<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fwkern.conf modified at boot. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115561#M16263</link>
    <description>&lt;P&gt;Great,&amp;nbsp; have you also seen reduced CPU utilisation since applying JHFA100?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also are you running Identity Awareness blade?&amp;nbsp; Wondering if it has something to do with that parameter.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Apr 2021 13:18:48 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2021-04-08T13:18:48Z</dc:date>
    <item>
      <title>fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115506#M16244</link>
      <description>&lt;P&gt;Hi, first time posting here. Apologies in advance for my limited english : )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, we've been working with Checkpoint for years now, but since the 80.40 Jumbo 100 update applied a few days ago, the strangest bug happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At boot, the fwkern.conf file is being backup in a new file, copy_fwkern.conf, and a line added at the end of the custom fwkern.conf. But the addition is messed up, and If I reboot with this fwkern.conf, the gateway is stuck at loading.&lt;/P&gt;&lt;P&gt;So, I believe is was a problem due tu multiples updates on top of another. I re-done a gateway (we are in high availability cluster) from scratch, starting with the r80.40 iso, and then patching up to latest jumbo 100. No restore, no snapshot used. Same behaviour.&lt;/P&gt;&lt;P&gt;This is my fwkern.conf :&lt;/P&gt;&lt;P&gt;cphwd_nat_templates_support=1&lt;BR /&gt;cphwd_nat_templates_enabled=1&lt;BR /&gt;enhanced_ssl_inspection=0&lt;BR /&gt;bypass_on_enhanced_ssl_inspection=1&lt;BR /&gt;fwha_resend_arp_unicast=1&lt;BR /&gt;fwha_forw_packet_to_not_active=1&lt;BR /&gt;fwha_arp_forward_standby=1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after a reboot :&lt;/P&gt;&lt;P&gt;cphwd_nat_templates_support=1&lt;BR /&gt;cphwd_nat_templates_enabled=1&lt;BR /&gt;enhanced_ssl_inspection=0&lt;BR /&gt;bypass_on_enhanced_ssl_inspection=1&lt;BR /&gt;fwha_resend_arp_unicast=1&lt;BR /&gt;fwha_forw_packet_to_not_active=1&lt;BR /&gt;fwha_arp_forward_standby=1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;nac_max_enforced_identities=90000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doesn't matter if I put the file in read only, since it's regenerated at boot... Before opening a ticket, have you some stuff to look at ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Florian -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 14:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115506#M16244</guid>
      <dc:creator>Florian_B</dc:creator>
      <dc:date>2021-04-07T14:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115526#M16253</link>
      <description>&lt;P&gt;I would open a TAC case regardless&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 20:06:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115526#M16253</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-07T20:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115546#M16257</link>
      <description>&lt;P&gt;Yes, I did too, I'm waiting for the support now. It's really strange. If I delete fwkern.conf, It comes back after a reboot, with the same&amp;nbsp;&lt;SPAN&gt;nac_max_enforced_identities=90000 line only... So something is generating or adding this line to the file, but I really don't know what... Especially since it's doing the same thing on a "brand new" gateway too...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 05:47:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115546#M16257</guid>
      <dc:creator>Florian_B</dc:creator>
      <dc:date>2021-04-08T05:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115558#M16260</link>
      <description>&lt;P&gt;I don't have the entry in our systems but we are running JHFA91 at the moment.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 08:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115558#M16260</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-08T08:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115560#M16262</link>
      <description>&lt;P&gt;We didn't have the problem with the Take 93. It's really since the Take 100... I'll let you know what the support says.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 08:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115560#M16262</guid>
      <dc:creator>Florian_B</dc:creator>
      <dc:date>2021-04-08T08:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115561#M16263</link>
      <description>&lt;P&gt;Great,&amp;nbsp; have you also seen reduced CPU utilisation since applying JHFA100?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also are you running Identity Awareness blade?&amp;nbsp; Wondering if it has something to do with that parameter.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 13:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115561#M16263</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-08T13:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115805#M16324</link>
      <description>&lt;P&gt;The parameter name suggests it's related to Identity Awareness.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 05:11:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115805#M16324</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-12T05:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: fwkern.conf modified at boot.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115808#M16325</link>
      <description>&lt;P&gt;I would open a TAC case.&lt;/P&gt;
&lt;P&gt;As an emergency solution. You can also set the file with an "s" or "t" bit, then it can no longer be overwritten by the system:&lt;/P&gt;
&lt;P&gt;chmod u+s fwkern.conf&lt;BR /&gt;&lt;BR /&gt;The chmod command is also capable of changing the additional permissions or special modes of a file or directory. The symbolic modes use 's' to represent the setuid and setgid modes, and 't' to represent the sticky mode. The modes are only applied to the appropriate classes, regardless of whether or not other classes are specified.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 06:23:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fwkern-conf-modified-at-boot/m-p/115808#M16325</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-04-12T06:23:56Z</dc:date>
    </item>
  </channel>
</rss>

