The ticket
Change window. You click Install. Error about lock / unpublished / another administrator. Night shift left SmartConsole on a jump box overnight.
R80+ uses sessions. You Publish to commit to the database, then Install Policy to push to gateways. A leftover session or lock blocks install. Discard or take over that session. This is not SIC Not Trusted.
SMS sms-lab 10.10.10.5 · cluster VIP 10.10.10.1 (cp-gw-01 10.10.10.2 / cp-gw-02 10.10.10.3) · external 203.0.113.25 · internal LAN 10.20.30.0/24 · HR PC 10.20.30.80 TECHCLICK\priya.hr · HR app 10.20.30.41 hr.techclick-lab.in. Not a live customer.
Sessions and locks
Security Management install topics: Menu → Publish session → Verify → Install Policy. Two people can edit; they must not sit on unpublished conflicting changes forever.
If SmartConsole crashed, the session can remain on the SMS. The next installer sees a lock.
Publish vs discard vs SIC
| Error flavour | Do | Do not |
|---|---|---|
| Unpublished changes / session | Publish yours or discard theirs (if allowed) | Reset SIC |
| Not Trusted / SIC | Lesson 3 | Discard random sessions |
| Verify failed (object) | Read the verify line | Force install twice |
Connected sessions
Unlock runbook
Side A — read the exact toast
Screenshot the error. SIC vs lock vs verify.
Side B — sessions
Manage & Settings → Sessions (or the session pane). Publish your work. Discard/disconnect the stale admin per your change policy.
Side C — verify + install
Verify Policy. Install Access Control (and TP if needed).
fw staton the gateway shows new timestamp.
# Prefer SmartConsole Sessions UI. # If a documented SK for your train shows a session/lock CLI, use that SK — # do not invent fwm kill commands from memory on production. cpwd_admin list | grep FWM # FWM executing is required to install at all.
Four lock failures
1 · Stale GUI
Jump box still has SmartConsole. Disconnect that session.
2 · You forgot Publish
Install pushes last published DB, not your editor buffer. Publish first.
3 · Verify object error
Empty group, missing VPN community, bad IP. Fix the object named in verify.
4 · Treated as SIC
Resetting SIC during a lock makes two problems.
How to prove it
1) Sessions list is clean. 2) Publish done. 3) Install succeeded. 4) fw stat time updated. 5) SIC still Communicating.
Traps
| Symptom | Story | Wrong fix |
|---|---|---|
| Install locked | Leftover session | SIC reset |
| Install ok, change missing | Never published | New gateway object |
| Verify fail | Bad object | Force twice |
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
Check Point class series: Architecture · Gaia first day · SIC reset · Objects + first match · Policy layers · Hide vs Static NAT · Identity Awareness · HTTPS Inspection · Threat Prevention · Find the drop · fw monitor · SecureXL · ClusterXL · VPN Community · Policy install lock · vs PA vs Forti · CCSA / CCSE interview
Sources
- R81 Security Management — Installing the Access Control Policy (Publish, Verify, Install).
- SmartConsole session management help for your train.
Related: Check Point evidence desk · session factory · next lesson in the series above.