Article

### (1) Introduction {#Introduction}

Show / Hide this section  
> The range and sophistication of the techniques used by hackers and crackers to penetrate private networks is increasing all the time. Very few organizations can hope to maintain up-to-the-minute protection against the latest attacks.
>
> Network Storm Centers are collaborative initiatives that have been set up to help the beleaguered Security Administrator fight back. Storm Centers gather logging information about attacks. This information is voluntarily provided by organizations from across the world for the benefit of all. Storm Centers collate and present report on real-time threats to network security in a way that is immediately useful.
>
> One of the leading Storm Centers is SANS Dshield.org [http://secure.dshield.org](http://secure.dshield.org/). DShield.org gathers statistics and presents it as a series of reports at <http://feeds.dshield.org/block.txt>, which is a list of address ranges that are worth blocking.
>
> Check Point IPS database includes the IPS protection called "**`Malicious IPs`** " (in R6x versions, it was called "`Block malicious IPs`"), which downloads the list of blocked IP addresses and updates the Security Gateway's database of dynamic IP addresses.
>
> An agent (daemon) on each Security Gateway, on which the IPS protection "**`Malicious IPs`** " is enabled, receives the Block List of malicious IP addresses from the *Dshield.org*. After every refresh interval (the default is three hours), the agent takes the DShield Block List and populates the list of Dynamic Objects with the IP address ranges from that DShield Block List.

### (2) Configuration and Important Notes {#Configuration and Important Notes}

Show / Hide this section  
> **Procedure:**
>
> 1. Security Gateway / Cluster members must be able to connect to the Internet.
>
>    **Important Note:** If a Proxy server is used, then by default, STORMD daemon on Security Gateway / Cluster members will not be able to connect to DShield web site.  
>    Security Gateway's administrator must follow the "Solution" steps listed in the section "(3) Troubleshooting" -  
>    in the "Issue #3: Security Gateway is not able to download DShield BlockList through a Proxy server".
> 2. On Security Gateway / Cluster members, configure the DNS servers (should be reachable).
>
> 3. Enable the Implied Rule that allows the Security Gateway / Cluster members to accept its own outgoing packets:
>
>    |-----------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
>    | Where?                | How?                                                                                                                                                                                               | Example                                                                                                                                                                                                                        |
>    | In R8x SmartConsole   | 1. Go to the main ***Application Menu*** menu - click on the ***Global properties...*** 2. On the ***FireWall*** pane, check the box ***Accept Outgoing packets from the Gateway*** 3. Click on OK | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Global_properties.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Global_properties.png "Click the image to see it in full size in a new tab/window") |
>    | In R7x SmartDashboard | 1. Go to the ***Policy*** menu - click on the ***Global Properties...*** 2. On the ***FireWall*** pane, check the box ***Accept Outgoing packets from the Gateway*** 3. Click on OK                | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Global_properties.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Global_properties.png "Click the image to see it in full size in a new tab/window") |
>
>    Related solutions:
>    * [sk106251 - How to configure Security Gateway to accept its own traffic only to Check Point online services](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106251)
>    * [sk31832 - How to prevent ClusterXL / VRRP / IPSO IP Clustering from hiding its own traffic behind Virtual IP address](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk31832)
>    * [sk43401 - How to completely disable FireWall Implied Rules](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk43401)
> 4. Add an explicit rule to allow the Security Management Server / Domain Management Server and the Security Gateway / Cluster Members to connect to the DShield Storm Center *https://secure.dshield.org/feeds/block.txt* over the HTTPS protocol.
>
> 5. Enable the IPS protection ***Malicious IPs***:
>
>    |-----------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
>    | Where?                | How?                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
>    | In R8x SmartConsole   | 1. Go to the ***SECURITY POLICIES*** app 2. Click on the ***Threat Prevention*** header 3. At the bottom, in the ***Threat Tools*** section, click on the ***IPS Protections*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_1.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_1.png "Click the image to see it in full size in a new tab/window") 4. In the upper right corner, search for ***Malicious IPs*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_2.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_2.png "Click the image to see it in full size in a new tab/window") 5. Right-click on the ***Malicious IPs*** protection - click on ***Edit...*** 6. Select the relevant IPS profile that is assign to the relevant Security Gateway / Cluster - click on the ***Edit...*** icon [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_3.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_3.png "Click the image to see it in full size in a new tab/window") 7. Select the option ***Override with Action*** - select ***Drop*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_4.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R8x_4.png "Click the image to see it in full size in a new tab/window") 8. Click on OK 9. Click on Close |
>    | In R7x SmartDashboard | 1. Go to the ***IPS*** tab 2. In the left tree, click on ***Protections*** 3. Search for ***Malicious IPs*** (or expand *Protections* - expand *By Protocol* - expand *IPS Software Blade* - expand *Network Security* - click on the *DShield Storm Center* ) [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_1.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_1.png "Click the image to see it in full size in a new tab/window") 4. Right-click on the ***Malicious IPs*** protection - click on ***Details...*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_2.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_2.png "Click the image to see it in full size in a new tab/window") 5. Select the relevant IPS profile that is assign to the relevant Security Gateway / Cluster - click on the ***Edit...*** button 6. Select the option ***Override IPS Policy with*** - select either ***Prevent*** (recommended), or ***Detect*** [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_3.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/R7x_3.png "Click the image to see it in full size in a new tab/window") 7. Select the desired track option 8. Click on OK                                                                                                                   |
>
> 6. Install the Network Security policy and Threat Prevention policy on the relevant Security Gateway / Cluster object.
>
> 7. **CRUCIAL STEP:**   
>    On the Security Gateway, replace the current ***$FWDIR/conf/equifax.cer*** file with the modified certificate file,  
>    and on the Management Server, modify the value of the property ***SDT_DShieldStormCenter_downstream***.
>
>    In Apr 2017, it was discovered that the DShield web site's certificate has changed.  
>    As a result, Security Gateway will not be able to communicate with the DShield web site.
>
>    **Security Gateway's administrator must follow the "Solution" steps listed
>    in the section "(3) Troubleshooting" -**   
>    **in the "Issue #2: Security Gateway is not able to download DShield BlockList because in Apr 2017, DShield changed their SSL certificate".**
> 8. On Security Gateway / Cluster members, check that *stormd* process is running:
>
>    ***\[Expert@HostName:0\]# ps auxw \| grep stormd***
> 9. SmartLog / SmartView Tracker should show the following `Control` log:
>
>    ```
>    Type:           Control
>    Information:    StormAgentName: CPDShield
>                          StormAgentAction: Retrieve blocklist
>                          StormAgentMsg: IP blocklist updated with the following: range0, range1, range2, ...
>    ```
>
> 10. On Security Gateway / Cluster members, verify that the list of dynamic IP addresses that should be blocked was updated:
>
>     ***\[Expert@HostName:0\]# dynamic_objects -l***
>     Output should show the correct ranges of IP addresses as appears in the <http://feeds.dshield.org/block.txt>
>
> **Important Notes:**
>
> * The IPS protection "`Malicious IPs`" is *not* functional without connectivity to Check Point cloud service.
>
> * The IPS protection "`Malicious IPs`" is applied **before** any rules in the Rule Base.
>
> * The DShield Storm Center block list blocks the entire Class C (/24) subnets, not just individual IP addresses.
>
> * To verify the connectivity to the DShield Storm Center, run the following command on the Security Gateway:
>
>   **`[Expert@HostName:0]# curl [-v] https://secure.dshield.org/feeds/block.txt`**
> * When the IPS protection "Malicious IPs" is activated, SecureXL is not able to created Connection Templates (refer to [sk32578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk32578)).
>
> * The IPS protection "`Malicious IPs`" is *not* supported with IPv6 traffic.
>
> * The IPS protection "`Malicious IPs`" is *not* enforced, when converting Security Gateway R75.40VS and R76 to VSX Mode (refer to [sk79260](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk79260)).

### (3) Troubleshooting {#Troubleshooting}

Click Here to Show the entire section

Or click on each scenario...

* **Issue #1: Security Gateway is not able to download DShield BlockList because in Dec 2012, DShield changed the way they present their SSL certificate**  
  >
  > |------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  > | Symptoms   | * Log in SmartLog / SmartView Tracker shows: ``` Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Failed to access URL Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Data has expired. Clearing defined ranges ``` * *$FWDIR/log/stormd.elg* file on Security Gateway shows: ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x8) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * Output of '`dynamic_objects -l`' command on Security Gateway shows only the default range: ``` object name : CPDShield range 0 : 0.0.0.1       0.0.0.1 Operation completed successfully ```                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  > | Root Cause | In December 2012, the way the DShield Storm Center's SSL certificate is presented to Check Point Security Gateway, has changed. As a result, the validation of the `$FWDIR/conf/equifax.cer` certificate on Check Point Security Gateway fails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
  > | Issue ID   | * 00865963 * 00865965                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
  > | Solution   | **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster. 1. Install the required hotfix to process the DShield Storm Center's SSL certificate correctly. Note: This hotfix is integrated since *Check Point R75.45* 2. Replace the current certificate file *$FWDIR/conf/equifax.cer* with the modified certificate file (instead of the site's certificate, we use only the root certificate): 1. Download the modified certificate [from here](http://supportcontent.checkpoint.com/file_download?id=10163). Show / Hide the explanation > Check Point performed the following steps in order to solve the issue with the certificate that was reported in December 2012: > 1. Open this URL in your web browser: <https://secure.dshield.org> > 2. Click on the lock sign in the address bar to see the site's SSL certificate. > 3. As you can see: >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_1.png) >    1. This certificate was issued to **\*.dshield.org** (<http://www.dshield.org/>). >    2. This certificate was issued by **StartCom Class 2 Primary Intermediate Server CA** (<http://www.startssl.com/>). >    3. The Certification Path is: >       ``` >       StartCom Certification Authority >           StartCom Class 2 Primary Intermediate Server CA >               *.dshield.org >       ``` >       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_2.png) > 4. Click on '`StartCom Class 2 Primary Intermediate Server CA`' in Certification Path: >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_3.png) > 5. Click on '`View Certificate`'. > 6. As you can see: >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_4.png) >    1. This certificate was issued to **StartCom Class 2 Primary Intermediate Server CA**. >    2. This certificate was issued by **StartCom Certification Authority**. >    3. The Certification Path is: >       ``` >       StartCom Certification Authority >           StartCom Class 2 Primary Intermediate Server CA >       ``` >       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_5.png) > 7. Go to '`Details`' tab - click on '`Copy to File...`': >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk38492/Certificate_6.png) >    Certificate Export Wizard opens: >    1. Click '`Next`' - select the '`DER encoded binary X.509 (.CER)`' - click '`Next`'. >    2. Click on '`Browse...`': >       * Choose the location >       * Enter the file name - **equifax** >       * Click '`Save`'. >    3. Click '`Next`' and check the settings. >    4. Click '`Finish`'. >    5. Click '`OK`' in the confirmation pop up. > 8. Transfer the modified certificate to the Security Gateway (into some directory, e.g., */some_path_to_fix/*). <br /> <br /> 2. Transfer the modified certificate to the Security Gateway (into some directory, e.g., */some_path_to_fix/*). 3. Stop Check Point services: ***\[Expert@HostName:0\]# cpstop*** Note: Security Gateway will stop processing any traffic. In cluster, this can cause a fail-over. 4. Backup the current certificate: ***\[Expert@HostName:0\]# mv -v $FWDIR/conf/equifax.cer $FWDIR/conf/equifax.cer_BKP*** 5. Copy the modified certificate: ***\[Expert@HostName:0\]# cp -v /some_path_to_fix/equifax.cer $FWDIR/conf/equifax.cer*** 3. Start Check Point services: ***\[Expert@HostName:0\]# cpstart*** Note: In cluster, this can cause a fail-over. 4. SmartLog / SmartView Tracker should show the following logs: ``` Type:           Control Information:    StormAgentName: daemon StormAgentAction: Agent is up Type:           Control Information:    StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: IP blocklist updated with the following: range0, range1, range2, ... ``` 5. Verify that the list of dynamic IP addresses that should be blocked was updated: ***\[Expert@HostName:0\]# dynamic_objects -l*** Output should show the correct ranges of IP addresses as appears in the <http://feeds.dshield.org/block.txt> |

  <br />

  <br />

  {#Troubleshooting - Issue #1}
{#Troubleshooting - Issue #1}
* **Issue #2: Security Gateway is not able to download DShield BlockList because in Apr 2017, DShield changed their SSL certificate**  
  >
  > |------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  > | Symptoms   | * Log in SmartLog / SmartView Tracker shows: ``` Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Failed to access URL Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Data has expired. Clearing defined ranges ``` * *$FWDIR/log/stormd.elg* file on Security Gateway shows one of the following error codes: * ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x8) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x4) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * Output of '`dynamic_objects -l`' command on Security Gateway shows only the default range: ``` object name : CPDShield range 0 : 0.0.0.1       0.0.0.1 Operation completed successfully ``` * Debug of STORMD daemon on Security Gateway (refer to the "Debug" section) shows: ``` [stormd ...]@HostName[Date Time][CPDShield][] fwCert_FixChain_do: didn't find root ca in chain top [stormd ...]@HostName[Date Time][CPDShield][] fwCert_FixChain_do: Can't find the chains' root CA in my token [stormd ...]@HostName[Date Time][CPDShield][] ckpSSL_VerifyCallback: failed to fixed chain [stormd ...]@HostName[Date Time][CPDShield][] ckpSSL_NegotiateStep: Current step failed. Error is: 336134278 ``` * Checking the connectivity to *dshield.org* with `curl` command on Security Gateway fails with either one of the following errors: * ``` [Expert@HostName:0]# curl -v https://secure.dshield.org/feeds/block.txt * About to connect() to secure.dshield.org port 443 (#0) * Trying X.X.X.X... * connected * Connected to secure.dshield.org (X.X.X.X) port 443 (#0) * SSLv3, TLS handshake, Client hello (1): * SSLv3, TLS alert, Server hello (2): * error:<N>:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure * Closing connection #0 curl: (35) error:<N>:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure ``` * ``` [Expert@HostName:0]# curl -v https://secure.dshield.org/feeds/block.txt * About to connect() to secure.dshield.org port 443 (#0) * Trying X.X.X.X... * connected * Connected to secure.dshield.org (X.X.X.X) port 443 (#0) * SSLv3, TLS handshake, Client hello (1): * SSLv3, TLS handshake, Server hello (2): * SSLv3, TLS handshake, CERT (11): * SSLv3, TLS alert, Server hello (2): * SSL certificate problem: self signed certificate in certificate chain * Closing connection #0 curl: (60) SSL certificate problem: self signed certificate in certificate chain ```                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  > | Root Cause | In Apr 2017, it was discovered that the DShield web site's certificate has changed. As a result, the default certificate file *$FWDIR/conf/equifax.cer* on the Security Gateway will not work anymore.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
  > | Issue ID   | * 02508279 * 01863493                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
  > | Solution   | **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster. 1. On the Security Gateway, replace the current ***$FWDIR/conf/equifax.cer*** file with the modified certificate file as described below: Note: Instead of the site's certificate, we use only the root certificate. * Either install the hotfix to replace this file *automatically*: [Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification, please collect [CPInfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case. * Or replace this file *manually*: 1. Download the modified certificate [from here](http://supportcontent.checkpoint.com/file_download?id=55323). 2. Transfer the modified certificate to the Security Gateway (into some directory, e.g., */some_path_to_fix/*). 3. Backup the current certificate: ***\[Expert@HostName:0\]# mv -v $FWDIR/conf/equifax.cer $FWDIR/conf/equifax.cer_BKP*** 4. Copy the modified certificate: ***\[Expert@HostName:0\]# cp -v -f /some_path_to_fix/equifax.cer $FWDIR/conf/equifax.cer*** 5. Restart Check Point services (so that the new certificate file is loaded): ***\[Expert@HostName:0\]# cpstop ; cpstart*** Note: Traffic will be interrupted. In cluster, this can cause a fail-over. Show / Hide the explanation about the modified certificate file > Check Point performed the following steps in order to extract the relevant certificate: > 1. Open this URL in your web browser: <https://secure.dshield.org> > 2. Click on the lock sign in the address bar to see the site's SSL certificate. > 3. As you can see: >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Certificate_1.png) >    1. This certificate was issued to **dshield.org** >       (this URL is crucial for configuration of the property *SDT_DShieldStormCenter_downstream* in the management database). >    2. This certificate was issued by **Let's Encrypt Authority X3**. > 4. Go to the '`Certification Path`' tab. >    1. The Certification Path is: >       ``` >       DST Root CA X3 >           Let's Encrypt Authority X3 >               dshield.org >       ``` >    2. Click on the top line '`DST Root CA X3`' in Certification Path - click on the '`View Certificate`' button at the bottom. >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Certificate_2.png) > 5. In the '`Certificate`' window, go to the '`Details`' tab - click on the '`Copy to File ...`' button: >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Certificate_3.png) > 6. Certificate Export Wizard opens: >    1. Click '`Next`' - select the '`DER encoded binary X.509 (.CER)`' - click '`Next`'. >       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Certificate_4.png) >    2. Click on '`Browse...`': >       * Choose the location >       * Enter the file name - **equifax** >       * Click '`Save`' >    3. Click '`Next`' and check the settings. >    4. Click '`Finish`'. >    5. Click '`OK`' in the confirmation pop up. > 7. Transfer the modified certificate to the Security Gateway (into some directory, e.g., */some_path_to_fix/*). <br /> <br /> 2. On the Management Server, modify the value of the property ***SDT_DShieldStormCenter_downstream***: 1. Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.). Verify by running the "*cpstat mg* " command on Security Management Server / in the context of *each* Domain Management Server. 2. Connect to the command line on the Security Management Server / Multi-Domain Security Management Server. 3. Log in to the Expert mode. 4. On the Multi-Domain Security Management Server, switch to the context of the relevant Domain Management Server: ***\[Expert@HostName:0\]# mdsenv \<Name of IP of Domain Management Server\>*** * For version **R77.30 and below** : 1. Connect with the [dbedit](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=skI3301) utility to the management database: ***\[Expert@HostName:0\]# dbedit*** 2. Modify the value of the property *SDT_DShieldStormCenter_downstream*: ***dbedit\> modify sd_topics SDT_DShieldStormCenter_downstream blocklist_url "https://feeds.dshield.org/block.txt"*** **Important Note:** The URL (in this case, `.../dshield.org/...`) must be identical to the URL that appears in the certificate file in the "**`Issued to:`**". <br /> 1. Save the changes: ***dbedit\> update_all*** Output should show: `sd_topics::SDT_DShieldStormCenter_downstream Updated Successfully` <br /> 1. Exit from the dbedit: ***dbedit\> quit*** <br /> * For version **R80 and above** : 1. Download the script: changeSDT_DShieldStormCenter_downstreamBlockUrl.sh from **[HERE](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=61924)** 2. Copy the script to a temporary directory on the Security Management Server, and give it executable permission: **`# chmod +x changeSDT_DShieldStormCenter_downstreamBlockUrl.sh`** 3. Run the script with the command: **`# changeSDT_DShieldStormCenter_downstreamBlockUrl.sh "https://feeds.dshield.org/block.txt"`** 4. Refresh cache: any change in management would refresh it. 5. Connect with SmartDashboard to Security Management Server / Domain Management Server. 6. Make a rulebase change (such as changing the name of a rule), and publish the change. Afterwards, install the policy onto the relevant Security Gateway / Cluster object. 3. SmartLog / SmartView Tracker should show the following log: ``` Type:           Control Information:    StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: IP blocklist updated with the following: range0, range1, range2, ... ``` 4. On the Security Gateway, verify that the list of dynamic IP addresses that should be blocked was updated: ***\[Expert@HostName:0\]# dynamic_objects -l*** Output should show the correct ranges of IP addresses as appears in the <http://feeds.dshield.org/block.txt> |

  <br />

  <br />

  {#Troubleshooting - Issue #2}
{#Troubleshooting - Issue #2}
* **Issue #3: Security Gateway is not able to download DShield BlockList through a Proxy server**  
  >
  > |------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  > | Symptoms   | * Log in SmartLog / SmartView Tracker shows: ``` Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Failed to access URL Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Data has expired. Clearing defined ranges ``` * *$FWDIR/log/stormd.elg* file on Security Gateway shows: ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x4) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * Output of '`dynamic_objects -l`' command on Security Gateway shows only the default range: ``` object name : CPDShield range 0 : 0.0.0.1       0.0.0.1 Operation completed successfully ```                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  > | Root Cause | Although Proxy server is configured on Security Gateway, it tries to connect to *dshield.org* directly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
  > | Issue ID   | 01182483                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  > | Solution   | [Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification, please collect [CPInfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case. **Code was improved:** * Security Gateway (STROMD daemon) can now be configured to connect to *dshield.org* via a configured Proxy server. The new behavior is controlled by the attribute `DSHIELD_USE_PROXY` in the Check Point Registry. **Action plan:** Note: In cluster environment, this procedure must be performed on *all* members of the cluster. 1. Install the required hotfix and reboot. 2. To allow the Security Gateway to connect to *dshield.org* via a configured Proxy server, run: ***\[Expert@HostName:0\]# ckp_regedit -a SOFTWARE\\\\CheckPoint\\\\FW1\\\\$(cpprod_util CPPROD_GetCurrentVersion FW1) DSHIELD_USE_PROXY 1*** 3. Verify that the attribute was added: ***\[Expert@HostName:0\]# cpprod_util CPPROD_GetValue FW1 DSHIELD_USE_PROXY 1*** 4. To forbid the Security Gateway to connect to *dshield.org* via a configured Proxy server, run: ***\[Expert@HostName:0\]# ckp_regedit -d SOFTWARE\\\\CheckPoint\\\\FW1\\\\$(cpprod_util CPPROD_GetCurrentVersion FW1) DSHIELD_USE_PROXY*** |

  <br />

  <br />

  {#Troubleshooting - Issue #3}
{#Troubleshooting - Issue #3}
* **Issue #4: All traffic stopped passing through the Virtual System after enabling IPS protection "Malicious IPs" in the assigned IPS profile**  
  >
  > |------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  > | Symptoms   | * All traffic stopped passing through the Virtual System after enabling IPS protection "Malicious IPs" in the assigned IPS profile and installing the policy on that Virtual System. * Kernel debug in the context of the involved Virtual System ('`fw ctl debug -m fw + drop`') during the issue showed that traffic is dropped by a rule with abnormal number. *Example* : `;[vs_1];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto= ... dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1191182336;`                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  > | Root Cause | DShield Storm Center certificate (`$FWDIR/conf/equifax.cer`) exists only in the context of VSX Gateway itself (VS0). As a result, Virtual Systems are not able to update the blocklist, which in turn, causes them to block all traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
  > | Issue ID   | 01657311                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
  > | Solution   | [Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification, please collect [CPInfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case. Note: This hotfix is already integrated into the following versions: * R76SP.10 for 61000 / 41000 appliances - since *Take_67* of [R76SP.10 Jumbo Hotfix Accumulator](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103121) * [R76SP.20 for 61000 / 41000 appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105938) |

  {#Troubleshooting - Issue #4}
{#Troubleshooting - Issue #4}
* **Issue #5: Security Gateway is not able to download DShield BlockList because of a Host object with name "dshield.org"**  
  >
  > |------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  > | Symptoms   | * Log in SmartLog / SmartView Tracker shows: ``` Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Failed to access URL Origin:               	<Name of Security Gateway> Type:                 	Control Action: Information:      	StormAgentName: CPDShield StormAgentAction: Retrieve blocklist StormAgentMsg: Data has expired. Clearing defined ranges ``` * *$FWDIR/log/stormd.elg* file on Security Gateway shows one of the following error codes: * ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x8) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * ``` [stormd ...]@HostName[Date Time][CPDShield] Failed to get URL data (code=0x4) [stormd ...]@HostName[Date Time][CPDShield] Data has expired. Clearing defined ranges from object. ``` * Checking the connectivity to dshield.org with *curl* command on Security Gateway shows that the connection was successful. `[Expert@HostName:0]# curl -v https://secure.dshield.org/feeds/block.txt` * Debug of STORMD daemon on Security Gateway (refer to the "Debug" section) shows that Security Gateway tries to connect to some IP address that is not the resolved IP address of the *dshield.org*: ``` [stormd ...]@HostName[Date Time][] Snatcher: Host name resolved synchroniously. [stormd ...]@HostName[Date Time][] Snatcher: Resolving host name completed successfully. ... ... [stormd ...]@HostName[Date Time][fwasync] fwasync_make_connection_e_bindopt_ex: W.X.Y.Z/443: dowait is -1 sock is 13 ``` * Output of the "`nslookup dshield.org`" shows the correct IP address (and different than the IP address seen in the debug of STORMD daemon). *Example* : ``` [Expert@GW:0]# nslookup dshield.org Server: ... Address: ... Non-authoritative answer: Name: dshield.org Address: 204.51.94.155 ``` |
  > | Root Cause | A Host object was configured in SmartDashboard with the name "`dshield.org`" and the IP address that is seen in the debug of STORMD daemon. As a result, Security Gateway tries to connect to the wrong IP address. *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Example_of_Host_object_dshield.org.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk21534/Example_of_Host_object_dshield.org.png "Click the image to see it in full size in a new tab/window")                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
  > | Solution   | 1. Connect to the command line on the Security Gateway / each Cluster member. 2. Log in to the Expert mode. 3. Stop the STORMD daemon: ***\[Expert@HostName:0\]# kill $(pidof stormd)*** 4. In SmartDashboard, modify the Host object "`dshield.org`": * Either change the name of the Host object from "`dshield.org`" to some other domain * Or change the IP address of the Host object to the real IP address of the `dshield.org` 5. Install the policy. 6. Check if STORMD daemon was started on the Security Gateway / Cluster members: ***\[Expert@HostName:0\]# ps auxw \| grep stormd*** If not, then install the policy again. 7. On Security Gateway / Cluster members, verify that the list of dynamic IP addresses that should be blocked was updated: ***\[Expert@HostName:0\]# dynamic_objects -l***                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

  {#Troubleshooting - Issue #5}
{#Troubleshooting - Issue #5}

Related troubleshooting solutions:

* [sk116013 - NAT fails after policy installation](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116013)
* [sk97704 - Security Gateway may stop accepting new IPv4 connections when working with Dynamic Objects or with IPS protection 'Malicious IPs'](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97704)

### (4) Debug {#Debug}

Show / Hide this section  
> **Background:**
>
> To debug the main daemon *STORMD* on Security Gateway, it is necessary to start the debug of the FWD daemon and kill the STORMD daemon.  
> When the STORMD daemon is re-spawned automatically by the FWD daemon, the STORMD daemon will inherit the debug environment from the FWD daemon.
>
> **Follow this procedure on Security Gateway:**
>
> **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.
>
> 1. On SecurePlatform OS: Disable log rotation per Solution [sk52120](http://supportcontent.checkpoint.com/solutions?id=sk52120):
>
>    ***\[Expert@HostName:0\]# log list \| grep fwd***   
>    ***\[Expert@HostName:0\]# log unlimit 8***   
>    ***\[Expert@HostName:0\]# log list \| grep fwd***
> 2. Add a mark into log files:
>
>    ***\[Expert@HostName:0\]# echo '=debug_start=' \>\> $FWDIR/log/fwd.elg***   
>    ***\[Expert@HostName:0\]# echo '=debug_start=' \>\> $FWDIR/log/stormd.elg***
> 3. Start the debug of the FWD daemon (refer to [sk86321](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86321)):
>
>    ***\[Expert@HostName:0\]# fw debug fwd on TDERROR_ALL_ALL=5***
>    Note:  
>    It is possible to limit the scope of debug only to STORMD  
>    by using the `TDERROR_STORMD_ALL` instead of `TDERROR_ALL_ALL`.  
>    However, this is *not* recommended.
> 4. Determine the PID of the STORMD daemon:
>
>    ***\[Expert@HostName:0\]# ps auxw \| grep -v grep \| egrep "PID\|stormd"***
>
>    *Example output*:
>
>    ```
>    USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
>    root     17997  0.1  4.9 159612 19980 ?        S    15:22   0:00 stormd 0
>    [Expert@HostName:0]#
>    ```
>
> 5. Kill the STORMD daemon:
>
>    ***\[Expert@HostName:0\]# kill $(pidof stormd)***
> 6. Verify that the STORMD daemon was re-spawned (PID should change):
>
>    ***\[Expert@HostName:0\]# ps auxw \| grep -v grep \| egrep "PID\|stormd"***
>
>    *Example output*:
>
>    ```
>    USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
>    root     18103 28.5  4.9 159612 19720 ?        S    15:36   0:00 stormd 0
>    ```
>
> 7. Replicate the problem.
>
>    For example, install policy to trigger STORMD to download Blocklist from DShield web site.
> 8. Stop the debug of the FWD daemon (refer to [sk86321](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86321)):
>
>    ***\[Expert@HostName:0\]# fw debug fwd off TDERROR_ALL_ALL=0***
> 9. Add a mark into log files:
>
>    ***\[Expert@HostName:0\]# echo '=debug_stop=' \>\> $FWDIR/log/fwd.elg***   
>    ***\[Expert@HostName:0\]# echo '=debug_stop=' \>\> $FWDIR/log/stormd.elg***
> 10. On SecurePlatform OS: Re-enable log rotation per Solution [sk52120](http://supportcontent.checkpoint.com/solutions?id=sk52120):
>
>     ***\[Expert@HostName:0\]# log list \| grep fwd***   
>     ***\[Expert@HostName:0\]# log limit 8 64536 4***   
>     ***\[Expert@HostName:0\]# log list \| grep fwd***
> 11. Send the following to [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html):
>
>     * Description of the issue
>     * Relevant logs from SmartLog / SmartView Tracker
>     * `$FWDIR/log/fwd.elg*` files
>     * `$FWDIR/log/stormd.elg*` files
>     * `$CPDIR/log/cpwd.elg*` files
>     * [CPInfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) file from Security Gateway
>     * [CPInfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) file from Security Management Server

### (5) Related documentation {#Related documentation}

Show / Hide this section  
> * IPS Administration Guide ([R70](http://downloads.checkpoint.com/dc/download.htm?ID=8746), [R70.20](http://downloads.checkpoint.com/dc/download.htm?ID=10511), [R71](http://downloads.checkpoint.com/dc/download.htm?ID=10316), [R75](http://downloads.checkpoint.com/dc/download.htm?ID=11663), [R75.20](http://downloads.checkpoint.com/dc/download.htm?ID=12270), [R75.40](http://downloads.checkpoint.com/dc/download.htm?ID=13089), [R75.40VS](http://downloads.checkpoint.com/dc/download.htm?ID=16281), [R76](http://downloads.checkpoint.com/dc/download.htm?ID=22915), [R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24806), [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46525))
> * Firewall Administration Guide ([R70](http://downloads.checkpoint.com/dc/download.htm?ID=8738), [R71](http://downloads.checkpoint.com/dc/download.htm?ID=10309), [R75](http://downloads.checkpoint.com/dc/download.htm?ID=11660), [R75.20](http://downloads.checkpoint.com/dc/download.htm?ID=12267), [R75.40](http://downloads.checkpoint.com/dc/download.htm?ID=13088), [R75.40VS](http://downloads.checkpoint.com/dc/download.htm?ID=16261), [R76 Firewall Admin Guide](http://downloads.checkpoint.com/dc/download.htm?ID=22913) / [R76 Security Gateway Tech Admin Guide](http://downloads.checkpoint.com/dc/download.htm?ID=23622), [R77 Firewall Admin Guide](http://downloads.checkpoint.com/dc/download.htm?ID=24832) / [R77 Security Gateway Tech Admin Guide](http://downloads.checkpoint.com/dc/download.htm?ID=24836), [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46528) / [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46524))
> * Security Management Server Administration Guide ([R70](http://downloads.checkpoint.com/dc/download.htm?ID=8745), [R70.20](http://downloads.checkpoint.com/dc/download.htm?ID=10510), [R71](http://downloads.checkpoint.com/dc/download.htm?ID=10315), [R75](http://downloads.checkpoint.com/dc/download.htm?ID=11667), [R75.20](http://downloads.checkpoint.com/dc/download.htm?ID=12277), [R75.40](http://downloads.checkpoint.com/dc/download.htm?ID=13953), [R75.40VS](http://downloads.checkpoint.com/dc/download.htm?ID=16301), [R76](http://downloads.checkpoint.com/dc/download.htm?ID=22920), [R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24830), [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46534) / [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46535))
> * Command Line Interface Reference Guide ([R70](http://downloads.checkpoint.com/dc/download.htm?ID=8713), [R71](http://downloads.checkpoint.com/dc/download.htm?ID=10324), [R75](http://downloads.checkpoint.com/dc/download.htm?ID=11657), [R75.20](http://downloads.checkpoint.com/dc/download.htm?ID=12264), [R75.40](http://downloads.checkpoint.com/dc/download.htm?ID=13944), [R75.40VS](http://downloads.checkpoint.com/dc/download.htm?ID=16262), [R76](http://downloads.checkpoint.com/dc/download.htm?ID=22909), [R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24833))

### (6) Related solutions {#Related solutions}

Show / Hide this section  
> * [sk103154 - How to block traffic coming from known malicious IP addresses](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103154)
> * [sk112061 - How to create and view Suspicious Activity Monitoring (SAM) Rules](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112061)
> * [sk106251 - How to configure Security Gateway to accept its own traffic only to Check Point online services](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106251)
> * [sk94508 - Recommended Internet Access Settings for Automatic Downloads](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk94508)

### (7) Revision history {#Revision history}

Show / Hide this section  
>
> |--------------|----------------------------------------------------------------------------------------------------|
> | Date         | Description                                                                                        |
> | 01 June 2017 | "Troubleshooting" section - added Issue #5 (Host object with name "dshield.org")                   |
> | 29 Apr 2017  | Improved the configuration instructions - added references to the required hotfixes                |
> | 27 Apr 2017  | First release of the redesigned article, which contains the information from other merged articles |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
