<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105958#M10015</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34257"&gt;@ProxyOps&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for the kind words!&lt;/P&gt;</description>
    <pubDate>Sun, 20 Dec 2020 07:08:52 GMT</pubDate>
    <dc:creator>Royi_Priov</dc:creator>
    <dc:date>2020-12-20T07:08:52Z</dc:date>
    <item>
      <title>Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105734#M10009</link>
      <description>&lt;P&gt;Very recently, sk170516 was published.&lt;/P&gt;&lt;P&gt;It is linked in R80.40 JHF T91 / R80.30 JHF T227&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;PRJ-18247,&lt;BR /&gt;PRJ-18124&lt;/TD&gt;&lt;TD&gt;Identity Awareness&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;NEW&lt;/STRONG&gt;: Added Identity Sharing's performance and functionality improvements. Refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170516" target="_blank" rel="noopener"&gt;sk170516&lt;/A&gt;.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sk170516 tells us, that we need to clear the internal IA tables on all gateways after upgrading to JHFs that include this improvements:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;We recommend to run the following command on all members of all clusters in the policy simultaneously and only after the Jumbo Hotfix upgrade was finished.&lt;BR /&gt;Running the following command will remove zombie entries from Identity Awareness kernel tables and will initiate a sync between all PDP and PEP Security Gateways.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: This procedure removes all identities that were learned, therefore perform it during the maintenance window.&lt;/P&gt;&lt;P&gt;The commands are the well-known ones, that do a complete purge of all IA data.&lt;/P&gt;&lt;P&gt;This sounds like there was some breaking change done here which is just incompatible with the old internal data structure.&lt;/P&gt;&lt;P&gt;This can be a little challenging in the field, because usually in customers environments, not all gateways are updated during the same maintenance window.&lt;/P&gt;&lt;P&gt;I would really appriciate getting some clarification here about when to do this procedure and if it is possible to mix old versions and new versions (regarding this change) together in Identity Sharing environment.&lt;/P&gt;&lt;P&gt;Example scenario:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;GW1: PDP and PEP, R80.40 JHF T89 on SMS-1&lt;/LI&gt;&lt;LI&gt;GW2:&amp;nbsp; PEP only, R80.30 JHF T226 on SMS-2 (foreign IA-Trust: sk65404 )&lt;/LI&gt;&lt;LI&gt;GW3-n: PEP only, R80.40 JHF T89 on SMS-1&lt;/LI&gt;&lt;LI&gt;SMS-1: R80.40 JHF T89&lt;/LI&gt;&lt;LI&gt;SMS-2: R80.30 JHF T226&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now the customer wants to schedule different maintenance windows to update these boxes. What should we tell them?&lt;/P&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Not possible, because we have to update all of them at the same time.&lt;/LI&gt;&lt;LI&gt;Possible, but we need to clear the tables after every update.&lt;/LI&gt;&lt;LI&gt;Possible, but we need to clear the tables after update of GW2 (because only this one is a PDP).&lt;/LI&gt;&lt;LI&gt;Some other.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thank you for clarification &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It would also good to know, what kind of "functionality improvements" were implemented here, but maybe Check Point does not want to disclose this.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 10:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105734#M10009</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2020-12-17T10:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105735#M10010</link>
      <description>&lt;P&gt;I would suggest rather to contact TAC with your questions, that will supply an official wording for the customer. Or contact your local SE first.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 11:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105735#M10010</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-12-17T11:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105747#M10011</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1408"&gt;@Tobias_Moritz&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;I will start with the bottom line - the key for success will be:&lt;/P&gt;
&lt;P&gt;Once the PDP/PEP finished the JHF upgrade - clear it's tables. If it's cluster, clear all members at once.&lt;/P&gt;
&lt;P&gt;There is no breaking change between PDP to PEP sharing in this bundle.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And for the long version:&lt;/P&gt;
&lt;P&gt;In Identity Awareness R&amp;amp;D, we have done an internal quality cycle on Identity Sharing flows, to raise issues proactively.&lt;/P&gt;
&lt;P&gt;As part of this cycle, we have created more than 20 code changes which are both functional, optimization and debuggability improvements.&lt;/P&gt;
&lt;P&gt;This bundle was already implemented with some key customers production and in large QA cycle to ensure high quality before adding to the JHF.&lt;/P&gt;
&lt;P&gt;If the IDA tables will not be cleared, 2 main behaviors are possible:&lt;/P&gt;
&lt;P&gt;1. leftovers on the kernel tables, which usually not cause any issue other than memory taken by them.&lt;/P&gt;
&lt;P&gt;2. temporary sync issues to PEP in Identity Sharing, until the next sharing sync.&lt;/P&gt;
&lt;P&gt;Since upgrading JHF anyhow involves maintenance window, I prefer writing the above SK to avoid such undesired behaviors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any additional questions, feel free to tag me&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 13:37:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105747#M10011</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-12-17T13:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105755#M10012</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thank you very much for you fast and detailed response. Really appreciated.&lt;/P&gt;&lt;P&gt;That sounds much better that what I expected after reading the sk.&lt;/P&gt;&lt;P&gt;Maybe someone can update the sk and add the info that purging these tables on PDP side after updating PDP gateways is enough and that there is no action needed on PEP-only gateways. And that there are no compatibility issues between updated and not updated gateways &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 14:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105755#M10012</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2020-12-17T14:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105932#M10013</link>
      <description>&lt;P&gt;We as a intensive IA using company, are looking foward for this JHF to become GA so we can push it to all our PEPs and our dedicated PDP Brokers, in our IA enviroment.&lt;/P&gt;&lt;P&gt;With the recent improvoments coming with the offical release of the PDP Broker and now the finished quality lifecyle for IA flows, CheckPoint is definitly going in the right direction regarding the Identity Awareness Blade. The scalabillity and reliabillity improvments are great.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;Great work and kudos to the complete team !&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 18:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105932#M10013</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2020-12-19T18:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105957#M10014</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1408"&gt;@Tobias_Moritz&lt;/a&gt;&amp;nbsp;- Will do, thanks for the suggestion.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 07:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105957#M10014</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-12-20T07:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105958#M10015</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34257"&gt;@ProxyOps&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for the kind words!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 07:08:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/105958#M10015</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-12-20T07:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Breaking IA change in R80.40 JHF T91 / R80.30 JHF T227 - sk170516</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/110162#M15123</link>
      <description>&lt;P&gt;This procedure should be performed after upgrading clustered gateways with enabled Identity Awareness Blade of the following versions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116380" target="_blank" rel="noopener"&gt;R80.10 Jumbo Hotfix&lt;/A&gt; Take 287 and below upgraded to Take 288 and higher&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;amp;solutionid=sk153152" target="_blank" rel="noopener"&gt;R80.30 Jumbo Hotfix&lt;/A&gt; Take 226 and below upgraded to Take 227 and higher&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;amp;solutionid=sk153152" target="_blank" rel="noopener"&gt;R80.30 Jumbo Hotfix&lt;/A&gt; Gaia 3.10 Take 227 and below upgraded to Take 228 and higher&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;amp;solutionid=sk165456" target="_blank" rel="noopener"&gt;R80.40 Jumbo Hotfix&lt;/A&gt; Take 90 and below upgraded to Take 91 and higher&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170114" target="_blank" rel="noopener"&gt;R81 Jumbo Hotfix&lt;/A&gt; Take 11 and below upgraded to Take 13 and higher&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I have seen issues with MUH agent after upgrades without performing it.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 11:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Breaking-IA-change-in-R80-40-JHF-T91-R80-30-JHF-T227-sk170516/m-p/110162#M15123</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-02-08T11:04:21Z</dc:date>
    </item>
  </channel>
</rss>

