Troubleshooting Zero Touch
Common troubleshooting issues and how to fix them:
Enabling Zero Touch through Spark Management (under the account's settings) must be configured in the account that the User Center account is linked to. Most of the time, that is the MSP / MSSP account.
-
Go to Settings > Zero Touch.
-
Enable Use Zero Touch from Spark Management.
-
If the Gateway settings are already configured, perform a factory reset / next fetch. Otherwise, wait for the next fetch.
-
Zero Touch should now successfully connect to the Gateway.
If you still experience any issues, contact Check Point Support.
Procedure:
-
In the top toolbar of the Gateways page, click More.
-
Click Manage User Center accounts.
-
Click the Sync button for each of your linked accounts.
-
Close the dialog.
-
Repeat step 1: In the top toolbar, click More.
-
Click Resync inventory from User Center.
Other options:
-
Verify in the Gateways list that the MAC address is not already deployed.
-
Move appliances between User Center accounts or ask your distributor to move the license to your account.
-
Verify that the MAC has a valid license.
-
Verify the appliance is not under Archived Gateways
-
Wait several hours for the User Center synchronization to complete.
-
Verify your linked User Center accounts (see step 2 in the procedure above).
Possible Causes:
-
No User Center accounts are connected.
-
Connected accounts contain no Spark Firewall Appliances.
-
All Gateways are already deployed (and appear in the Gateways list).
This status is informational and does not indicate an error. Resync your Gateways or follow the procedure for Gateways are not visible after a resync above.
Possible causes and resolutions:
-
Your appliance cannot be connected to the Internet due to a pre-existing condition such as your country / region is under Point-to-Point Protocol over Ethernet (PPPoE) and PPPoE is not configured.
-
In the Getting Started Guide for your appliance model, open the First Time Configuration Wizard section and follow the instructions.
-
Access the Gateway locally.
-
-
The Gateway is already deployed in another account.
-
Access the Gateway locally.
-
Perform a factory reset.
-
-
For Legacy Zero Touch users, see Situations unique to Legacy Zero Touch Users:.
Procedure:
-
Access the Gateway locally.
-
Run this command from the Gateway CLI:
test zero-touch-request -
Open a support ticket and provide this information:
-
Command output
-
Account ID (parent and customer)
-
Plan name
-
Configuration screenshots
-
CPINFO file
-
Gateway MAC address
-
Workaround:
For urgent deployments, manually activate the Gateway (see Connecting Spark Firewall Appliances to Spark Management) instead of using Zero Touch.
Situations unique to Legacy Zero Touch Users:
There are two Zero Touch modes:
-
Legacy Zero Touch mode (uses Zero Touch portal) - Default
-
The new Zero Touch mode managed through Spark Management
A User Center account's Spark Gateway inventory can only use one Zero Touch mode at a time.
To change the Zero Touch mode, use one of these options:
-
Recommended: Enable Zero Touch during the Zero Touch configuration in a Plan (see Configuring Zero Touch).
-
Alternative:
-
Go to Settings > Zero Touch.
-
Toggle the mode.
-