<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy push on security gateway cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137802#M20879</link>
    <description>&lt;P&gt;Hi Ratnesh,&lt;BR /&gt;&lt;BR /&gt;It really doesn't make a difference, policy will start applying once the active gets it, whilst the standby is on-freeze and not getting data connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having said that, Which one "installs first" will depend on many factors but mainly:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Which member gets the policy files on&amp;nbsp;$FWDIR/state/__tmp/FW1 first&lt;UL&gt;&lt;LI&gt;This will depend if the standby is a silent standby, or independent with different network speeds from manager to active and manager to standby&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Which one processes those files first&lt;UL&gt;&lt;LI&gt;Here, as you guess, will depend on the resources available. In general, a standby member is idler than the active so it installs the policy first.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jan 2022 09:58:59 GMT</pubDate>
    <dc:creator>Juan_</dc:creator>
    <dc:date>2022-01-06T09:58:59Z</dc:date>
    <item>
      <title>Policy push on security gateway cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137751#M20870</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I need some clarification. When we are installing policy on security gateway cluster configured in HA (Active/ Standby) .On which gateway policy will get install 1st . Standby or Active or both in parallel . Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 15:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137751#M20870</guid>
      <dc:creator>Ratnesh_Singh</dc:creator>
      <dc:date>2022-01-05T15:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push on security gateway cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137755#M20871</link>
      <description>&lt;P&gt;I could be wrong when I say this, but I dont believe there is a method to it. I had seen many times where backup member gets policy first, but then in lots of cases, its master that gets done before backup.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 16:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137755#M20871</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-05T16:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push on security gateway cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137802#M20879</link>
      <description>&lt;P&gt;Hi Ratnesh,&lt;BR /&gt;&lt;BR /&gt;It really doesn't make a difference, policy will start applying once the active gets it, whilst the standby is on-freeze and not getting data connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having said that, Which one "installs first" will depend on many factors but mainly:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Which member gets the policy files on&amp;nbsp;$FWDIR/state/__tmp/FW1 first&lt;UL&gt;&lt;LI&gt;This will depend if the standby is a silent standby, or independent with different network speeds from manager to active and manager to standby&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Which one processes those files first&lt;UL&gt;&lt;LI&gt;Here, as you guess, will depend on the resources available. In general, a standby member is idler than the active so it installs the policy first.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 09:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-on-security-gateway-cluster/m-p/137802#M20879</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2022-01-06T09:58:59Z</dc:date>
    </item>
  </channel>
</rss>

