<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard On Azure management Server High Availability failing in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163477#M731</link>
    <description>&lt;P&gt;Okay, thanks for your patience. The suggested SK is for MDS environment only, and your installation is clearly SMS, not MDS pair.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Your secondary MGMT, is it set as secondary? It might be you deployed two primary ones...&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 09:21:42 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-11-29T09:21:42Z</dc:date>
    <item>
      <title>Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163360#M724</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Hi,&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I will appreciate any ideas regarding Management HA in Azure or Cloudguard in cloud environment. Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two management servers both on Azure, R81.10. Deployed straight from the marketplace and for the sake of the tests in the very same Vnet and Subnet to avoid routing and firewall issues. Connected to the Primary and following&amp;nbsp;&lt;SPAN&gt;sk54160 I am getting:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;SIC Status for azurecpmngmhubneu: Not Communicating&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;Peer sent wrong DN: cn=cp_mgmt,o=azurecpmngmhubneu..krdwxk** Reset SIC from peer, and establish trust again. **&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Opened TAC service request "6-0003465014" ten days ago and they suggested&amp;nbsp;&lt;SPAN&gt;sk110514. This article however is pointing to mdsenv command which is not available:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;Primary Management Server:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;[Expert@azurecpmngmhubweu:0]# mdsenv azurecpmngmhubweu&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;-bash: mdsenv: command not found&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;Secondary Management Server:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;[Expert@azurecpmngmhubneu:0]# mdsenv&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;-bash: mdsenv: command not found&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The second suggestion was to check the MTU, but the MTU is the default one and changes according to Microsoft can cause even more issues, so I am not being willing to play with that on VM level.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Deployment of security gateway from the marketplace and trying to activate it as a secondary management however is failing with another error which is kind of expected (Did it just for the sake of the initial SIC Trust Establishment and seems to work just fine):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT color="#3366FF"&gt;&lt;STRONG&gt;Error: 'Security Management Server' is not responding. Verify that 'Security Management Server' is installed on the gateway. If 'Security Management Server' should not be installed verify that it is not selected in the Products List of the gateway (SmartDashboard &amp;gt; Security Gateway &amp;gt; General Properties &amp;gt; Software Blades List).&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 28 Nov 2022 13:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163360#M724</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-28T13:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163369#M725</link>
      <description>&lt;P&gt;Could you please share the content of your&amp;nbsp;/etc/profile.d/CP.sh file?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 13:53:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163369#M725</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-28T13:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163375#M726</link>
      <description>&lt;P&gt;Sure Val, thanks for the reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if [ -r /opt/CPshrd-R81.10/tmp/.CPprofile.sh ]; then&lt;BR /&gt;. /opt/CPshrd-R81.10/tmp/.CPprofile.sh&lt;BR /&gt;fi&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 14:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163375#M726</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-28T14:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163392#M727</link>
      <description>&lt;P&gt;Ooookay, then&amp;nbsp;&lt;SPAN&gt;/opt/CPshrd-R81.10/tmp/.CPprofile.sh, please &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 14:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163392#M727</guid>
      <dc:creator>test</dc:creator>
      <dc:date>2022-11-28T14:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163396#M728</link>
      <description>&lt;P&gt;Yep, this one is holding a bit more&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;====================================================================&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;# vi /opt/CPshrd-R81.10/tmp/.CPprofile.sh&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;. /opt/CPshrd-R81.10/scripts/cpprofile_functions.sh&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPDIR /opt/CPshrd-R81.10 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir PATH $CPDIR/util 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPAPACHEDIR "/opt/CPshrd-R81.10/web/Apache" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;SAMLPORTAL_HOME=/opt/CPSamlPortal ; export SAMLPORTAL_HOME ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;#CPPostgreSQL Start DON'T REMOVE MANUALLY&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;PG_LIB_PATH=$CPDIR/database/postgresql/lib&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=$LD_LIBRARY_PATH:$PG_LIB_PATH ; export LD_LIBRARY_PATH&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;#CPPostgreSQL End DON'T REMOVE MANUALLY&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=${LD_LIBRARY_PATH}:${CPDIR}/lib64 ; export LD_LIBRARY_PATH&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add FWDIR "/opt/CPsuite-R81.10/fw1" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=${LD_LIBRARY_PATH}:${FWDIR}/lib64 ; export LD_LIBRARY_PATH&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add MDS_FWDIR "/opt/CPsuite-R81.10/fw1" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPMDIR "/opt/CPsuite-R81.10/fw1" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add SUDIR "/opt/CPsuite-R81.10/fw1/sup" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add SUROOT "/var/log/cpupgrade/suroot" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add FW_BOOT_DIR "/etc/fw.boot" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add NGM_SOLR_LOCAL_PATH "/opt/CPsuite-R81.10/fw1/Solr" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add JAVA_HOME "/opt/CPsuite-R81.10/fw1/jre" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add NGM_MEM "2048" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add PGDIR "/opt/CPshrd-R81.10/database/postgresql" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add PGDATA "/opt/CPshrd-R81.10/database/postgresql/data" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DONT_LOAD_FWM_OBJECTS "1" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DC_DIR "/opt/CPDynamicContent" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add ITP_DIR "/opt/CPInfinityTp" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CLASSPATH "/opt/CPsuite-R81.10/fw1/ngm" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=/opt/uf/SecureComputing/lib:${LD_LIBRARY_PATH} ; export LD_LIBRARY_PATH ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;UCPORTALDIR_HOME=/opt/CPUserCheckPortal ; export UCPORTALDIR_HOME ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;DLPDIR=/opt/CPsuite-R81.10/fw1/dlp ; export DLPDIR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;PATH=${PATH}:${FWDIR}/oracle_oi/sdk ; export PATH ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=${FWDIR}/oracle_oi/sdk:${LD_LIBRARY_PATH} ; export LD_LIBRARY_PATH ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;POSTFIX_DIR=/opt/postfix ; export POSTFIX_DIR ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;MAIL_CONFIG=/opt/postfix/etc/postfix ; export MAIL_CONFIG ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add JAVA_HOME "/opt/CPshrd-R81.10/jre_32" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add JAVA_HOME_32 "/opt/CPshrd-R81.10/jre_32" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add JAVA_HOME_64 "/opt/CPshrd-R81.10/jre_64" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add JETTY_HOME "/opt/CPshrd-R81.10/jetty" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add FGDIR "/opt/CPsuite-R81.10/fg1" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add ZETCDIR "/opt/CPzetc" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DADIR "/opt/CPda" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;START_AUTO_UPDATER=1 ; export START_AUTO_UPDATER&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;AUTOUPDATERDIR=/opt/AutoUpdater ; export AUTOUPDATERDIR&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;PATH=${PATH}:${AUTOUPDATERDIR}/latest/bin ; export PATH ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add INFODIR "/opt/CPinfo-10" -1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add PATH_DIR "/opt/CPDepInst/latest" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DDRDIR "/opt/DDR" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;NACPORTAL_HOME=/opt/CPNacPortal ; export NACPORTAL_HOME ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DIAGDIR "/opt/CPdiag" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add RTDIR "/opt/CPrt-R81.10" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir PATH "/opt/CPrt-R81.10/log_indexer" 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir PATH "/opt/CPrt-R81.10/log_exporter" 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add INDEXERDIR "/opt/CPrt-R81.10/log_indexer" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add EXPORTERDIR "/opt/CPrt-R81.10/log_exporter" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add UEPMDIR "/opt/CPuepm-R81.10" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir PATH "${CPDIR}/database/postgresql/bin" 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir PATH "${UEPMDIR}/engine/scripts" 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_dir LD_LIBRARY_PATH "${CPDIR}/database/postgresql/lib" 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add VSECDIR "/opt/CPvsec-R81.10" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CDTDIR "/opt/CPcdt" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;LD_LIBRARY_PATH=/opt/CPcdt/lib:${LD_LIBRARY_PATH} ; export LD_LIBRARY_PATH ; hash 1&amp;gt;/dev/null 2&amp;gt;&amp;amp;1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DEPCONDIR "/opt/CPDepCon-R81.10" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add REPMANDIR "/opt/CPRepMan-R81.10" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add SMARTLOGDIR "/opt/CPSmartLog-R81.10" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPM_DOCTOR "ON" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add DYNAMICCONTENTDIR "/opt/CPDynamicContent" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CMEDIR "/opt/CPcme" 1 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add OPENSSL_CONF "/opt/CPshrd-R81.10/conf/openssl.cnf" 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPOTELCOL_DIR "/opt/CPotelcol" 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;_cpprof_add CPVIEWEXPORTER_DIR "/opt/CPviewExporter" 1 1&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 15:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163396#M728</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-28T15:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163403#M729</link>
      <description>&lt;P&gt;Ok, this one looks okay. Try checking if $MDSDIR is resolved for you. If it is, run mdsenv as $MDSDIR/bin/mdsenv. If it is not, this is something for TAC to look into.&lt;BR /&gt;&lt;BR /&gt;Your bash shell, did you set up bash for a user manually, or are you accessing it with expert command, while first logging to cpshell?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 15:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163403#M729</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-28T15:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163457#M730</link>
      <description>&lt;P&gt;During the arm template deployment from the marketplace it is providing few options for "Default shell for admin user"&lt;/P&gt;&lt;P&gt;The options are: (I am choosing /bin/bash)&lt;/P&gt;&lt;P&gt;/etc/cli.sh&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/bin/bash&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;/bin/csh&lt;/P&gt;&lt;P&gt;/bin/tcsh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's all I got:&lt;/P&gt;&lt;P&gt;# echo $MDSDIR&lt;/P&gt;&lt;P&gt;# $MDSDIR/bin/mdsenv&lt;BR /&gt;-bash: /bin/mdsenv: No such file or directory&lt;BR /&gt;# echo $MDS_FWDIR&lt;BR /&gt;/opt/CPsuite-R81.10/fw1&lt;BR /&gt;# $MDS_FWDIR/bin/mdsenv&lt;BR /&gt;-bash: /opt/CPsuite-R81.10/fw1/bin/mdsenv: No such file or directory&lt;BR /&gt;# cd $MDS_FWDIR/bin/&lt;BR /&gt;# mds&lt;BR /&gt;mds_backup_start mds_uncheck_IPSEventManager mdsstart_eventia mdsstop_eventia&lt;BR /&gt;mds_check_IPSEventManager mdscmd_start mdsstart_start mdsstop_start&lt;BR /&gt;mds_restore_start mdsconfig_start mdsstat_start&lt;BR /&gt;mds_restored.sh mdsstart_customer_start mdsstop_customer_start&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 08:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163457#M730</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-29T08:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163477#M731</link>
      <description>&lt;P&gt;Okay, thanks for your patience. The suggested SK is for MDS environment only, and your installation is clearly SMS, not MDS pair.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Your secondary MGMT, is it set as secondary? It might be you deployed two primary ones...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163477#M731</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-29T09:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163484#M732</link>
      <description>&lt;P&gt;Yes, seems like two primary managements, but during the deployment from aARM it is not providing the same options like before to choose primary or secondary.&lt;/P&gt;&lt;P&gt;I was wondering if the marketplace image is somehow different, but doesn't make much sense. Should be pretty much the standard, just the initial setup is not in checkpoint, but instead in the ARM providing variables.&lt;/P&gt;&lt;P&gt;Single domain is enough for us at this point. Just want the autosync to another management is second region for disaster recovery. I can use Azure DR options, but there is a downtime and that's why I prefer the checkpoint native approach.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:32:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163484#M732</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-29T09:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163704#M733</link>
      <description>&lt;P&gt;Quick Update:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. After manual initial configuration (Skipping the ARM template variables) and specifying in GAIA as a Secondary management the Trust was established.&amp;nbsp;SIC Status for Secondary: Communicating&lt;/P&gt;&lt;P&gt;2. Ping from 1&amp;gt;&amp;gt;&amp;gt;2 works, ping from 2&amp;gt;&amp;gt;&amp;gt;1 works. They are in the same subnet so no chance for routing or other blockers. Direct access to one another.&lt;/P&gt;&lt;P&gt;3. Following&amp;nbsp;&lt;SPAN&gt;sk54160 I am fine until the very moment&amp;nbsp;when host is added, but the status is "Machine Status is not available"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4. Publish or Install Database fails with "Publish Failed - Action Failed due to an Internal Error"&lt;/P&gt;&lt;P&gt;5. The only choice to continue is to Discard the changes.&lt;/P&gt;&lt;P&gt;6. Installed the latest Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T79_FULL.tgz successfully. No change, same error!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are welcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 12:02:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163704#M733</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-30T12:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163705#M734</link>
      <description>&lt;P&gt;Both servers seems to be up and running properly:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# $MDS_FWDIR/scripts/cpm_status.sh&lt;BR /&gt;Check Point Security Management Server is running and ready&lt;/P&gt;&lt;P&gt;# $MDS_FWDIR/scripts/cpm_status.sh&lt;BR /&gt;Check Point Security Management Server is running and ready&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 12:11:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163705#M734</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-30T12:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163725#M735</link>
      <description>&lt;P&gt;OK, so this is the cause. You cannot set up SIC between two primary SMSs. Please explain to your TAC engineer this fact, and ask for guidance. You need to demote one to be secondary, and only TAC can help you with this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 13:53:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163725#M735</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-30T13:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163727#M736</link>
      <description>&lt;P&gt;They are responding extremely slow. The case is 11 days now and still not even a single viable solution . Not sure if they are reading my emails at all.&lt;/P&gt;&lt;P&gt;Instead I've deleted the secondary and deployed a new one with manual first time wizard as a secondary (much faster solution). Trust is established, but still not communicating properly for some reason. Check the above post for details. Same subnet, no NSG's, No Firewall, No UDR or something. Direct communication. There is something I am missing with the chekpoints itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saw this&amp;nbsp; sk39345 and the restrictions not mentioned in the admin guide. Even switched off the SmartEvent blade, but still the same.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 14:08:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163727#M736</guid>
      <dc:creator>razotevsSVR</dc:creator>
      <dc:date>2022-11-30T14:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard On Azure management Server High Availability failing</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163750#M737</link>
      <description>&lt;P&gt;If nothing is working correctly, you will need to debug CPD and review $FWDIR/log/cpd.elg to see where it fails. &amp;nbsp;If your CloudGuard management is in different VNETs, then you are getting hit by your management server being subject to NAT by Azure VNET, and this won't work for management HA. &amp;nbsp;CPD needs to see the packets as its native IP. &amp;nbsp;This may need to be a change with GUIDBedit to allow the two hosts to communicate SIC despite the IP changes (just like $FWDIR/conf/masters on a gateway, but I don't think this applies to management; you can try it tho: &amp;nbsp;either&amp;nbsp;&lt;SPAN&gt;sk102712 or manually edit the file then run "chattr +i $FWDIR/conf/masters" to make it immutable.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's an SK on doing manual/quasi-emergency Active/Primary management changes when you lost the Active+Primary management:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Likewise, if your HA management goes dual Active, here's how to quell one:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109794&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109794&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your host came up as primary management, you can verify everything with the internal variable configs:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# cpprod_util FwIsHAManagement&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This will return 0 if this is not a management HA. &amp;nbsp;Obviously, 1 if so.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can change its configuration to HA instead with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cpprod_util &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;FwSet&lt;/SPAN&gt;&lt;SPAN&gt;HA&lt;/SPAN&gt;&lt;SPAN&gt;Management 1 1 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That will set it as Management HA. &amp;nbsp;cpstop/cpstart, then check the first one again, and you should be good to go. &amp;nbsp;Feel free to check this with TAC, tho.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A neat trick: &amp;nbsp;You can build a gateway+management host, then later "turn off" the management server with cpprod_util and reboot. &amp;nbsp;That will disable the local management and let you re-do SIC to control the gateway from another management server. &amp;nbsp;I've had to do this a time or two for customers doing acquisitions where we needed to take over a gateway until we could get it rebuilt. &amp;nbsp;YES, re-building the gateway is the proper way, but if you're pushed into a deadline.... you do what you gotta do. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;(and yes, we did rebuild those hosts later). &amp;nbsp;This trick actually came directly from TAC long ago. &amp;nbsp;(Yes, you can also do the opposite, and "turn off" the gateway instead).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 16:32:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-On-Azure-management-Server-High-Availability-failing/m-p/163750#M737</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-11-30T16:32:05Z</dc:date>
    </item>
  </channel>
</rss>

