<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Synchronization of gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164264#M29401</link>
    <description>&lt;P&gt;Configure the OS settings the same as the one you're replacing it with.&lt;BR /&gt;You will need to reset SIC with the device and push policy.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2022 00:52:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-12-06T00:52:37Z</dc:date>
    <item>
      <title>Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161792#M28698</link>
      <description>&lt;P&gt;We have 2 checkpoint 7000 series appliances. We have configured them as a cluster. Last time the standby server hardware unable to reboot and now we are pushing policies on 1 gateway only.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I want to know what happens when the 2nd gateway gets fixed. Does the policies that are installed on the active gateway synchronized with the standby one?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 10 Nov 2022 17:17:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161792#M28698</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2022-11-10T17:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161808#M28703</link>
      <description>&lt;P&gt;When a gateway boots up, it will try to load one of the following policies in order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Gateway will fetch last compiled and installed policy from management&lt;/LI&gt;
&lt;LI&gt;If the gateway cannot reach the management, the gateway will use a locally cached copy of the last policy installed&lt;/LI&gt;
&lt;LI&gt;If no policy was installed, the policy is corrupt/compiled for the wrong version, or there is an issue with the firewall license, the gateway will load DefaultFilter, which blocks all traffic.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The much shorter answer is yes, but it pulls the current policy from management, not the other gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 18:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161808#M28703</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-10T18:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161812#M28705</link>
      <description>&lt;P&gt;To add to this, I also find that most of the time, for step 2 phoneboy mentioned, IF gateway cant "talk" to the management, it will usually load initial policy (though this usually may happen after major upgrade, which requires a reboot), which pretty much block everything, but unlike default filter, it would let you ssh and web UI, but only on default port 443, nothing else.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 20:21:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161812#M28705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T20:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161839#M28718</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Thank You for the immediate response.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Which means when we start configuring the second gateway as a cluster with the one currently working it will push the gateway from SMS?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 05:18:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161839#M28718</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2022-11-11T05:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161870#M28736</link>
      <description>&lt;P&gt;If you restore from a system backup onto identical hardware, you shouldn't need to do anything special.&lt;BR /&gt;If you rebuild the cluster member from scratch, it's possible you may need to push policy from management, which you should probably do anyway just to confirm proper operation.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 16:14:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/161870#M28736</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-11T16:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164196#M29384</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any steps to be followed during the process?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have bought a new 7000 series device. Now we want to configure the new gateway (the standby cluster before), to the existing cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, how could we do that? If there is any steps to be followed?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 15:15:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164196#M29384</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2022-12-05T15:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164264#M29401</link>
      <description>&lt;P&gt;Configure the OS settings the same as the one you're replacing it with.&lt;BR /&gt;You will need to reset SIC with the device and push policy.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 00:52:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164264#M29401</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-06T00:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164280#M29409</link>
      <description>&lt;P&gt;So that it will get all the policies installed on the active gateway including static routes on GAIA, Right?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 05:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164280#M29409</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2022-12-06T05:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164283#M29410</link>
      <description>&lt;P&gt;Nope - Configuration persisting to device itself wont be recovered from policy push like &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned. Those settings either has to be restored from backup or manually from other service from clish with &amp;gt; show configuration and then picking up specific commands like changing the IP addresses of interfaces. You will get the routes though and other settings which can be stay common on both the devices.&lt;/P&gt;&lt;P&gt;Like routes/snmp/users etc.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 05:57:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-gateways/m-p/164283#M29410</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-06T05:57:14Z</dc:date>
    </item>
  </channel>
</rss>

