CHKP004 - Check Point Source IP Not Authorised
Uploading..Agent error code #CHKP004 indicates that the Check Point gateway recognised the shared secret but refused the request because the agent connected from an IP address the Identity Web API client does not accept.
The Identity Web API enforces a source-IP allow-list in addition to the shared secret. That allow-list comes from the host object bound to the Authorized Client, not from a field on the client itself. This error means the agent's actual source address is not that host object's IP.
This is distinct from #CHKP003, where the shared secret itself was rejected, and from #CHKP005, where the gateway would not say whether the secret or the source IP was the problem.
Common causes include:
Steps to Resolve
Confirm the Agent's Real Source IP
Update the Host Object in SmartConsole
knocknoc-agent)
Set its IPv4 Address to the agent's real source IP
Install Policy
For the full setup, see the Check Point setup guide.