<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to delete VS firewalls when VSX members are offline in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/149019#M23853</link>
    <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an update.&lt;/P&gt;&lt;P&gt;We restored to a snapshot and got back to a known good state.&amp;nbsp; enabled the debug and was able to move through and delete all the VSX environment successfully.&lt;/P&gt;&lt;P&gt;Thanks for the help.&amp;nbsp; All good now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. This is why I love Checkmates.&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2022 12:39:59 GMT</pubDate>
    <dc:creator>Jacques_Spelier</dc:creator>
    <dc:date>2022-05-19T12:39:59Z</dc:date>
    <item>
      <title>unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148911#M23838</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;We seem to have created an issue and wondering if anybody has come across similar situation and how they resolved it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have decomm'ed our VSX appliances before deleting the VS/VSX objects in SmartCenter. We are now stuck in a loop where the SC is trying to communicate to the VSX members to inform them of the deletion. We opened a ticket with TAC and they directed us to delete the reference of the VS via GUIDBEDIT.&amp;nbsp; We have remove the vs_slot_members references as per SK127232. When we reattempt to delete the VS in question, still generates communication attempts and fails to remove the object. Also since we did the DBedit change as recommended by TAC, we can no longer push policy to other non-vsx gateways. Message to the effect of "A Cluster (VSNAME) cannot be empty. It must have cluster members."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am thinking that a deletion of the "vs_slots_objects" container located under the "Network Objects"&amp;nbsp; could resolve our issue but looking for feedback from the community. We are waiting on TAC right now.&lt;/P&gt;&lt;P&gt;Thoughts/suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 14:02:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148911#M23838</guid>
      <dc:creator>Jacques_Spelier</dc:creator>
      <dc:date>2022-05-18T14:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148913#M23839</link>
      <description>&lt;P&gt;Deleting things in GuiDBEdit may have left you in an inconsistent state which may require more GuiDBEdit work to fix. Export your config &lt;EM&gt;&lt;STRONG&gt;right now&lt;/STRONG&gt;&lt;/EM&gt; to be sure you can always get back to this point at worst.&lt;/P&gt;
&lt;P&gt;If this sort of thing comes up in the future, you should run these commands on your management server:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_PING=INFO
fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_INSTALL=INFO
fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_PULL_SIC=INFO&lt;/LI-CODE&gt;
&lt;P&gt;Together, they let you make management-side changes without needing communications with the VSX boxes. Good for deleting VSs when you can't reach the cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 14:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148913#M23839</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-05-18T14:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148917#M23841</link>
      <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;Did as you suggested with the debug cmds. Some of the warning messages disappeared by at the end still got an error message and the VS did not get deleted.&lt;/P&gt;&lt;P&gt;"Checking connection with VSX&lt;/P&gt;&lt;P&gt;Deleting VSNAME&lt;/P&gt;&lt;P&gt;Internal error: Number of members should be greater then 1&lt;/P&gt;&lt;P&gt;Virtual System Deletion Completed with Errors.&lt;/P&gt;&lt;P&gt;We tried to delete a "non-modified" VS object on that same VSX cluster with same results.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 15:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148917#M23841</guid>
      <dc:creator>Jacques_Spelier</dc:creator>
      <dc:date>2022-05-18T15:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148929#M23842</link>
      <description>&lt;P&gt;Like I mentioned, I think those commands will probably only help in the future. I think the GuiDBEdit changes have broken your database enough to require manual intervention to fix it.&amp;nbsp;If you can restore back to a management export, snapshot, or whatever taken before you made changes with GuiDBEdit, the debug flags might help.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 17:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148929#M23842</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-05-18T17:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/149019#M23853</link>
      <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an update.&lt;/P&gt;&lt;P&gt;We restored to a snapshot and got back to a known good state.&amp;nbsp; enabled the debug and was able to move through and delete all the VSX environment successfully.&lt;/P&gt;&lt;P&gt;Thanks for the help.&amp;nbsp; All good now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. This is why I love Checkmates.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 12:39:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/149019#M23853</guid>
      <dc:creator>Jacques_Spelier</dc:creator>
      <dc:date>2022-05-19T12:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete VS firewalls when VSX members are offline</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/149037#M23856</link>
      <description>&lt;P&gt;Nice! Good to hear you had a backup from before the dbedit changes.&lt;/P&gt;
&lt;P&gt;I've had to use these debugs in the past when upgrading a cluster member. The VSX object on the SmartCenter had incorrect interface definitions. For example, the SmartCenter listed eth4 and eth5 as interfaces, but they were members of bond1, which was also listed. When running 'vsx_util reconfigure', they were no longer seen as valid interfaces. I only had so many physical ports on the box, so I couldn't just rearrange some. I had to remove the missing interfaces from the object, but when I tried, it failed because it couldn't connect to the member I had upgraded. Dumb problem. Fortunately, the fix is pretty simple.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 13:50:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/149037#M23856</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-05-19T13:50:11Z</dc:date>
    </item>
  </channel>
</rss>

