<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When to perform Database update in checkpoint GW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119790#M16954</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Im new to checkpoint and have some queries.&lt;/P&gt;&lt;P&gt;What are the few occasions when we need to perform database update ?&lt;/P&gt;&lt;P&gt;What are the few common changes we cannot perform on a GW through Management server if we have physical Gateway vs Virtual system.&lt;/P&gt;&lt;P&gt;I have come to know that route addition on vsx can be done via Smart dash board.&lt;/P&gt;&lt;P&gt;On Physical GW, we need to do it via cli or Gateway GUI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 30 May 2021 07:38:19 GMT</pubDate>
    <dc:creator>RBS56505</dc:creator>
    <dc:date>2021-05-30T07:38:19Z</dc:date>
    <item>
      <title>When to perform Database update in checkpoint GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119790#M16954</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Im new to checkpoint and have some queries.&lt;/P&gt;&lt;P&gt;What are the few occasions when we need to perform database update ?&lt;/P&gt;&lt;P&gt;What are the few common changes we cannot perform on a GW through Management server if we have physical Gateway vs Virtual system.&lt;/P&gt;&lt;P&gt;I have come to know that route addition on vsx can be done via Smart dash board.&lt;/P&gt;&lt;P&gt;On Physical GW, we need to do it via cli or Gateway GUI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 07:38:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119790#M16954</guid>
      <dc:creator>RBS56505</dc:creator>
      <dc:date>2021-05-30T07:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: When to perform Database update in checkpoint GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119846#M16959</link>
      <description>&lt;P&gt;What do you mean by "database update" exactly?&lt;BR /&gt;Screenshots of exactly what you're talking about might be helpful.&lt;/P&gt;
&lt;P&gt;In general, there are a couple of differences between VSX and regular gateways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can't "reboot" a single VS (only the entire chassis)&lt;/LI&gt;
&lt;LI&gt;If you need to make any changes to static routing, this is done via SmartConsole (dynamic routing can be configured via clish, I believe)&lt;/LI&gt;
&lt;LI&gt;Any troubleshooting involving a VS means you need to switch into the VS context (vsenv X or set virtual-system X)&lt;/LI&gt;
&lt;LI&gt;VSX gateway interface changes require disabling VSX mode temporarily (see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92425" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92425&lt;/A&gt;)&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You cannot manipulate VS objects with the API (some manipulation can be done with the vsx_provisioning_tool)&lt;/LI&gt;
&lt;LI&gt;Some features are not supported on VSX:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are possibly others, but those are the ones that immediately come to mind.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 02:47:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119846#M16959</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-31T02:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: When to perform Database update in checkpoint GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119855#M16961</link>
      <description>&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;Thank you for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all my used term is wrong. It should be "install database"&lt;/P&gt;&lt;P&gt;I dont have a a snapshot however let me give some background here.&lt;/P&gt;&lt;P&gt;We are migrating our checkpoint infrastructure to R80.30&lt;/P&gt;&lt;P&gt;As a interim steps, we are migrating all our existing infrastructure to a new R77.30.&lt;/P&gt;&lt;P&gt;Now while migrating one of the Mgt Server (managing 4 GWs) , there was OPSEC server(SKYBOX).&lt;/P&gt;&lt;P&gt;They did reset that communication for OPSEC server. My understanding is they initiated SIC from new Mgt Server.&lt;/P&gt;&lt;P&gt;Corresponding changes at SKYBOX is pending. (New CMA IP etc)&lt;/P&gt;&lt;P&gt;Now they kept saying that until we install updates this will not work.&lt;/P&gt;&lt;P&gt;My understanding is when we migrated to new Mgt server, we did install policy and that includes install database.&lt;/P&gt;&lt;P&gt;Am i wrong ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 06:57:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119855#M16961</guid>
      <dc:creator>RBS56505</dc:creator>
      <dc:date>2021-05-31T06:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: When to perform Database update in checkpoint GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119860#M16962</link>
      <description>&lt;P&gt;No - see&amp;nbsp;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;&lt;STRONG&gt;Security Management R81 Administration Guide&lt;/STRONG&gt;, e.g. p166:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="page" title="Page 165"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;Installing the User Database&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When you make changes to user definitions through SmartConsole, they are saved to the user database on the Security Management Server. User authentication methods and encryption keys are also saved in this database. The user database does not contain information about users defined externally to the Security Gateway (such as users in external User Directory groups), but it does contain information about the external groups themselves (for example, on which Account Unit the external group is defined). Changes to external groups take effect only after the policy is installed, or the user database is downloaded from the Security Management Server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="page" title="Page 166"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;You must choose to install the policy or the user database, based on the changes you made:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;n &lt;/SPAN&gt;&lt;SPAN&gt;Install the policy, if you modified additional components of the Policy Package (for example, added new Security Policy rules) that are used by the installation targets&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;n &lt;/SPAN&gt;&lt;SPAN&gt;Install the user database, if you only changed the user definitions or the administrator definitions - from the Menu, select &lt;/SPAN&gt;&lt;SPAN&gt;Install Database&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The user database is installed on:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;n &lt;/SPAN&gt;&lt;SPAN&gt;Security Gateways - during policy installation&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;n &lt;/SPAN&gt;&lt;SPAN&gt;Check Point hosts with one or more Management Software Blades enabled - during database installation&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also install the user database on Security Gateways and on a remote server, such as a Log Server, from the command line interface on the Security Management Server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 May 2021 07:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/When-to-perform-Database-update-in-checkpoint-GW/m-p/119860#M16962</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-31T07:28:30Z</dc:date>
    </item>
  </channel>
</rss>

