<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vsec controller status on standby machine (partial data) in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141935#M1091</link>
    <description>&lt;P&gt;You are right, this is a current limitation and it is on the roadmap to fix.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are planning a long downtime to the mgmt server, do a failover to the secondary mgmt and the CloudGuard Controller there will update the GWs.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Feb 2022 17:01:02 GMT</pubDate>
    <dc:creator>Gil_Sudai</dc:creator>
    <dc:date>2022-02-18T17:01:02Z</dc:date>
    <item>
      <title>vsec controller status on standby machine (partial data)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141779#M1088</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using an R80.40 Management in HA. There is a vSec Integration (for datacenter obects) implemented. This is where the management gets the objects dynamically from the vCenter and sends these data center objects to the gateways.&lt;/P&gt;&lt;P&gt;On the primary management I can se this status:&lt;/P&gt;&lt;P&gt;vSEC Controller Status: on, Number of imported Data Center Objects: 100&lt;/P&gt;&lt;P&gt;At the same time I can see on the standby management system:&lt;/P&gt;&lt;P&gt;vsec controller status on, standby machine (partial data),&amp;nbsp;Number of imported Data Center Objects: 85&lt;/P&gt;&lt;P&gt;This does not change over time. On both machines I can see the vCenter status "connected".&lt;/P&gt;&lt;P&gt;Is this normal? What will happen if primary management fails? Will we only have 85 DC objects?&lt;/P&gt;&lt;P&gt;Unfortunately I was not able to find any sk or documentation for vSEC controller redundancy. Any hints?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 13:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141779#M1088</guid>
      <dc:creator>Daniel_Fischler</dc:creator>
      <dc:date>2022-02-17T13:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: vsec controller status on standby machine (partial data)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141793#M1089</link>
      <description>&lt;P&gt;Hi Daniel, not sure why the on the Standby it show 85.&lt;/P&gt;
&lt;P&gt;On Standby, the CloudGuard Controller (old name vsec) is not doing much. Only the instance on the Active mgmt is really doing the work.&lt;/P&gt;
&lt;P&gt;After the Standby will be set to Active (this is done from SmartConsole) the CloudGuard Controller (old name is vsec) will re-start and will handle all the tasks.&lt;/P&gt;
&lt;P&gt;HTH,&lt;/P&gt;
&lt;P&gt;Gil&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 14:20:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141793#M1089</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2022-02-17T14:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: vsec controller status on standby machine (partial data)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141844#M1090</link>
      <description>&lt;P&gt;Hi Gil&lt;/P&gt;&lt;P&gt;Thanks for the reply. That means if the active mgmt goes down there are no more updates for the gateways. There is no automatic failover for the CloudGard Controller itself? I know that the mgmt failover is a manual task (the mgmt itself is not relevant for a working firewall, so this is ok and most people do not panic if the mgmt goes down or is out of order during an upgrade &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ).&lt;/P&gt;&lt;P&gt;But a not working CloudGard Controller will interrupt traffic at least after some time when the object changes! Is there any way to make the CloudGard Controller redundant / high available? Or do you have any suggestions what to do during an upgrade of the active mgmt (that could go some hours)?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 07:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141844#M1090</guid>
      <dc:creator>Daniel_Fischler</dc:creator>
      <dc:date>2022-02-18T07:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: vsec controller status on standby machine (partial data)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141935#M1091</link>
      <description>&lt;P&gt;You are right, this is a current limitation and it is on the roadmap to fix.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are planning a long downtime to the mgmt server, do a failover to the secondary mgmt and the CloudGuard Controller there will update the GWs.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 17:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/vsec-controller-status-on-standby-machine-partial-data/m-p/141935#M1091</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2022-02-18T17:01:02Z</dc:date>
    </item>
  </channel>
</rss>

