<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Force an Active GW to 'Down' status in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146971#M23402</link>
    <description>&lt;P&gt;How do you mean, update? Did you upgrade your VSX cluster? What did you update? If that was an upgrade, policy push is required at the end.&lt;BR /&gt;&lt;BR /&gt;To see the policy status, run "fw stat". I also sincerely advise some formal Check Point courses to take, to gain a better understanding of the technology.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 11:23:27 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-04-25T11:23:27Z</dc:date>
    <item>
      <title>Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98840#M8628</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I was reading sk101690 (How to reset a VSX Gateway) and there is the pre-requisite below:&lt;/P&gt;&lt;P&gt;"On VSX cluster member, the member state must be 'Down' or 'Standby' before starting the VSX reset procedure."&lt;/P&gt;&lt;P&gt;For the Standby member (for all Virtual systems) this is OK, but how to force the Active GW to be in 'Down' state?&lt;/P&gt;&lt;P&gt;Should i just use the command clusterXL_admin down on the Active? I guess i cannot force the Active to the 'Standby' status, since it will be the only GW on the cluster after resetting the Standby one.&lt;/P&gt;&lt;P&gt;I am interested for doing sth similar on Gaia R80.10 (VSLS).&lt;/P&gt;&lt;P&gt;Thank you in advance for your ideas!&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;George&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98840#M8628</guid>
      <dc:creator>georgemal</dc:creator>
      <dc:date>2020-10-12T09:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98865#M8629</link>
      <description>&lt;P&gt;When you push your &lt;U&gt;Physica&lt;/U&gt;l Active to Down as the SK describes, your Standby becomes Active Attention and starts passing traffic. Depending on your cluster settings, cancelling down status you just forced may result in one of the following actions (physical clusters only):&lt;BR /&gt;1. Your cluster member A goes to Standby, while the cluster member B (Previously Standby) remains Active till the next failover&lt;/P&gt;
&lt;P&gt;2. You cluster member A resumes Active and, member B goes back to Standby.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In case of VSX, forced down status for VS0 does not affect the rest of the VSs, as described in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95133" target="_self"&gt;&lt;SPAN&gt;sk95133&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 12:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98865#M8629</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-12T12:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98887#M8630</link>
      <description>&lt;P&gt;When you need to make sure you have 1 member active in a VSLS environment you can als use 'vsx_util vsls' on the management server to make all VS's actives on one member.&lt;/P&gt;
&lt;P&gt;This will not change the cluster state but will make sure a VS will only be active on a certain member.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 14:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/98887#M8630</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-10-12T14:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/99053#M8631</link>
      <description>&lt;P&gt;Thank you guys for your answers.&lt;/P&gt;&lt;P&gt;In my case i would like to try resetting both GWs, (at first the Standby one and then the Active)&amp;nbsp; and it is ok not to have any active GW all the time until i will completely reconfigure them.&lt;/P&gt;&lt;P&gt;So, my question has to do with the most convenient way that i can follow in order to reset the Active GW, since it needs to be in 'Down' or 'Standby' state first.&amp;nbsp; During the time i will reset the 'Active' GW, there will be no Standby one since it will have been reset already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope i clarified better my case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 07:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/99053#M8631</guid>
      <dc:creator>georgemal</dc:creator>
      <dc:date>2020-10-14T07:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146832#M23365</link>
      <description>&lt;P&gt;Maarten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use the make all VSes active on 1 member is it correct that on the other member the VSes show as DOWN instead of STANDBY? That is how cphaprob stat shows them (ACTIVE and DOWN, not ACTIVE!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**bleep**&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 07:59:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146832#M23365</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-22T07:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146836#M23368</link>
      <description>&lt;P&gt;Not under normal operational conditions, only if you push them down with admin command&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 09:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146836#M23368</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-22T09:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146846#M23370</link>
      <description>&lt;P&gt;Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp; I'll wait what TAC makes of it. For now I even worry to push a ruleset since I have no idea if this will further break things. I have my active virtual systems running but no standby's.&lt;/P&gt;&lt;P&gt;No need to sign my name since it will be beeped again I guess&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 13:05:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146846#M23370</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-22T13:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146851#M23372</link>
      <description>&lt;P&gt;what do you see from "cphaprob stat" on per vs?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 13:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146851#M23372</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-22T13:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146860#M23374</link>
      <description>&lt;P&gt;Val,&lt;/P&gt;&lt;P&gt;On the active member both vs's are ACTIVE (not ACTIVE!) and on the standby unit DOWN. FWD process is running in all context.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 15:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146860#M23374</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-22T15:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146862#M23375</link>
      <description>&lt;P&gt;Virtual Devices Status on each Cluster Member&lt;BR /&gt;=============================================&lt;/P&gt;&lt;P&gt;ID | Weight| NLHTNFW01 | NLGRNFW01&lt;BR /&gt;| | | [local]&lt;BR /&gt;-------+-------+-----------+-----------&lt;BR /&gt;2 | 10 | ACTIVE | DOWN&lt;BR /&gt;3 | 10 | ACTIVE | DOWN&lt;BR /&gt;---------------+-----------+-----------&lt;BR /&gt;Active | 2 | 0&lt;BR /&gt;Weight | 20 | 0&lt;BR /&gt;Weight (%) | 100 | 0&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 15:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146862#M23375</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-22T15:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146866#M23377</link>
      <description>&lt;P&gt;do the same with "cphaprob list"&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 16:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146866#M23377</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-22T16:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146942#M23394</link>
      <description>&lt;P&gt;Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That gives "there are no pnodes in problem state"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 05:58:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146942#M23394</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-25T05:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146944#M23395</link>
      <description>&lt;P&gt;on both sides? very unlikely&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 06:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146944#M23395</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-25T06:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146945#M23396</link>
      <description>&lt;P&gt;also, does it show policy installed on those which are down?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 06:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146945#M23396</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-25T06:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146954#M23397</link>
      <description>&lt;P&gt;Val,&lt;/P&gt;&lt;P&gt;No pnodes in problem state on both sides. How do I check if the policy is installed?&lt;/P&gt;&lt;P&gt;I don't want to push a policy (what I would normally do first ) because of the unexpected result of the update. I don't know if it break some more.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 08:29:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146954#M23397</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-25T08:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146971#M23402</link>
      <description>&lt;P&gt;How do you mean, update? Did you upgrade your VSX cluster? What did you update? If that was an upgrade, policy push is required at the end.&lt;BR /&gt;&lt;BR /&gt;To see the policy status, run "fw stat". I also sincerely advise some formal Check Point courses to take, to gain a better understanding of the technology.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 11:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146971#M23402</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-25T11:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146975#M23408</link>
      <description>&lt;P&gt;Val,&lt;/P&gt;&lt;P&gt;I installed JHF an the openssl patch on the vsx cluster. We were on an older JHF that does not support the patch.&lt;/P&gt;&lt;P&gt;I first installed the JHF and patch on the unit where both virtual systems were in standby, waited 2 days to see if all kept working, moved the virtual systems with vsx_util vsls to the other node, waited another 2 days and finally installed the JHF and patch on the other unit.&lt;/P&gt;&lt;P&gt;fw stat shows the vsx policy installed on both. I am missing a bond on the node where the virtual systems did run before I started installing (now the system where they are supposed to be standby).&lt;/P&gt;&lt;P&gt;Your continuing help is highly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 12:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146975#M23408</guid>
      <dc:creator>IT_Infra_Arval</dc:creator>
      <dc:date>2022-04-25T12:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Force an Active GW to 'Down' status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146976#M23409</link>
      <description>&lt;P&gt;I would check what policy is running, and would push a new version of the policy anyway to each of the VSs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Missing bond should show in the pnotes, if it is a cluster monitored interface. Get a service window, push policies, and, if not cleared, rebook both physical GWs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, please send me your SR number to &lt;A href="mailto:vloukine@checkpoint.com," target="_blank"&gt;vloukine@checkpoint.com,&lt;/A&gt;&amp;nbsp;I will take a look, just in case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 12:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Force-an-Active-GW-to-Down-status/m-p/146976#M23409</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-25T12:41:49Z</dc:date>
    </item>
  </channel>
</rss>

