<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.20.M1 and Cloudguard NSX in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26652#M3417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wanted to try R80.20 and vSec for NSX in my lab (trying to figure out if we should start with R80.20M1 or stick with R80.10 for management). The R80.20 documentation covers the management part only, nothing about deployment/registering of OVFs for NSX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the sk114518, the R80.20 is not even mentioned and I am unable to find any other SK relevant to R80.20 managing R80.10 Cloudguard for NSX gateway.&amp;nbsp;&lt;EM&gt;vSEC Gateway for NSX Managed by R80.10 Platforms Administration Guide&lt;/EM&gt; has info how to deploy gateways managed by R80.10 but these commands are not working. On R80.20.M1, there is &lt;STRONG&gt;cloudguard on&lt;/STRONG&gt; command (instead of &lt;STRONG&gt;vsec on&lt;/STRONG&gt;) but there is no &lt;STRONG&gt;vsec_config&lt;/STRONG&gt; or &lt;STRONG&gt;cloudguard_config&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Should I just stick with R80.10 for managing Cloudguard for NSX or there is some SK which I missed? Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2018 15:13:11 GMT</pubDate>
    <dc:creator>Srdjan_B</dc:creator>
    <dc:date>2018-09-12T15:13:11Z</dc:date>
    <item>
      <title>R80.20.M1 and Cloudguard NSX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26652#M3417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wanted to try R80.20 and vSec for NSX in my lab (trying to figure out if we should start with R80.20M1 or stick with R80.10 for management). The R80.20 documentation covers the management part only, nothing about deployment/registering of OVFs for NSX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the sk114518, the R80.20 is not even mentioned and I am unable to find any other SK relevant to R80.20 managing R80.10 Cloudguard for NSX gateway.&amp;nbsp;&lt;EM&gt;vSEC Gateway for NSX Managed by R80.10 Platforms Administration Guide&lt;/EM&gt; has info how to deploy gateways managed by R80.10 but these commands are not working. On R80.20.M1, there is &lt;STRONG&gt;cloudguard on&lt;/STRONG&gt; command (instead of &lt;STRONG&gt;vsec on&lt;/STRONG&gt;) but there is no &lt;STRONG&gt;vsec_config&lt;/STRONG&gt; or &lt;STRONG&gt;cloudguard_config&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Should I just stick with R80.10 for managing Cloudguard for NSX or there is some SK which I missed? Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 15:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26652#M3417</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2018-09-12T15:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20.M1 and Cloudguard NSX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26653#M3418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt;‌, can you help here or redirect to a relevant team/person?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 15:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26653#M3418</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-12T15:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20.M1 and Cloudguard NSX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26654#M3419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/53992"&gt;Srdjan Bosnjak&lt;/A&gt;‌, SecureKnowledge does not mentioned versions that are not GA. R80.20 is on public EA now, and the focus of that cycle is GW part.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For all production purposes, including pre-production tests in your lab, I would recommend sticking to GA releases. R80.20.M1 is GA, and I am quite sure all management command working there will be availabe with R80.20 GA as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing and making your mind based on EA version is tricky, as there is no guarantie EA version will be consistent with GA one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, I hope Tomer will be able to give you some guidance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 15:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26654#M3419</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-12T15:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20.M1 and Cloudguard NSX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26655#M3420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was not clear, sorry for confusion. The idea was to use R80.20.M1 management and R80.10 Cloudguard gateway (both are GA). This combo (or anything with R80.20.M1) is not covered in&amp;nbsp;sk114518.&lt;/P&gt;&lt;P&gt;The issue I am facing is this: Cloudguard controller is integrated in R80.20.M1, but there is no equivalent of &lt;EM&gt;vSEC Service Registration v5 Hotfix for R80.10 Management Server&lt;/EM&gt;. On R80.10 management, this hotfix brings &lt;STRONG&gt;cloudguard_config&lt;/STRONG&gt; command. In the sk128612 it is written that during the upgrade from R80.10 to R80.20.M1 the hotfix needs to be uninstalled but it does not say anything about installing a new one for R80.20.M1. I expected that functionality of the hotfix was integrated in R80.20.M1, but I was probably wrong. So, I will change my question and ask if service registration is supported in R80.20.M1 with R80.10 Cloudguard gateway for NSX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried to start with R80.10 management with the idea to use R80.10 management to deploy R80.10 gateways and immediately upgrade management to R80.20.M1 (keeping GWs at R80.10). However, it seems that even my NSX version is too recent. Basically, it looks that VMware made a change which throws Cloudguard off. When registering service, Cloudguard is checking &lt;A class="link-titled" href="https://nsx-manager.your.domain//api/2.0/global/heartbeat" title="https://nsx-manager.your.domain//api/2.0/global/heartbeat"&gt;https://nsx-manager.your.domain//api/2.0/global/heartbeat&lt;/A&gt;. With that call, NSX 6.3 returns:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;vsmGlobalConfig &lt;SPAN style="color: #ff0000;"&gt;xmlns="vmware.vshield.edge.2.0"&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;nbsp; &amp;lt;versionInfo&amp;gt;6.4&amp;lt;/versionInfo&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;/vsmGlobalConfig&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while NSX 6.4.2 returns (please note there is no red text from above):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;vsmGlobalConfig&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;nbsp; &amp;lt;versionInfo&amp;gt;6.4&amp;lt;/versionInfo&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;&amp;lt;/vsmGlobalConfig&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bottom line is that with 6.4.2 the registration fails and $FWDIR/log/vsec_config.elg records this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;ERROR [main] (RestRequest.java:113) - Parsing the XML failed..&lt;BR /&gt;DEBUG [main] (RestRequest.java:70) - Stack trace: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier, monospace;"&gt;javax.xml.bind.UnmarshalException: unexpected element (uri:"", local:"vsmGlobalConfig"). Expected elements are &amp;lt;{vmware.vshield.edge.2.0}vsmGlobalConfig&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As this is lab environment, I cannot open service request for this but I guess it will need to be fixed anyway.&lt;/P&gt;&lt;P&gt;I will downgrade my NSX but since I spent some time on this, I wanted to report it as it would be wasted time otherwise.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26655#M3420</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2018-09-14T14:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20.M1 and Cloudguard NSX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26656#M3421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an update: with R80.10 management, VSR5 hotfix and NSX 6.4.1 everything went well, service can be registered without issues. It seems that only NSX 6.4.2 returns version info without &lt;SPAN style="color: #ff0000; font-family: courier new, courier, monospace;"&gt;xmlns="vmware.vshield.edge.2.0"&lt;/SPAN&gt; part as show in previous post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2018 06:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-20-M1-and-Cloudguard-NSX/m-p/26656#M3421</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2018-09-18T06:16:42Z</dc:date>
    </item>
  </channel>
</rss>

