<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding more gateways to &amp;amp;quot;Gateways Enforcing Data Center Objects&amp;amp;quot; List in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205626#M4595</link>
    <description>&lt;P&gt;Are you using the datacenter object in a rule on the relevant gateway/VS?&lt;BR /&gt;What version/JHF is the management and gateways?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 21:34:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-02-09T21:34:31Z</dc:date>
    <item>
      <title>Adding more gateways to Gateways Enforcing Data Center Objects List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205071#M4577</link>
      <description>&lt;P&gt;Hello Checkmates,&lt;BR /&gt;In our DC we have a VSX cluster with 95 VS running on it, we also deployed an on-prem Cloudguard that should filter the ACI traffic&lt;/P&gt;&lt;P&gt;At the moment 19 gateways enforce the Datacenter Objects when running the command "cpstat vsec"&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;vSEC Controller Status: on&lt;BR /&gt;Number of disconnected Data Centers: 0&lt;BR /&gt;Number of Data Centers: 2&lt;BR /&gt;Number of imported Data Center objects: 461&lt;BR /&gt;Number of gateways enforcing Data Center objects: 19&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;Also, in the " CloudGuard Controller Service Manager Menu" (vsec_controller_cli) there are only 85 VS gateways out of 95 listed&lt;/P&gt;&lt;P&gt;We are using Datacenter Object for all the tenants and i don't know how i can enforce the datacenter objects on more VS or what is the issue that the Datacenter Objects are enforced on only 19 GW.&lt;/P&gt;&lt;P&gt;The 2nd topic would be, how can I add all 95 or more gateways to the " CloudGuard Controller Service Manager Menu" list&lt;/P&gt;&lt;P&gt;I have opened a TAC case for this issue but there is no real progress with it, only trial-and-error solutions.&lt;/P&gt;&lt;P&gt;Thank you for your support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205071#M4577</guid>
      <dc:creator>Daniel_Ionut_Ba</dc:creator>
      <dc:date>2024-02-13T15:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205626#M4595</link>
      <description>&lt;P&gt;Are you using the datacenter object in a rule on the relevant gateway/VS?&lt;BR /&gt;What version/JHF is the management and gateways?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 21:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205626#M4595</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-09T21:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205676#M4596</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned, CloudGuard Controller only propagates identities/data center object to gateways which enforce security policy rules that contains data center objects.&lt;/P&gt;
&lt;P&gt;So the most obvious reason for the behavior you are describing is that the security policy rules that contain data center objects are not related to those gateways.&lt;/P&gt;
&lt;P&gt;If you can share the SR number, we might be able to provide more specific answers.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2024 07:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205676#M4596</guid>
      <dc:creator>avivs</dc:creator>
      <dc:date>2024-02-11T07:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205960#M4600</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using the datacenter object in all the policies for all the VSX VS (for all our clients)&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output of the command vsec_controler_cli&amp;nbsp; shows 87 objects but the output of&amp;nbsp;cpstat vsec shows that only 19 GW enforcing Data Center objects.&lt;/P&gt;&lt;P&gt;vSEC Controller Status: on&lt;BR /&gt;Number of disconnected Data Centers: 0&lt;BR /&gt;Number of Data Centers: 2&lt;BR /&gt;Number of imported Data Center objects: 462&lt;BR /&gt;Number of gateways enforcing Data Center objects: 19&lt;/P&gt;&lt;P&gt;on the SMS we are running R81.10 Take110&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the VSX GW R80.30 Take236&lt;/P&gt;&lt;P&gt;Thank you for your support&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205960#M4600</guid>
      <dc:creator>Daniel_Ionut_Ba</dc:creator>
      <dc:date>2024-02-13T15:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205963#M4601</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37680"&gt;@avivs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I agree with you, but in this case what you describe does not apply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have as an usecase a VS, we are using the datacenter object in the policy, in&amp;nbsp; the datcenert object some EPGs are imported but still this VS is not listed in the&amp;nbsp;gateways enforcing Data Center objects list (cpsta vsec) neither in&amp;nbsp;CloudGuard Controller Service Manager Menu (vsec_controller_cli)&lt;/P&gt;&lt;P&gt;the SR is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SR#6-0003792393&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for your support&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:39:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/205963#M4601</guid>
      <dc:creator>Daniel_Ionut_Ba</dc:creator>
      <dc:date>2024-02-13T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206018#M4602</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11200"&gt;@Daniel_Ionut_Ba&lt;/a&gt;&amp;nbsp; please share with me the file $FWDIR/conf/vsec_controller_targets_data.set from your mgmt server.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 07:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206018#M4602</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2024-02-14T07:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206019#M4603</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7211"&gt;@Gil_Sudai&lt;/a&gt;, Could you please send me a private message where I can replay and send the file?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Daniel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 08:24:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206019#M4603</guid>
      <dc:creator>Daniel_Ionut_Ba</dc:creator>
      <dc:date>2024-02-14T08:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206165#M4606</link>
      <description>&lt;P&gt;Updating the thread that we did remote session, found the root cause to be wrong configuration of the mgmt interface on the VSX, fixed it and now the issue is solved.&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11200"&gt;@Daniel_Ionut_Ba&lt;/a&gt;&amp;nbsp; for the remote session.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 11:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206165#M4606</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2024-02-15T11:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206172#M4607</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7211"&gt;@Gil_Sudai&lt;/a&gt;&amp;nbsp;thank you for your fast response and support, you guys are the best!&amp;nbsp;&lt;/P&gt;&lt;P&gt;One small request, could you please add to this post the script for verifying the management interface and a small description, unfortunately, i have closed the ssh connection and forgot to save it? Maybe someone else might&amp;nbsp; have the same issue and this can save a lot of time&lt;/P&gt;&lt;P&gt;Again, many tanks for your help!&lt;BR /&gt;Cheers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 12:50:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206172#M4607</guid>
      <dc:creator>Daniel_Ionut_Ba</dc:creator>
      <dc:date>2024-02-15T12:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more gateways to &amp;quot;Gateways Enforcing Data Center Objects&amp;quot; List</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206176#M4608</link>
      <description>&lt;P&gt;What we did:&lt;/P&gt;
&lt;P&gt;Followup on cpm.elg during policy installation and understand that /etc/fw/tmp/getVsData.sh script invocation on the vsx failed.&lt;/P&gt;
&lt;P&gt;So we ssh the vsx gw and run it manually with bash debug:&lt;/P&gt;
&lt;P&gt;bash -x /etc/fw/tmp/getVsData.sh&lt;/P&gt;
&lt;P&gt;and saw that the script fails to get the mgmt interface.&lt;/P&gt;
&lt;P&gt;That made us realize that the mgmt interface was incorrect.&lt;/P&gt;
&lt;P&gt;Customer fixed it using clish APIs.&lt;/P&gt;
&lt;P&gt;Once the mgmt interface on the vsx was correct, an install-policy fixed the CloudGuard Controller side.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 13:16:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Adding-more-gateways-to-Gateways-Enforcing-Data-Center-Objects/m-p/206176#M4608</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2024-02-15T13:16:34Z</dc:date>
    </item>
  </channel>
</rss>

