Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Checking client/server synchronisation

From Tech-Wiki


Compare the Endpoint Management Policy Assignment Table (PAT) version on the management server and endpoint client when troubleshooting policy synchronisation.

ⓘ
Expected relationship
The original procedure expects the PAT version on the management server to be higher than the version reported by clients.

Check the management-server PAT version

>_Management server
uepm patver get

Check the endpoint PAT version

32-bit Windows

HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\Endpoint Security\Device Agent\PATVersion
>_Query the 32-bit registry value
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\Endpoint Security\Device Agent" /v PATVersion

64-bit Windows

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\Endpoint Security\Device Agent\PATVersion
>_Query the 64-bit registry value
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\Endpoint Security\Device Agent" /v PATVersion

If the management PAT version is too low

The original procedure calculates a new value as:

new_PAT_version = client_PAT_version + 100

Set the new PAT version:

>_Set a new PAT version
uepm patver set <Value_of_new_PAT_version>

Example:

>_Example PAT value
uepm patver set 150000

Verify it:

>_Confirm the configured PAT version
uepm patver get

Restart Check Point services

!
Service restart is disruptive
The final step in the original procedure restarts Check Point services. Confirm the impact and use an approved maintenance/change window before running it.
>_Restart Check Point services
cpstop;cpstart

See also