Checking client/server synchronisation
From Tech-Wiki
More actions
Compare the Endpoint Management Policy Assignment Table (PAT) version on the management server and endpoint client when troubleshooting policy synchronisation.
Expected relationship
The original procedure expects the PAT version on the management server to be higher than the version reported by clients.
Check the management-server PAT version
Management server
uepm patver get
Check the endpoint PAT version
32-bit Windows
HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\Endpoint Security\Device Agent\PATVersion
Query the 32-bit registry value
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\Endpoint Security\Device Agent" /v PATVersion
64-bit Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\Endpoint Security\Device Agent\PATVersion
Query the 64-bit registry value
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\Endpoint Security\Device Agent" /v PATVersion
If the management PAT version is too low
The original procedure calculates a new value as:
new_PAT_version = client_PAT_version + 100
Set the new PAT version:
Set a new PAT version
uepm patver set <Value_of_new_PAT_version>
Example:
Example PAT value
uepm patver set 150000
Verify it:
Confirm the configured PAT version
uepm patver get
Restart Check Point services
Service restart is disruptive
The final step in the original procedure restarts Check Point services. Confirm the impact and use an approved maintenance/change window before running it.
Restart Check Point services
cpstop;cpstart