Support Center > Search Results > SecureKnowledge Details
Policy installation might fail with "ERROR: stab identifier <lsv_profiles> for host redefined" in certain scenario when DLP blade is used
Symptoms
  • Policy installation might fail with "ERROR: stab identifier <lsv_profiles> for host redefined" in the following scenario:

    1. R77.30 Security Management Server running on Gaia OS or IPSO OS.
    2. There are two R77.x Security Gateways / Clusters (e.g., "GW_1" and "GW_2") managed by this server:
      • "GW_1" has IPSec VPN blade enabled
      • "GW_2" has DLP blade enabled, IPSec VPN blade disabled, and belongs to VPN Encryption Domain of "GW_1"
Solution

Check Point offers a hotfix for this issue for R77.30 Security Management Server running on Gaia OS and on IPSO OS.

Important Note: This hotfix was already integrated into R77.30 Security Management Server running on SecurePlatform OS, Linux OS and Windows OS, effective May 27, 2015. For details, refer to R77.30 Home Page.

Click Here to Show Entire Article

 

Installation instructions

  • Hotfix package for R77.30 - Gaia OS using CPUSE (Check Point Update Service Engine)

    • Online installation

      1. Connect to the Gaia Portal on R77.30 Security Management Server / Multi-Domain Security Management Server and navigate to Upgrades (CPUSE) pane - click on Status and Actions.
      2. Select the hotfix package R77.30 Hotfix for sk106196 (Policy installation fails with "ERROR: stab identifier for host redefined") - click on Install Update button on the toolbar.
      3. When the hotfix installation completes, log in to Expert mode and start Check Point services with "cpstart" command.


    • Offline installation

      In order to download this package you will need to have a Software Subscription or Active Support plan.

      OS R77.30
      Gaia - CPUSE

    Notes:

    • Hotfix has to be installed on R77.30 Security Management Server / Multi-Domain Security Management Server running on Gaia OS.
    • For detailed installation instructions, refer to sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent) - section "(4) How to work with CPUSE".
    • Make sure to take a snapshot of your Check Point machine before installing this hotfix.
    • In Management HA environment, this procedure must be performed on both Management Servers.


  • Hotfix package for R77.30 - Gaia OS (manual installation in Command Line)

    In order to download this package you will need to have a Software Subscription or Active Support plan.

    OS R77.30
    Gaia - CLI

    Procedure:

    1. Hotfix has to be installed on R77.30 Security Management Server / Multi-Domain Security Management Server running Gaia OS.
    2. Download the relevant hotfix package from the table below, transfer the hotfix package to the machine and unpack it:
      [Expert@HostName]# tar -zxvf Check_Point_Hotfix_R77.30_Gaia_sk106196.tgz
    3. Install the hotfix:
      [Expert@HostName]# ./UnixInstallScript
      Note: The script will stop all of Check Point services ('cpstop') - read the output on the screen.
    4. Start Check Point services:
      [Expert@HostName]# cpstart

    Notes:

    • Make sure to take a snapshot of your Check Point machine before installing this hotfix.
    • In Management HA environment, this procedure must be performed on both Management Servers.


  • Hotfix package for R77.30 - IPSO OS (manual installation in Command Line)

    In order to download this package you will need to have a Software Subscription or Active Support plan.

    OS R77.30
    IPSO - CLI

    Procedure:

    1. Hotfix has to be installed on R77.30 Security Management Server running on IPSO OS.
    2. Download the relevant hotfix package from the table below, transfer the hotfix package to the machine and unpack it:
      [admin]# tar -zxvf Check_Point_Hotfix_R77.30_IPSO_sk106196.tgz
    3. Install the hotfix:
      [admin]# ./UnixInstallScript
      Note: The script will stop all of Check Point services ('cpstop') - read the output on the screen.
    4. Start Check Point services:
      [admin]# cpstart

    Notes:

    • In Management HA environment, this procedure must be performed on both Management Servers.

 

Uninstall instructions

  • On Gaia OS using CPUSE (Check Point Update Service Engine)

    1. Connect to the Gaia Portal on R77.30 Security Management Server / Multi-Domain Security Management Server and navigate to Upgrades (CPUSE) pane - click on Status and Actions.
    2. Select Installed in the menu near the Help icon.
    3. Select the hotfix package R77.30 Hotfix for sk106196 (Policy installation fails with "ERROR: stab identifier for host redefined") - click on More button on the toolbar - click on Uninstall.
      Example:
    4. When the hotfix uninstall completes, log in to Expert mode and start Check Point services with "cpstart" command.

    Notes:



  • On Gaia OS and IPSO OS (manual uninstall in Command Line)

    1. Download and unpack the hotfix package (refer to the "Installation instructions" (manual installation in Command Line) above) on R77.30 Security Management Server / Multi-Domain Security Management Server.
    2. Run the installation script with "-u" flag:
      # ./UnixInstallScript -u
    3. Start Check Point services:
      # cpstart

    Notes:
    • In Management HA environment, this procedure must be performed on both Management Servers.

 

Workaround instructions

If you do not wish to install the hotfix, then the following workaround is available:

  1. In SmartDashboard, open the object of Security Gateway "GW_2" (refer to the example in "Symptoms" section).
  2. Enable the "IPSec VPN" blade and click on OK.
  3. Install policy on "GW_2".
Applies To:
  • 01678465 , 01951764 , 01709620 , 01678185

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment