<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ... in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147132#M23442</link>
    <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;In my case - R80.40, Cluster LS with 3 members, clean install, Jumbo 156.&lt;/P&gt;&lt;P&gt;2 gateways - defaultfilter after every reboot (fw fetch works), one is working fine.&lt;/P&gt;&lt;P&gt;Any news from TAC?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2022 07:23:47 GMT</pubDate>
    <dc:creator>Pawel_Szetela</dc:creator>
    <dc:date>2022-04-27T07:23:47Z</dc:date>
    <item>
      <title>After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146480#M23265</link>
      <description>&lt;P&gt;Hello Check Mates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we have seen several occasions that the firewall policy got totaly lost after installing Take 58.&lt;BR /&gt;the "Default Filter Policy" was loaded.&amp;nbsp;&lt;BR /&gt;we mostly deploy updates via CDT.&lt;BR /&gt;&lt;BR /&gt;we went from Take 44 to Take 58, installed the hotfix on 13 gateways and all 13 got totaly stuck.&lt;BR /&gt;a CP Case in ongoing.&lt;BR /&gt;&lt;BR /&gt;When we did "fw fetch" on the CLI it works instantly ...&lt;BR /&gt;But when we do a reboot of the firewall the issue happens again.&lt;BR /&gt;&lt;BR /&gt;has anybody seen this before?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 13:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146480#M23265</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-04-19T13:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146735#M23349</link>
      <description>&lt;P&gt;Yeah, that does not sound like expected behavior at all, since the gateway should:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Fetch from management the last installed policy&lt;/LI&gt;
&lt;LI&gt;Use the last policy the gateway has cached if management is unavailable&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is long established behavior and the fact it's doing neither is definitely a bug.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 14:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146735#M23349</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-21T14:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146760#M23353</link>
      <description>&lt;P&gt;Yea, I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;. That certainly does not seem like normal/expected behaviour. Hopefully, TAC will involve R&amp;amp;D into the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 21:41:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/146760#M23353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-21T21:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147132#M23442</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;In my case - R80.40, Cluster LS with 3 members, clean install, Jumbo 156.&lt;/P&gt;&lt;P&gt;2 gateways - defaultfilter after every reboot (fw fetch works), one is working fine.&lt;/P&gt;&lt;P&gt;Any news from TAC?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 07:23:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147132#M23442</guid>
      <dc:creator>Pawel_Szetela</dc:creator>
      <dc:date>2022-04-27T07:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147134#M23443</link>
      <description>&lt;P&gt;Hi Pawel,&lt;BR /&gt;&lt;BR /&gt;well no real news yet so far ... we still wait ...&lt;BR /&gt;at best for a remote session to simulate and replicate the issue ...&lt;BR /&gt;i will keep you posted when new infos become available ...&lt;BR /&gt;&lt;BR /&gt;regards.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 07:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147134#M23443</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-04-27T07:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147157#M23455</link>
      <description>&lt;P&gt;Hi &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24246"&gt;@Thomas_Eichelbu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my name is Naama Specktor and I am from checkpoint ,&lt;/P&gt;
&lt;P&gt;I will appreciate it if you will share the TAC SR # with me , here or in PM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;
&lt;P&gt;Naama&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 10:07:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147157#M23455</guid>
      <dc:creator>Naama_Specktor</dc:creator>
      <dc:date>2022-04-27T10:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147223#M23488</link>
      <description>&lt;P&gt;Same issue on one site (cluster of 2 x 6400's) we upgraded to Take 65.&lt;/P&gt;
&lt;P&gt;Going in via LOM and running "fw stat" shows defaultfilter as firewall policy, and "cphaprob stat" of course then shows HA module not started.&lt;/P&gt;
&lt;P&gt;"fw fetch" was a temporary fix to get connectivity up and running, but it would revert to the defaultfilter policy again on reboot.&amp;nbsp; The permanent fix was to push policy from the SMS.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 16:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147223#M23488</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-04-27T16:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147298#M23508</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In our case policy installation didn't fix problem. But we have manage to fix this another way.&lt;/P&gt;&lt;P&gt;Later checks showed that even fw fetch worked partially - AV and ABot were not working till policy install.&lt;/P&gt;&lt;P&gt;After many checks and tries with findings in support center without luck,&amp;nbsp; we started to analyze messages files. We compared files from "working" cluster member with faulty one and found some differences.&lt;/P&gt;&lt;P&gt;In faulty member we found many of this:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_13];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_13];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_13];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_13];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: FW-1: lost 3252 debug messages&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_14];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_14];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_14];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_14];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: FW-1: lost 2904 debug messages&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_15];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_15];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_15];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_15];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: FW-1: lost 3392 debug messages&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_16];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_16];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_16];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_16];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: FW-1: lost 2716 debug messages&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_17];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_17];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_17];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_17];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: FW-1: lost 2424 debug messages&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_18];[ERROR]: domo_ip_to_domain_lookup: domo global is NULL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_18];[ERROR]: nrb_column_ip_match_domains_for_ip: domo_ip_to_domain_lookup failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_18];[ERROR]: nrb_column_ip_match: nrb_column_ip_match_domains_for_ip failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Apr 27 18:27:00 2022 CPFWX kernel: [fw4_18];[ERROR]: nrb_rulebase_default_match: virtual match_func failed for column 'Destination IP' (2)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Later, after reboot (before runinng fw fetch) we analyzed install_policy_report.txt. First error in this file:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;cmi_loader: 'signatures_done_cb' failed for app: (FILE_SECURITY), app_id (12)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;lead us to sk173248 and gave us a clue - maybe IOC problem, maybe MD5.&lt;/P&gt;&lt;P&gt;In our policy we use IOC configured in SmartConsole and form IOC feeds. Removing IOC feed for MD5 resolved problem. So we decided to remove all IOC from SmartConsole and move them to IOC feed.&lt;/P&gt;&lt;P&gt;And that solved our problem. Strange thing is that one cluster member worked fine ... but that's another mistery of Check Point &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 07:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147298#M23508</guid>
      <dc:creator>Pawel_Szetela</dc:creator>
      <dc:date>2022-04-28T07:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: After installing Take 58 on R81, FW Policy is lost. Firewall becomes unavailable ...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147656#M23567</link>
      <description>&lt;P&gt;Hello Guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;on this customer with the corrupt Take 58 installations we have and still have Indicator files loaded with MD5 hashes ...&lt;BR /&gt;we saw that after a policy push from the SMS the polic was loaded successfully.. the policy then was not lost after subsequent reboots.&lt;BR /&gt;&lt;BR /&gt;other costumers which do not have Indicator files with MD5 hashes loaded have no issue at all with Take 58.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;i hope we find time to invest the by ourself a bit more ... and reproduce the issue in a lab enviroment.&lt;BR /&gt;Check Point TAC is also still investigating ...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 07:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-installing-Take-58-on-R81-FW-Policy-is-lost-Firewall/m-p/147656#M23567</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-05-03T07:45:08Z</dc:date>
    </item>
  </channel>
</rss>

