<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sk183754 MANA in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277582#M6237</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Simple query - if you manually edit the VM overview page and add the&amp;nbsp;&lt;SPAN&gt;LegacyVMNVA tag and then stop/start - is that sufficient to scope the opt-out to that vm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2026 15:01:47 GMT</pubDate>
    <dc:creator>LazarusG</dc:creator>
    <dc:date>2026-05-28T15:01:47Z</dc:date>
    <item>
      <title>sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277582#M6237</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Simple query - if you manually edit the VM overview page and add the&amp;nbsp;&lt;SPAN&gt;LegacyVMNVA tag and then stop/start - is that sufficient to scope the opt-out to that vm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 15:01:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277582#M6237</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2026-05-28T15:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277609#M6238</link>
      <description>&lt;P&gt;That's what the compliance/remediation policy is doing, except the policy is filtered for a select list of marketplace publishers. &amp;nbsp;The resulting tag has no value on it, either. &amp;nbsp;Here's what it looks like on a VM after the policy remediation ran.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you deploy it as a compliance policy, it can automate the remediation as well. &amp;nbsp;This is the result.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 00:12:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277609#M6238</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-05-29T00:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277618#M6240</link>
      <description>&lt;P&gt;cool yeh - so in a really simple environment - where someone might not have permissions to run the policy in their org - you could just manually poke it in there and restart the vm right?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 08:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277618#M6240</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2026-05-29T08:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277619#M6241</link>
      <description>&lt;P&gt;also we have customers having errors trying to apply the label - and also customers asking how to remove the label.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 08:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277619#M6241</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2026-05-29T08:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277623#M6242</link>
      <description>&lt;P&gt;thanks for the screnshot though - most helpful&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 11:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277623#M6242</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2026-05-29T11:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277632#M6243</link>
      <description>&lt;DIV&gt;
&lt;P&gt;We should look at this in two scenarios:&lt;/P&gt;
&lt;H3&gt;1. VM currently on Mellanox&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Applying the &lt;CODE&gt;LegacyVMNVA&lt;/CODE&gt; tag is sufficient to &lt;STRONG&gt;protect future allocations&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;No immediate action is required&lt;/LI&gt;
&lt;LI&gt;The tag is evaluated only during lifecycle events (stop/start, redeploy, scale-out), so it mainly matters for future changes&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. VM currently on MANA&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;The tag alone is &lt;STRONG&gt;not enough to move the VM off MANA&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;A lifecycle event is required (stop/start, redeploy, or VMSS instance replacement) to trigger reallocation and enforce the tag&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As these mechanisms are all Microsoft owned, operated and documented, In any case of errors applying the azure policy or opt-out tag, kindly contact Microsoft Azure support.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 29 May 2026 15:47:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277632#M6243</guid>
      <dc:creator>avivs</dc:creator>
      <dc:date>2026-05-29T15:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277635#M6244</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;About VMSS,&amp;nbsp; &amp;nbsp;Must we Stop/Start the VMSS group or it is enough apply this by each vm in the scale-set group?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 17:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277635#M6244</guid>
      <dc:creator>Cristobal_Valle</dc:creator>
      <dc:date>2026-05-29T17:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277931#M6247</link>
      <description>&lt;P&gt;Applying the compliance and auto-remediation policy to the resource group will ensure the VMs get the tag. &amp;nbsp;You can do a scale out event to test the results and verify, however.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2026 20:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277931#M6247</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-06-06T20:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: sk183754 MANA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277932#M6248</link>
      <description>&lt;P&gt;For those interested, here's an Ansible playbook to add the MANA driver to the modprobe deny-list. &amp;nbsp;This assumes you have an Ansible inventory group for your CloudGuard management and CloudGuard gateway hosts. &amp;nbsp;You also need a user that can login via SSH directly into Expert mode. &amp;nbsp;This playbook does not use Gaia API.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;---
# disable_mana.yml
# Add the Microsoft MANA driver to modprobe deny-list
# sk183754
#
- name: Disable Microsoft MANA driver
  hosts: ckp_mgmt_azure,ckp_gw_azure  # Inventory group of Azure hosts
  gather_facts: false
  become: false
  remote_user: YOUR_EXPERT_MODE_USER

  vars:
    output_dir: /tmp/disable_microsoft_mana # Change to your own output path

  tasks:
    - name: Create output directories
      ansible.builtin.file:
        path: "{{ item }}"
        state: directory
        recurse: true
      loop:
        - "{{ output_dir }}/{{ inventory_hostname }}/BEFORE"
        - "{{ output_dir }}/{{ inventory_hostname }}/AFTER"
      delegate_to: localhost

    # ITSM Change Control BEFORE state
    - block:
        - name: Get current modprobe config
          ansible.builtin.fetch:
            src: /etc/modprobe.d/disable_mana.conf
            dest: "{{ output_dir }}/{{ inventory_hostname }}/BEFORE/disable_mana.conf"
            flat: true
          register: fetch_result
      rescue:
        - name: modprobe config absent
          ansible.builtin.copy:
            content: "disable_mana.conf does not exist"
            dest: "{{ output_dir }}/{{ inventory_hostname }}/BEFORE/disable_mana.conf.txt"
          delegate_to: localhost

    - name: Add MANA to modprobe config
      ansible.builtin.copy:
        content: "blacklist mana\n"
        dest: /etc/modprobe.d/disable_mana.conf
        owner: root
        group: root
        mode: '0644'

    # ITSM Change Control AFTER state
    - block:
        - name: Get current modprobe config
          ansible.builtin.fetch:
            src: /etc/modprobe.d/disable_mana.conf
            dest: "{{ output_dir }}/{{ inventory_hostname }}/AFTER/disable_mana.conf"
            flat: true
      rescue:
        - name: modprobe config absent
          ansible.builtin.copy:
            content: "disable_mana.conf does not exist"
            dest: "{{ output_dir }}/{{ inventory_hostname }}/AFTER/disable_mana.conf.txt"
          delegate_to: localhost

...
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your inventory would look like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;---
# inventory.yml
all:
  children:
    ckp_mgmt_azure:
      hosts:
        mgmt01:
          ansible_host: 192.0.2.1
    ckp_gw_azure:
      hosts:
        gw01:
          ansible_host: 192.0.2.2
        gw02:
          ansible_host: 192.0.2.3
...
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run the playbook:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ansible-playbook -i inventory.yml disable_mana.yml -k  # "-k" asks for the expert-level user password&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The playbook will capture the BEFORE/AFTER state of the configuration for your ITSM/Change Control management. &amp;nbsp;There is no TEST plan, however, since this is just modifying the file. &amp;nbsp;This doesn't automatically reboot the host. &amp;nbsp;If you want to do that, you can add a &lt;FONT face="andale mono,times"&gt;ansible.builtin.reboot&lt;/FONT&gt; module task at the end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2026 20:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/sk183754-MANA/m-p/277932#M6248</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-06-06T20:56:07Z</dc:date>
    </item>
  </channel>
</rss>

